Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 299
GHSA-2628-4jvp-96vc
Use-after-free in the Audio/Video: GMP component. This vulnerability affects Firefox < 146.
GHSA-c45v-h9vf-q66x
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6.
GHSA-vxvx-cxrx-x52j
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6.
GHSA-g2fh-3663-3jf8
Use-after-free in the WebRTC: Signaling component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6.
GHSA-4mm6-6c2q-x3fp
Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6.
GHSA-w8g6-3pw6-4hxr
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6.
GHSA-r52p-x88m-mm4j
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6.
GHSA-24pp-jv4q-cp8j
Privilege escalation in the DOM: Notifications component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6.
GHSA-7873-9g8c-6fm2
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6.
CVE-2025-14333
Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-2628-4jvp-96vc Use-after-free in the Audio/Video: GMP component. This vulnerability affects Firefox < 146. | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
GHSA-c45v-h9vf-q66x JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6. | CVSS3: 9.8 | 1% Низкий | 8 месяцев назад | |
GHSA-vxvx-cxrx-x52j Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6. | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
GHSA-g2fh-3663-3jf8 Use-after-free in the WebRTC: Signaling component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6. | CVSS3: 9.8 | 1% Низкий | 8 месяцев назад | |
GHSA-4mm6-6c2q-x3fp Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6. | CVSS3: 8.1 | 0% Низкий | 8 месяцев назад | |
GHSA-w8g6-3pw6-4hxr Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6. | CVSS3: 8 | 0% Низкий | 8 месяцев назад | |
GHSA-r52p-x88m-mm4j JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6. | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
GHSA-24pp-jv4q-cp8j Privilege escalation in the DOM: Notifications component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6. | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
GHSA-7873-9g8c-6fm2 Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 146 and Firefox ESR < 140.6. | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
CVE-2025-14333 Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | CVSS3: 8.1 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу