Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 691
CVE-2011-2984
Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.
CVE-2011-2981
The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
CVE-2011-0084
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
CVE-2011-0084
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox be ...
CVE-2011-2983
Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, ...
CVE-2011-2990
The implementation of Content Security Policy (CSP) violation reports ...
CVE-2011-2988
Buffer overflow in an unspecified string class in the WebGL shader imp ...
CVE-2011-2993
The implementation of digital signatures for JAR files in Mozilla Fire ...
CVE-2011-2987
Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANG ...
CVE-2011-2992
The Ogg reader in the browser engine in Mozilla Firefox 4.x through 5, ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2011-2984 Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events. | CVSS2: 10 | 4% Низкий | около 15 лет назад | |
CVE-2011-2981 The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site. | CVSS2: 9.3 | 2% Низкий | около 15 лет назад | |
CVE-2011-0084 The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer." | CVSS2: 10 | 5% Низкий | около 15 лет назад | |
CVE-2011-0084 The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox be ... | CVSS2: 10 | 5% Низкий | около 15 лет назад | |
CVE-2011-2983 Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, ... | CVSS2: 4.3 | 2% Низкий | около 15 лет назад | |
CVE-2011-2990 The implementation of Content Security Policy (CSP) violation reports ... | CVSS2: 5 | 1% Низкий | около 15 лет назад | |
CVE-2011-2988 Buffer overflow in an unspecified string class in the WebGL shader imp ... | CVSS2: 10 | 5% Низкий | около 15 лет назад | |
CVE-2011-2993 The implementation of digital signatures for JAR files in Mozilla Fire ... | CVSS2: 9.3 | 1% Низкий | около 15 лет назад | |
CVE-2011-2987 Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANG ... | CVSS2: 10 | 5% Низкий | около 15 лет назад | |
CVE-2011-2992 The Ogg reader in the browser engine in Mozilla Firefox 4.x through 5, ... | CVSS2: 10 | 4% Низкий | около 15 лет назад |
Уязвимостей на страницу