Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-7575
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
ELSA-2016-0008
ELSA-2016-0008: openssl security update (MODERATE)
ELSA-2016-0007
ELSA-2016-0007: nss security update (MODERATE)
ELSA-2016-0012
ELSA-2016-0012: gnutls security update (MODERATE)
CVE-2015-7575
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
openSUSE-SU-2016:0007-1
Security update for MozillaFirefox
openSUSE-SU-2015:2405-1
Security update for mozilla-nss
CVE-2015-7223
The WebExtension APIs in Mozilla Firefox before 43.0 allow remote atta ...
CVE-2015-7223
The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.
CVE-2015-7222
Integer underflow in the Metadata::setData function in MetaData.cpp in ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-7575 Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision. | CVSS3: 5.9 | 3% Низкий | больше 10 лет назад | |
ELSA-2016-0008 ELSA-2016-0008: openssl security update (MODERATE) | 3% Низкий | больше 10 лет назад | ||
ELSA-2016-0007 ELSA-2016-0007: nss security update (MODERATE) | 3% Низкий | больше 10 лет назад | ||
ELSA-2016-0012 ELSA-2016-0012: gnutls security update (MODERATE) | 3% Низкий | больше 10 лет назад | ||
CVE-2015-7575 Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision. | CVSS2: 5.8 | 3% Низкий | больше 10 лет назад | |
openSUSE-SU-2016:0007-1 Security update for MozillaFirefox | 3% Низкий | больше 10 лет назад | ||
openSUSE-SU-2015:2405-1 Security update for mozilla-nss | 3% Низкий | больше 10 лет назад | ||
CVE-2015-7223 The WebExtension APIs in Mozilla Firefox before 43.0 allow remote atta ... | CVSS2: 4 | 2% Низкий | больше 10 лет назад | |
CVE-2015-7223 The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site. | CVSS2: 4 | 2% Низкий | больше 10 лет назад | |
CVE-2015-7222 Integer underflow in the Metadata::setData function in MetaData.cpp in ... | CVSS2: 6.8 | 4% Низкий | больше 10 лет назад |
Уязвимостей на страницу