Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2013-5615
The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ...
CVE-2013-5615
The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors.
CVE-2013-5614
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly ...
CVE-2013-5614
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.
CVE-2013-5613
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove ...
CVE-2013-5613
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.
CVE-2013-5612
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26. ...
CVE-2013-5612
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
CVE-2013-5611
Mozilla Firefox before 26.0 does not properly remove the Application I ...
CVE-2013-5611
Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2013-5615 The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ... | CVSS3: 9.8 | 4% Низкий | больше 12 лет назад | |
CVE-2013-5615 The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors. | CVSS3: 9.8 | 4% Низкий | больше 12 лет назад | |
CVE-2013-5614 Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly ... | CVSS2: 4.3 | 2% Низкий | больше 12 лет назад | |
CVE-2013-5614 Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site. | CVSS2: 4.3 | 2% Низкий | больше 12 лет назад | |
CVE-2013-5613 Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove ... | CVSS3: 9.8 | 9% Низкий | больше 12 лет назад | |
CVE-2013-5613 Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function. | CVSS3: 9.8 | 9% Низкий | больше 12 лет назад | |
CVE-2013-5612 Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26. ... | CVSS2: 4.3 | 3% Низкий | больше 12 лет назад | |
CVE-2013-5612 Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header. | CVSS2: 4.3 | 3% Низкий | больше 12 лет назад | |
CVE-2013-5611 Mozilla Firefox before 26.0 does not properly remove the Application I ... | CVSS2: 5.8 | 2% Низкий | больше 12 лет назад | |
CVE-2013-5611 Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation. | CVSS2: 5.8 | 2% Низкий | больше 12 лет назад |
Уязвимостей на страницу