Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-7186
Mozilla Firefox before 42.0 on Android allows user-assisted remote att ...
CVE-2015-7186
Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document.
CVE-2015-7185
Mozilla Firefox before 42.0 on Android does not ensure that the addres ...
CVE-2015-7185
Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.
CVE-2015-7183
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape P ...
CVE-2015-7183
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
CVE-2015-7182
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Sec ...
CVE-2015-7182
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
CVE-2015-7181
The sec_asn1d_parse_leaf function in Mozilla Network Security Services ...
CVE-2015-7181
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-7186 Mozilla Firefox before 42.0 on Android allows user-assisted remote att ... | CVSS2: 4.3 | 2% Низкий | почти 11 лет назад | |
CVE-2015-7186 Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document. | CVSS2: 4.3 | 2% Низкий | почти 11 лет назад | |
CVE-2015-7185 Mozilla Firefox before 42.0 on Android does not ensure that the addres ... | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад | |
CVE-2015-7185 Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code. | CVSS2: 4.3 | 1% Низкий | почти 11 лет назад | |
CVE-2015-7183 Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape P ... | CVSS2: 7.5 | 7% Низкий | почти 11 лет назад | |
CVE-2015-7183 Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors. | CVSS2: 7.5 | 7% Низкий | почти 11 лет назад | |
CVE-2015-7182 Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Sec ... | CVSS3: 9.8 | 10% Средний | почти 11 лет назад | |
CVE-2015-7182 Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data. | CVSS3: 9.8 | 10% Средний | почти 11 лет назад | |
CVE-2015-7181 The sec_asn1d_parse_leaf function in Mozilla Network Security Services ... | CVSS2: 7.5 | 8% Низкий | почти 11 лет назад | |
CVE-2015-7181 The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue. | CVSS2: 7.5 | 8% Низкий | почти 11 лет назад |
Уязвимостей на страницу