Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-0832
Mozilla Firefox before 36.0 does not properly recognize the equivalenc ...
CVE-2015-0832
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.
CVE-2015-0831
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObject ...
CVE-2015-0831
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
CVE-2015-0830
The WebGL implementation in Mozilla Firefox before 36.0 does not prope ...
CVE-2015-0830
The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content.
CVE-2015-0829
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allow ...
CVE-2015-0829
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
CVE-2015-0828
Double free vulnerability in the nsXMLHttpRequest::GetResponse functio ...
CVE-2015-0828
Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-0832 Mozilla Firefox before 36.0 does not properly recognize the equivalenc ... | CVSS2: 5 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0832 Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character. | CVSS2: 5 | 1% Низкий | больше 11 лет назад | |
CVE-2015-0831 Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObject ... | CVSS2: 6.8 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0831 Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation. | CVSS2: 6.8 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0830 The WebGL implementation in Mozilla Firefox before 36.0 does not prope ... | CVSS2: 5 | 2% Низкий | больше 11 лет назад | |
CVE-2015-0830 The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content. | CVSS2: 5 | 2% Низкий | больше 11 лет назад | |
CVE-2015-0829 Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allow ... | CVSS2: 6.8 | 6% Низкий | больше 11 лет назад | |
CVE-2015-0829 Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback. | CVSS2: 6.8 | 6% Низкий | больше 11 лет назад | |
CVE-2015-0828 Double free vulnerability in the nsXMLHttpRequest::GetResponse functio ... | CVSS2: 6.8 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0828 Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data. | CVSS2: 6.8 | 4% Низкий | больше 11 лет назад |
Уязвимостей на страницу