Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2024-5693
Offscreen Canvas did not properly track cross-origin tainting, which c ...
CVE-2024-5692
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5692
On Windows 10, when using the 'Save As' functionality, an attacker cou ...
CVE-2024-5691
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5691
By tricking the browser with a `X-Frame-Options` header, a sandboxed i ...
CVE-2024-5690
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5690
By monitoring the time certain operations take, an attacker could have ...
CVE-2024-5689
In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.
CVE-2024-5689
In addition to detecting when a user was taking a screenshot (XXX), a ...
CVE-2024-5688
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-5693 Offscreen Canvas did not properly track cross-origin tainting, which c ... | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
CVE-2024-5692 On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-5692 On Windows 10, when using the 'Save As' functionality, an attacker cou ... | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-5691 By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-5691 By tricking the browser with a `X-Frame-Options` header, a sandboxed i ... | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-5690 By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 4.3 | 4% Низкий | больше 1 года назад | |
CVE-2024-5690 By monitoring the time certain operations take, an attacker could have ... | CVSS3: 4.3 | 4% Низкий | больше 1 года назад | |
CVE-2024-5689 In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127. | CVSS3: 4.3 | 1% Низкий | больше 1 года назад | |
CVE-2024-5689 In addition to detecting when a user was taking a screenshot (XXX), a ... | CVSS3: 4.3 | 1% Низкий | больше 1 года назад | |
CVE-2024-5688 If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 8.1 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу