Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2024-7531
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
CVE-2024-7531
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer ...
CVE-2024-7530
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
CVE-2024-7530
Incorrect garbage collection interaction could have led to a use-after ...
CVE-2024-7529
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVE-2024-7529
The date picker could partially obscure security prompts. This could b ...
CVE-2024-7528
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVE-2024-7528
Incorrect garbage collection interaction in IndexedDB could have led t ...
CVE-2024-7527
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVE-2024-7527
Unexpected marking work at the start of sweeping could have led to a u ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-7531 Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-7531 Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer ... | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-7530 Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129. | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-7530 Incorrect garbage collection interaction could have led to a use-after ... | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-7529 The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-7529 The date picker could partially obscure security prompts. This could b ... | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-7528 Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-7528 Incorrect garbage collection interaction in IndexedDB could have led t ... | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-7527 Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-7527 Unexpected marking work at the start of sweeping could have led to a u ... | CVSS3: 8.8 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу