Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
BDU:2015-10028
Уязвимость браузера Firefox, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2015-0799
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 ...
CVE-2015-0799
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.
CVE-2015-0798
The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, a ...
CVE-2015-0798
The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.
CVE-2015-0799
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.
CVE-2015-0799
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.
BDU:2015-09904
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику обойти проверку сертификата
CVE-2015-0816
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunder ...
CVE-2015-0816
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2015-10028 Уязвимость браузера Firefox, позволяющая нарушителю вызвать отказ в обслуживании | CVSS2: 6.8 | 3% Низкий | больше 11 лет назад | |
CVE-2015-0799 The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 ... | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0799 The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header. | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0798 The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, a ... | CVSS2: 5 | 2% Низкий | больше 11 лет назад | |
CVE-2015-0798 The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy. | CVSS2: 5 | 2% Низкий | больше 11 лет назад | |
CVE-2015-0799 The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header. | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0799 The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header. | CVSS2: 5.8 | 1% Низкий | больше 11 лет назад | |
BDU:2015-09904 Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику обойти проверку сертификата | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0816 Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunder ... | CVSS2: 5 | 67% Средний | больше 11 лет назад | |
CVE-2015-0816 Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js. | CVSS2: 5 | 67% Средний | больше 11 лет назад |
Уязвимостей на страницу