Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2024-9399
A website configured to initiate a specially crafted WebTransport sess ...
CVE-2024-9398
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-9398
By checking the result of calls to `window.open` with specifically set ...
CVE-2024-9397
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-9397
A missing delay in directory upload UI could have made it possible for ...
CVE-2024-9396
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-9396
It is currently unknown if this issue is exploitable but a condition m ...
CVE-2024-9395
A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
CVE-2024-9395
A specially crafted filename containing a large number of spaces could ...
CVE-2024-9394
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-9399 A website configured to initiate a specially crafted WebTransport sess ... | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-9398 By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131. | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
CVE-2024-9398 By checking the result of calls to `window.open` with specifically set ... | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
CVE-2024-9397 A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-9397 A missing delay in directory upload UI could have made it possible for ... | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-9396 It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-9396 It is currently unknown if this issue is exploitable but a condition m ... | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-9395 A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-9395 A specially crafted filename containing a large number of spaces could ... | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-9394 An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу