Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-0810
Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is ...
CVE-2015-0810
Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.
CVE-2015-0808
The webrtc::VPMContentAnalysis::Release function in the WebRTC impleme ...
CVE-2015-0808
The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
CVE-2015-0807
The navigator.sendBeacon implementation in Mozilla Firefox before 37.0 ...
CVE-2015-0807
The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.
CVE-2015-0806
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firef ...
CVE-2015-0806
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content.
CVE-2015-0805
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firef ...
CVE-2015-0805
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors that trigger rendering of 2D graphics content.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-0810 Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is ... | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0810 Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element. | CVSS2: 4.3 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0808 The webrtc::VPMContentAnalysis::Release function in the WebRTC impleme ... | CVSS2: 5 | 3% Низкий | больше 11 лет назад | |
CVE-2015-0808 The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of service (memory corruption) via unspecified vectors. | CVSS2: 5 | 3% Низкий | больше 11 лет назад | |
CVE-2015-0807 The navigator.sendBeacon implementation in Mozilla Firefox before 37.0 ... | CVSS2: 6.8 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0807 The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638. | CVSS2: 6.8 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0806 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firef ... | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0806 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content. | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0805 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firef ... | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0805 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors that trigger rendering of 2D graphics content. | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад |
Уязвимостей на страницу