Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 673
CVE-2004-2228
Mozilla Firefox before 1.0 is installed with world-writable permission ...
CVE-2004-1200
Firefox and Mozilla allow remote attackers to cause a denial of servic ...
CVE-2004-2657
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some r ...
CVE-2004-1156
Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attacker ...
CVE-2004-2227
Mozilla Firefox before 1.0 truncates long filenames in the file downlo ...
CVE-2004-1156
Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
CVE-2004-1200
Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
CVE-2004-1156
Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
CVE-2004-0904
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
CVE-2004-2227
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2004-2228 Mozilla Firefox before 1.0 is installed with world-writable permission ... | CVSS2: 7.2 | 0% Низкий | больше 21 года назад | |
CVE-2004-1200 Firefox and Mozilla allow remote attackers to cause a denial of servic ... | CVSS2: 5 | 2% Низкий | больше 21 года назад | |
CVE-2004-2657 Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some r ... | CVSS2: 1.7 | 0% Низкий | больше 21 года назад | |
CVE-2004-1156 Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attacker ... | CVSS2: 4.3 | 1% Низкий | больше 21 года назад | |
CVE-2004-2227 Mozilla Firefox before 1.0 truncates long filenames in the file downlo ... | CVSS2: 5 | 2% Низкий | больше 21 года назад | |
CVE-2004-1156 Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. | CVSS2: 4.3 | 1% Низкий | больше 21 года назад | |
CVE-2004-1200 Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays. | CVSS2: 5 | 2% Низкий | больше 21 года назад | |
CVE-2004-1156 Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. | CVSS2: 4.3 | 1% Низкий | больше 21 года назад | |
CVE-2004-0904 Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows. | CVSS2: 10 | 8% Низкий | больше 21 года назад | |
CVE-2004-2227 Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions. | CVSS2: 5 | 2% Низкий | больше 21 года назад |
Уязвимостей на страницу