Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 299
BDU:2026-06188
Уязвимость компонента UI веб-браузера Firefox, почтового клиента Thunderbird, позволяющая нарушителю получить доступ к конфиденциальным данным
BDU:2026-06193
Уязвимость компонента GC веб-браузера Firefox, почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2026:20253-1
Security update for MozillaFirefox
GHSA-jwv5-943c-f5wh
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1.
GHSA-c99q-x737-hc5j
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, and Firefox ESR < 115.32.1.
CVE-2026-2447
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
CVE-2026-2447
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefo ...
CVE-2026-2032
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1.
CVE-2026-2032
Malicious scripts that interrupt new tab page loading could cause desy ...
CVE-2026-2447
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2026-06188 Уязвимость компонента UI веб-браузера Firefox, почтового клиента Thunderbird, позволяющая нарушителю получить доступ к конфиденциальным данным | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
BDU:2026-06193 Уязвимость компонента GC веб-браузера Firefox, почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 9.8 | 0% Низкий | 5 месяцев назад | |
openSUSE-SU-2026:20253-1 Security update for MozillaFirefox | 1% Низкий | 6 месяцев назад | ||
GHSA-jwv5-943c-f5wh Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability affects Firefox for iOS < 147.2.1. | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
GHSA-c99q-x737-hc5j Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, and Firefox ESR < 115.32.1. | CVSS3: 8.8 | 1% Низкий | 6 месяцев назад | |
CVE-2026-2447 Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2. | CVSS3: 8.8 | 1% Низкий | 6 месяцев назад | |
CVE-2026-2447 Heap buffer overflow in libvpx. This vulnerability was fixed in Firefo ... | CVSS3: 8.8 | 1% Низкий | 6 месяцев назад | |
CVE-2026-2032 Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1. | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-2032 Malicious scripts that interrupt new tab page loading could cause desy ... | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
CVE-2026-2447 Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2. | CVSS3: 8.8 | 1% Низкий | 6 месяцев назад |
Уязвимостей на страницу