Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2024-4766
Different techniques existed to obscure the fullscreen notification in ...
CVE-2024-4765
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
CVE-2024-4765
Web application manifests were stored by using an insecure MD5 hash wh ...
CVE-2024-4764
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.
CVE-2024-4764
Multiple WebRTC threads could have claimed a newly connected audio inp ...
CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would al ...
CVE-2024-4774
The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.
CVE-2024-4764
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.
CVE-2024-4766
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-4766 Different techniques existed to obscure the fullscreen notification in ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-4765 Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126. | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-4765 Web application manifests were stored by using an insecure MD5 hash wh ... | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-4764 Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-4764 Multiple WebRTC threads could have claimed a newly connected audio inp ... | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-4367 A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. | CVSS3: 8.8 | 35% Средний | больше 1 года назад | |
CVE-2024-4367 A type check was missing when handling fonts in PDF.js, which would al ... | CVSS3: 8.8 | 35% Средний | больше 1 года назад | |
CVE-2024-4774 The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-4764 Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-4766 Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу