Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 304
CVE-2011-2374
Multiple unspecified vulnerabilities in the browser engine in Mozilla ...
CVE-2011-2373
Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when JavaScript is disabled, allows remote attackers to execute arbitrary code via a crafted XUL document.
CVE-2011-2373
Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x ...
CVE-2011-2371
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.
CVE-2011-2371
Integer overflow in the Array.reduceRight method in Mozilla Firefox be ...
CVE-2011-2370
Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote attackers to trigger an installation dialog for a (1) add-on or (2) theme via unspecified vectors.
CVE-2011-2370
Mozilla Firefox before 5.0 does not properly enforce the whitelist for ...
CVE-2011-2369
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.
CVE-2011-2369
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x throug ...
CVE-2011-2368
The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2011-2374 Multiple unspecified vulnerabilities in the browser engine in Mozilla ... | CVSS2: 10 | 5% Низкий | около 15 лет назад | |
CVE-2011-2373 Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when JavaScript is disabled, allows remote attackers to execute arbitrary code via a crafted XUL document. | CVSS2: 7.6 | 5% Низкий | около 15 лет назад | |
CVE-2011-2373 Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x ... | CVSS2: 7.6 | 5% Низкий | около 15 лет назад | |
CVE-2011-2371 Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object. | CVSS2: 10 | 76% Высокий | около 15 лет назад | |
CVE-2011-2371 Integer overflow in the Array.reduceRight method in Mozilla Firefox be ... | CVSS2: 10 | 76% Высокий | около 15 лет назад | |
CVE-2011-2370 Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote attackers to trigger an installation dialog for a (1) add-on or (2) theme via unspecified vectors. | CVSS2: 5 | 1% Низкий | около 15 лет назад | |
CVE-2011-2370 Mozilla Firefox before 5.0 does not properly enforce the whitelist for ... | CVSS2: 5 | 1% Низкий | около 15 лет назад | |
CVE-2011-2369 Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity. | CVSS2: 4.3 | 1% Низкий | около 15 лет назад | |
CVE-2011-2369 Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x throug ... | CVSS2: 4.3 | 1% Низкий | около 15 лет назад | |
CVE-2011-2368 The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. | CVSS2: 10 | 4% Низкий | около 15 лет назад |
Уязвимостей на страницу