Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2014-1502
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.
CVE-2014-1501
Mozilla Firefox before 28.0 on Android allows remote attackers to bypa ...
CVE-2014-1501
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
CVE-2014-1500
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote att ...
CVE-2014-1500
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.
CVE-2014-1499
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote att ...
CVE-2014-1499
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
CVE-2014-1498
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 a ...
CVE-2014-1498
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.
CVE-2014-1497
The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox b ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2014-1502 The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors. | CVSS2: 6.8 | 1% Низкий | больше 12 лет назад | |
CVE-2014-1501 Mozilla Firefox before 28.0 on Android allows remote attackers to bypa ... | CVSS2: 5.8 | 2% Низкий | больше 12 лет назад | |
CVE-2014-1501 Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection. | CVSS2: 5.8 | 2% Низкий | больше 12 лет назад | |
CVE-2014-1500 Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote att ... | CVSS2: 5 | 4% Низкий | больше 12 лет назад | |
CVE-2014-1500 Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution. | CVSS2: 5 | 4% Низкий | больше 12 лет назад | |
CVE-2014-1499 Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote att ... | CVSS2: 4.3 | 2% Низкий | больше 12 лет назад | |
CVE-2014-1499 Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt. | CVSS2: 4.3 | 2% Низкий | больше 12 лет назад | |
CVE-2014-1498 The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 a ... | CVSS2: 5 | 2% Низкий | больше 12 лет назад | |
CVE-2014-1498 The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm. | CVSS2: 5 | 2% Низкий | больше 12 лет назад | |
CVE-2014-1497 The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox b ... | CVSS3: 8.8 | 3% Низкий | больше 12 лет назад |
Уязвимостей на страницу