Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2014-1531
Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeig ...
CVE-2014-1531
Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that is not properly handled during an image-resize operation.
CVE-2014-1530
The docshell implementation in Mozilla Firefox before 29.0, Firefox ES ...
CVE-2014-1530
The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.
CVE-2014-1529
The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 2 ...
CVE-2014-1529
The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.
CVE-2014-1528
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo ...
CVE-2014-1528
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.
CVE-2014-1527
Mozilla Firefox before 29.0 on Android allows remote attackers to spoo ...
CVE-2014-1527
Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2014-1531 Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeig ... | CVSS3: 8.8 | 6% Низкий | больше 12 лет назад | |
CVE-2014-1531 Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that is not properly handled during an image-resize operation. | CVSS3: 8.8 | 6% Низкий | больше 12 лет назад | |
CVE-2014-1530 The docshell implementation in Mozilla Firefox before 29.0, Firefox ES ... | CVSS3: 6.1 | 2% Низкий | больше 12 лет назад | |
CVE-2014-1530 The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation. | CVSS3: 6.1 | 2% Низкий | больше 12 лет назад | |
CVE-2014-1529 The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 2 ... | CVSS3: 8.8 | 4% Низкий | больше 12 лет назад | |
CVE-2014-1529 The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted. | CVSS3: 8.8 | 4% Низкий | больше 12 лет назад | |
CVE-2014-1528 The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo ... | CVSS2: 10 | 6% Низкий | больше 12 лет назад | |
CVE-2014-1528 The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element. | CVSS2: 10 | 6% Низкий | больше 12 лет назад | |
CVE-2014-1527 Mozilla Firefox before 29.0 on Android allows remote attackers to spoo ... | CVSS2: 5 | 1% Низкий | больше 12 лет назад | |
CVE-2014-1527 Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen. | CVSS2: 5 | 1% Низкий | больше 12 лет назад |
Уязвимостей на страницу