Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 151
GHSA-3rc5-4jr8-p23m
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141.
GHSA-h3xr-99q8-227g
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks This vulnerability affects Firefox for iOS < 142.
GHSA-86q6-8hr2-487f
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.
GHSA-mv5m-p837-6xm9
'Denial-of-service due to out-of-memory in the Graphics: WebRender component.' This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2.
GHSA-vhcx-3xrg-8hjg
Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2.
GHSA-7379-6rf2-q4f9
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
CVE-2025-9187
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of ...
CVE-2025-9187
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142 and Thunderbird < 142.
CVE-2025-9186
Spoofing issue in the Address Bar component of Firefox Focus for Andro ...
CVE-2025-9186
Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-3rc5-4jr8-p23m In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-h3xr-99q8-227g Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks This vulnerability affects Firefox for iOS < 142. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-86q6-8hr2-487f Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
GHSA-mv5m-p837-6xm9 'Denial-of-service due to out-of-memory in the Graphics: WebRender component.' This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-vhcx-3xrg-8hjg Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-7379-6rf2-q4f9 An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-9187 Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of ... | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-9187 Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142 and Thunderbird < 142. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-9186 Spoofing issue in the Address Bar component of Firefox Focus for Andro ... | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2025-9186 Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу