Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 220
GHSA-3fxj-qpxv-j6qj
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.
CVE-2024-5702
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5702
Memory corruption in the networking stack could have led to a potentia ...
CVE-2024-5701
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.
CVE-2024-5701
Memory safety bugs present in Firefox 126. Some of these bugs showed e ...
CVE-2024-5700
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5700
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thu ...
CVE-2024-5699
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.
CVE-2024-5699
In violation of spec, cookie prefixes such as `__Secure` were being ig ...
CVE-2024-5698
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-3fxj-qpxv-j6qj By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12. | CVSS3: 4.3 | 2% Низкий | больше 1 года назад | |
CVE-2024-5702 Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-5702 Memory corruption in the networking stack could have led to a potentia ... | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-5701 Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-5701 Memory safety bugs present in Firefox 126. Some of these bugs showed e ... | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-5700 Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 7 | 0% Низкий | больше 1 года назад | |
CVE-2024-5700 Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thu ... | CVSS3: 7 | 0% Низкий | больше 1 года назад | |
CVE-2024-5699 In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-5699 In violation of spec, cookie prefixes such as `__Secure` were being ig ... | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-5698 By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу