Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 220
CVE-2024-5698
By manipulating the fullscreen feature while opening a data-list, an a ...
CVE-2024-5697
A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.
CVE-2024-5697
A website was able to detect when a user took a screenshot of a page u ...
CVE-2024-5696
By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5696
By manipulating the text in an `<input>` tag, an attacker could ...
CVE-2024-5695
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
CVE-2024-5695
If an out-of-memory condition occurs at a specific point using allocat ...
CVE-2024-5694
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.
CVE-2024-5694
An attacker could have caused a use-after-free in the JavaScript engin ...
CVE-2024-5693
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-5698 By manipulating the fullscreen feature while opening a data-list, an a ... | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-5697 A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-5697 A website was able to detect when a user took a screenshot of a page u ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-5696 By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 8.6 | 2% Низкий | больше 1 года назад | |
CVE-2024-5696 By manipulating the text in an `<input>` tag, an attacker could ... | CVSS3: 8.6 | 2% Низкий | больше 1 года назад | |
CVE-2024-5695 If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-5695 If an out-of-memory condition occurs at a specific point using allocat ... | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-5694 An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-5694 An attacker could have caused a use-after-free in the JavaScript engin ... | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-5693 Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу