Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-4488
Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment.
CVE-2015-4487
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, ...
CVE-2015-4487
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
CVE-2015-4486
The decrease_ref_count function in libvpx in Mozilla Firefox before 40 ...
CVE-2015-4486
The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed WebM video data.
CVE-2015-4485
Heap-based buffer overflow in the resize_context_buffers function in l ...
CVE-2015-4485
Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data.
CVE-2015-4484
The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript ...
CVE-2015-4484
The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.
CVE-2015-4483
Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypa ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-4488 Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment. | CVSS2: 7.5 | 4% Низкий | около 11 лет назад | |
CVE-2015-4487 The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, ... | CVSS2: 7.5 | 4% Низкий | около 11 лет назад | |
CVE-2015-4487 The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow." | CVSS2: 7.5 | 4% Низкий | около 11 лет назад | |
CVE-2015-4486 The decrease_ref_count function in libvpx in Mozilla Firefox before 40 ... | CVSS2: 10 | 7% Низкий | около 11 лет назад | |
CVE-2015-4486 The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed WebM video data. | CVSS2: 10 | 7% Низкий | около 11 лет назад | |
CVE-2015-4485 Heap-based buffer overflow in the resize_context_buffers function in l ... | CVSS2: 10 | 8% Низкий | около 11 лет назад | |
CVE-2015-4485 Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data. | CVSS2: 10 | 8% Низкий | около 11 лет назад | |
CVE-2015-4484 The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript ... | CVSS2: 5 | 4% Низкий | около 11 лет назад | |
CVE-2015-4484 The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object. | CVSS2: 5 | 4% Низкий | около 11 лет назад | |
CVE-2015-4483 Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypa ... | CVSS2: 4.3 | 2% Низкий | около 11 лет назад |
Уязвимостей на страницу