Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 14 782
CVE-2025-49709
Certain canvas operations could have lead to memory corruption. This v ...

CVE-2025-49710
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4.

CVE-2025-49709
Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4.

BDU:2025-07758
Уязвимость компонента Canvas Handler браузера Mozilla Firefox, позволяющая нарушителю выполнить произвольный код

BDU:2025-07759
Уязвимость компонента OrderedHashTable браузеров Mozilla Firefox, позволяющая нарушителю выполнить произвольный код
GHSA-h36q-jch3-f9mw
Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139.
GHSA-fjj5-r59g-88g7
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.
GHSA-xv7q-j96c-5r6v
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.
GHSA-hf6r-227w-qwf9
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139.
GHSA-xg8q-ggjx-6hx2
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
CVE-2025-49709 Certain canvas operations could have lead to memory corruption. This v ... | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад | |
![]() | CVE-2025-49710 An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4. | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад |
![]() | CVE-2025-49709 Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4. | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад |
![]() | BDU:2025-07758 Уязвимость компонента Canvas Handler браузера Mozilla Firefox, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад |
![]() | BDU:2025-07759 Уязвимость компонента OrderedHashTable браузеров Mozilla Firefox, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад |
GHSA-h36q-jch3-f9mw Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139. | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
GHSA-fjj5-r59g-88g7 Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11. | CVSS3: 4.8 | 0% Низкий | 2 месяца назад | |
GHSA-xv7q-j96c-5r6v Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-hf6r-227w-qwf9 In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-xg8q-ggjx-6hx2 A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11. | CVSS3: 5.4 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу