Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-4502
js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.
CVE-2015-4476
Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.
CVE-2015-4500
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2015-4507
The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.
CVE-2015-4504
The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.
ELSA-2015-1699
ELSA-2015-1699: nss-softokn security update (MODERATE)
ELSA-2015-1694
ELSA-2015-1694: gdk-pixbuf2 security update (MODERATE)
CVE-2015-4498
The add-on installation feature in Mozilla Firefox before 40.0.3 and F ...
CVE-2015-4498
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.
CVE-2015-4497
Use-after-free vulnerability in the CanvasRenderingContext2D implement ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-4502 js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site. | CVSS2: 4.3 | 2% Низкий | почти 11 лет назад | |
CVE-2015-4476 Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute. | CVSS2: 5 | 2% Низкий | почти 11 лет назад | |
CVE-2015-4500 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | CVSS2: 6.8 | 5% Низкий | почти 11 лет назад | |
CVE-2015-4507 The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site. | CVSS2: 5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4504 The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image. | CVSS2: 5.8 | 3% Низкий | почти 11 лет назад | |
ELSA-2015-1699 ELSA-2015-1699: nss-softokn security update (MODERATE) | 4% Низкий | почти 11 лет назад | ||
ELSA-2015-1694 ELSA-2015-1694: gdk-pixbuf2 security update (MODERATE) | 8% Низкий | почти 11 лет назад | ||
CVE-2015-4498 The add-on installation feature in Mozilla Firefox before 40.0.3 and F ... | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4498 The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process. | CVSS2: 7.5 | 3% Низкий | почти 11 лет назад | |
CVE-2015-4497 Use-after-free vulnerability in the CanvasRenderingContext2D implement ... | CVSS2: 10 | 8% Низкий | почти 11 лет назад |
Уязвимостей на страницу