Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2015-0827
Heap-based buffer overflow in the mozilla::gfx::CopyRect function in M ...
CVE-2015-0827
Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic.
CVE-2015-0826
The nsTransformedTextRun::SetCapitalization function in Mozilla Firefo ...
CVE-2015-0826
The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascading Style Sheets (CSS) token sequence that triggers a restyle or reflow operation.
CVE-2015-0825
Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuff ...
CVE-2015-0825
Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.
CVE-2015-0824
The mozilla::layers::BufferTextureClient::AllocateForSurface function ...
CVE-2015-0824
The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.
CVE-2015-0823
Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used ...
CVE-2015-0823
Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2015-0827 Heap-based buffer overflow in the mozilla::gfx::CopyRect function in M ... | CVSS2: 4.3 | 3% Низкий | больше 11 лет назад | |
CVE-2015-0827 Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic. | CVSS2: 4.3 | 3% Низкий | больше 11 лет назад | |
CVE-2015-0826 The nsTransformedTextRun::SetCapitalization function in Mozilla Firefo ... | CVSS2: 6.8 | 3% Низкий | больше 11 лет назад | |
CVE-2015-0826 The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascading Style Sheets (CSS) token sequence that triggers a restyle or reflow operation. | CVSS2: 6.8 | 3% Низкий | больше 11 лет назад | |
CVE-2015-0825 Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuff ... | CVSS2: 4.3 | 2% Низкий | больше 11 лет назад | |
CVE-2015-0825 Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback. | CVSS2: 4.3 | 2% Низкий | больше 11 лет назад | |
CVE-2015-0824 The mozilla::layers::BufferTextureClient::AllocateForSurface function ... | CVSS2: 5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0824 The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing. | CVSS2: 5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0823 Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used ... | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад | |
CVE-2015-0823 Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function. | CVSS2: 7.5 | 4% Низкий | больше 11 лет назад |
Уязвимостей на страницу