Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2012-4213
Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
CVE-2012-4212
Use-after-free vulnerability in the XPCWrappedNative::Mark function in ...
CVE-2012-4212
Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
CVE-2012-4210
The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10. ...
CVE-2012-4210
The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted stylesheet.
CVE-2012-4209
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderb ...
CVE-2012-4209
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a binary plugin.
CVE-2012-4208
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunder ...
CVE-2012-4208
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.
CVE-2012-4207
The HZ-GB-2312 character-set implementation in Mozilla Firefox before ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2012-4213 Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. | CVSS2: 9.3 | 6% Низкий | больше 13 лет назад | |
CVE-2012-4212 Use-after-free vulnerability in the XPCWrappedNative::Mark function in ... | CVSS2: 10 | 6% Низкий | больше 13 лет назад | |
CVE-2012-4212 Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. | CVSS2: 10 | 6% Низкий | больше 13 лет назад | |
CVE-2012-4210 The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10. ... | CVSS2: 9.3 | 4% Низкий | больше 13 лет назад | |
CVE-2012-4210 The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted stylesheet. | CVSS2: 9.3 | 4% Низкий | больше 13 лет назад | |
CVE-2012-4209 Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderb ... | CVSS2: 4.3 | 3% Низкий | больше 13 лет назад | |
CVE-2012-4209 Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a binary plugin. | CVSS2: 4.3 | 3% Низкий | больше 13 лет назад | |
CVE-2012-4208 The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunder ... | CVSS2: 4.3 | 2% Низкий | больше 13 лет назад | |
CVE-2012-4208 The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site. | CVSS2: 4.3 | 2% Низкий | больше 13 лет назад | |
CVE-2012-4207 The HZ-GB-2312 character-set implementation in Mozilla Firefox before ... | CVSS2: 4.3 | 3% Низкий | больше 13 лет назад |
Уязвимостей на страницу