Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-2716
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
CVE-2015-2715
Race condition in the nsThreadManager::RegisterCurrentThread function ...
CVE-2015-2715
Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) by leveraging improper Media Decoder Thread creation at the time of a shutdown.
CVE-2015-2714
Mozilla Firefox before 38.0 on Android does not properly restrict writ ...
CVE-2015-2714
Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.
CVE-2015-2713
Use-after-free vulnerability in the SetBreaks function in Mozilla Fire ...
CVE-2015-2713
Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence containing properties related to vertical text.
CVE-2015-2712
The asm.js implementation in Mozilla Firefox before 38.0 does not prop ...
CVE-2015-2712
The asm.js implementation in Mozilla Firefox before 38.0 does not properly determine heap lengths during identification of cases in which bounds checking may be safely skipped, which allows remote attackers to trigger out-of-bounds write operations and possibly execute arbitrary code, or trigger out-of-bounds read operations and possibly obtain sensitive information from process memory, via crafted JavaScript.
CVE-2015-2711
Mozilla Firefox before 38.0 does not recognize a referrer policy deliv ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-2716 Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283. | CVSS2: 7.5 | 7% Низкий | больше 11 лет назад | |
CVE-2015-2715 Race condition in the nsThreadManager::RegisterCurrentThread function ... | CVSS2: 6.8 | 2% Низкий | больше 11 лет назад | |
CVE-2015-2715 Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) by leveraging improper Media Decoder Thread creation at the time of a shutdown. | CVSS2: 6.8 | 2% Низкий | больше 11 лет назад | |
CVE-2015-2714 Mozilla Firefox before 38.0 on Android does not properly restrict writ ... | CVSS2: 2.1 | 0% Низкий | больше 11 лет назад | |
CVE-2015-2714 Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier. | CVSS2: 2.1 | 0% Низкий | больше 11 лет назад | |
CVE-2015-2713 Use-after-free vulnerability in the SetBreaks function in Mozilla Fire ... | CVSS2: 6.8 | 4% Низкий | больше 11 лет назад | |
CVE-2015-2713 Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence containing properties related to vertical text. | CVSS2: 6.8 | 4% Низкий | больше 11 лет назад | |
CVE-2015-2712 The asm.js implementation in Mozilla Firefox before 38.0 does not prop ... | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-2712 The asm.js implementation in Mozilla Firefox before 38.0 does not properly determine heap lengths during identification of cases in which bounds checking may be safely skipped, which allows remote attackers to trigger out-of-bounds write operations and possibly execute arbitrary code, or trigger out-of-bounds read operations and possibly obtain sensitive information from process memory, via crafted JavaScript. | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-2711 Mozilla Firefox before 38.0 does not recognize a referrer policy deliv ... | CVSS2: 4.3 | 2% Низкий | больше 11 лет назад |
Уязвимостей на страницу