Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-7191
Mozilla Firefox before 42.0 on Android improperly restricts URL string ...
CVE-2015-7191
Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka "Universal XSS (UXSS)."
CVE-2015-7190
The Search feature in Mozilla Firefox before 42.0 on Android through 4 ...
CVE-2015-7190
The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application.
CVE-2015-7189
Race condition in the JPEGEncoder function in Mozilla Firefox before 4 ...
CVE-2015-7189
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
CVE-2015-7188
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow rem ...
CVE-2015-7188
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string.
CVE-2015-7187
The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: ...
CVE-2015-7187
The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-7191 Mozilla Firefox before 42.0 on Android improperly restricts URL string ... | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад | |
CVE-2015-7191 Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka "Universal XSS (UXSS)." | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад | |
CVE-2015-7190 The Search feature in Mozilla Firefox before 42.0 on Android through 4 ... | CVSS2: 5 | 1% Низкий | почти 11 лет назад | |
CVE-2015-7190 The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application. | CVSS2: 5 | 1% Низкий | почти 11 лет назад | |
CVE-2015-7189 Race condition in the JPEGEncoder function in Mozilla Firefox before 4 ... | CVSS2: 6.8 | 3% Низкий | почти 11 лет назад | |
CVE-2015-7189 Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code. | CVSS2: 6.8 | 3% Низкий | почти 11 лет назад | |
CVE-2015-7188 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow rem ... | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-7188 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string. | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-7187 The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: ... | CVSS2: 4.3 | 2% Низкий | почти 11 лет назад | |
CVE-2015-7187 The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension. | CVSS2: 4.3 | 2% Низкий | почти 11 лет назад |
Уязвимостей на страницу