Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-7196
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a J ...
CVE-2015-7196
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (incorrect garbage collection and application crash) or possibly execute arbitrary code via a crafted Java applet that deallocates an in-use JavaScript wrapper.
CVE-2015-7195
The URL parsing implementation in Mozilla Firefox before 42.0 improper ...
CVE-2015-7195
The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect.
CVE-2015-7194
Buffer underflow in libjar in Mozilla Firefox before 42.0 and Firefox ...
CVE-2015-7194
Buffer underflow in libjar in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP archive.
CVE-2015-7193
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperl ...
CVE-2015-7193
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.
CVE-2015-7192
The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X ...
CVE-2015-7192
The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of the TABLE element, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using an NSAccessibilityIndexAttribute value to reference a row index.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-7196 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a J ... | CVSS2: 6.8 | 4% Низкий | почти 11 лет назад | |
CVE-2015-7196 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (incorrect garbage collection and application crash) or possibly execute arbitrary code via a crafted Java applet that deallocates an in-use JavaScript wrapper. | CVSS2: 6.8 | 4% Низкий | почти 11 лет назад | |
CVE-2015-7195 The URL parsing implementation in Mozilla Firefox before 42.0 improper ... | CVSS2: 5 | 2% Низкий | почти 11 лет назад | |
CVE-2015-7195 The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect. | CVSS2: 5 | 2% Низкий | почти 11 лет назад | |
CVE-2015-7194 Buffer underflow in libjar in Mozilla Firefox before 42.0 and Firefox ... | CVSS2: 7.5 | 4% Низкий | почти 11 лет назад | |
CVE-2015-7194 Buffer underflow in libjar in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP archive. | CVSS2: 7.5 | 4% Низкий | почти 11 лет назад | |
CVE-2015-7193 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperl ... | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-7193 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step. | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-7192 The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X ... | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-7192 The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of the TABLE element, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using an NSAccessibilityIndexAttribute value to reference a row index. | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад |
Уязвимостей на страницу