Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-0815
Multiple unspecified vulnerabilities in the browser engine in Mozilla ...
CVE-2015-0815
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2015-0814
Multiple unspecified vulnerabilities in the browser engine in Mozilla ...
CVE-2015-0814
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2015-0813
Use-after-free vulnerability in the AppendElements function in Mozilla ...
CVE-2015-0813
Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.
CVE-2015-0812
Mozilla Firefox before 37.0 does not require an HTTPS session for ligh ...
CVE-2015-0812
Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.
CVE-2015-0811
The QCMS implementation in Mozilla Firefox before 37.0 allows remote a ...
CVE-2015-0811
The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-0815 Multiple unspecified vulnerabilities in the browser engine in Mozilla ... | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0815 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0814 Multiple unspecified vulnerabilities in the browser engine in Mozilla ... | CVSS2: 7.5 | 5% Низкий | больше 11 лет назад | |
CVE-2015-0814 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | CVSS2: 7.5 | 5% Низкий | больше 11 лет назад | |
CVE-2015-0813 Use-after-free vulnerability in the AppendElements function in Mozilla ... | CVSS2: 5.1 | 5% Низкий | больше 11 лет назад | |
CVE-2015-0813 Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file. | CVSS2: 5.1 | 5% Низкий | больше 11 лет назад | |
CVE-2015-0812 Mozilla Firefox before 37.0 does not require an HTTPS session for ligh ... | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0812 Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain. | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0811 The QCMS implementation in Mozilla Firefox before 37.0 allows remote a ... | CVSS2: 6.4 | 3% Низкий | больше 11 лет назад | |
CVE-2015-0811 The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation. | CVSS2: 6.4 | 3% Низкий | больше 11 лет назад |
Уязвимостей на страницу