Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 299
CVE-2025-14860
Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.
CVE-2025-14744
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0.
CVE-2025-14861
Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146.0.1.
BDU:2025-16332
Уязвимость компонента интерфейса для людей с ограниченными возможностями браузера Firefox, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2025-16326
Уязвимость браузера Firefox, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код
BDU:2025-16336
Уязвимость компонента Downloads (Загрузки) браузера Firefox операционных систем iOS, позволяющая нарушителю проводить спуфинг-атаки
GHSA-wqgj-c38v-hpmm
Spoofing issue in the Downloads Panel component. This vulnerability affects Firefox < 146.
GHSA-364v-7wgj-4r69
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6.
GHSA-2ghp-fh92-8w9r
Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146.
GHSA-pq76-9m6x-m6mx
Same-origin policy bypass in the Request Handling component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-14860 Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
CVE-2025-14744 Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
CVE-2025-14861 Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146.0.1. | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
BDU:2025-16332 Уязвимость компонента интерфейса для людей с ограниченными возможностями браузера Firefox, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
BDU:2025-16326 Уязвимость браузера Firefox, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
BDU:2025-16336 Уязвимость компонента Downloads (Загрузки) браузера Firefox операционных систем iOS, позволяющая нарушителю проводить спуфинг-атаки | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
GHSA-wqgj-c38v-hpmm Spoofing issue in the Downloads Panel component. This vulnerability affects Firefox < 146. | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
GHSA-364v-7wgj-4r69 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6. | CVSS3: 7.3 | 0% Низкий | 8 месяцев назад | |
GHSA-2ghp-fh92-8w9r Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146. | CVSS3: 7.3 | 0% Низкий | 8 месяцев назад | |
GHSA-pq76-9m6x-m6mx Same-origin policy bypass in the Request Handling component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу