Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-4517
NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
CVE-2015-4516
Mozilla Firefox before 41.0 allows remote attackers to bypass certain ...
CVE-2015-4516
Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.
CVE-2015-4512
gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux ...
CVE-2015-4512
gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS element to trigger 2D rendering.
CVE-2015-4511
Heap-based buffer overflow in the nestegg_track_codec_data function in ...
CVE-2015-4511
Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.
CVE-2015-4510
Race condition in the WorkerPrivate::NotifyFeatures function in Mozill ...
CVE-2015-4510
Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.
CVE-2015-4509
Use-after-free vulnerability in the HTMLVideoElement interface in Mozi ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-4517 NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4516 Mozilla Firefox before 41.0 allows remote attackers to bypass certain ... | CVSS2: 9.3 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4516 Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs. | CVSS2: 9.3 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4512 gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux ... | CVSS2: 6.4 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4512 gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS element to trigger 2D rendering. | CVSS2: 6.4 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4511 Heap-based buffer overflow in the nestegg_track_codec_data function in ... | CVSS2: 6.8 | 5% Низкий | почти 11 лет назад | |
CVE-2015-4511 Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video. | CVSS2: 6.8 | 5% Низкий | почти 11 лет назад | |
CVE-2015-4510 Race condition in the WorkerPrivate::NotifyFeatures function in Mozill ... | CVSS2: 6.8 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4510 Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation. | CVSS2: 6.8 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4509 Use-after-free vulnerability in the HTMLVideoElement interface in Mozi ... | CVSS2: 7.5 | 6% Низкий | почти 11 лет назад |
Уязвимостей на страницу