Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 304
CVE-2011-3004
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.
CVE-2011-3004
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey b ...
CVE-2011-3003
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unspecified WebGL test case that triggers a memory-allocation error and a resulting out-of-bounds write operation.
CVE-2011-3003
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attac ...
CVE-2011-3002
Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a memory-allocation error and a resulting buffer overflow.
CVE-2011-3002
Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefo ...
CVE-2011-3001
Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.
CVE-2011-3001
Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey b ...
CVE-2011-3000
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
CVE-2011-3000
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7. ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2011-3004 The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior. | CVSS2: 4.3 | 1% Низкий | почти 15 лет назад | |
CVE-2011-3004 The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey b ... | CVSS2: 4.3 | 1% Низкий | почти 15 лет назад | |
CVE-2011-3003 Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unspecified WebGL test case that triggers a memory-allocation error and a resulting out-of-bounds write operation. | CVSS2: 10 | 4% Низкий | почти 15 лет назад | |
CVE-2011-3003 Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attac ... | CVSS2: 10 | 4% Низкий | почти 15 лет назад | |
CVE-2011-3002 Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a memory-allocation error and a resulting buffer overflow. | CVSS2: 9.3 | 3% Низкий | почти 15 лет назад | |
CVE-2011-3002 Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefo ... | CVSS2: 9.3 | 3% Низкий | почти 15 лет назад | |
CVE-2011-3001 Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error. | CVSS2: 4.3 | 1% Низкий | почти 15 лет назад | |
CVE-2011-3001 Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey b ... | CVSS2: 4.3 | 1% Низкий | почти 15 лет назад | |
CVE-2011-3000 Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values. | CVSS2: 4.3 | 2% Низкий | почти 15 лет назад | |
CVE-2011-3000 Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7. ... | CVSS2: 4.3 | 2% Низкий | почти 15 лет назад |
Уязвимостей на страницу