Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 151
CVE-2025-9180
Same-origin policy bypass in the Graphics: Canvas2D component. This vu ...
CVE-2025-9180
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
CVE-2025-9179
An attacker was able to perform memory corruption in the GMP process w ...
CVE-2025-9179
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
CVE-2025-8364
A crafted URL using a blob: URI could have hidden the true origin of t ...
CVE-2025-8364
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141.
CVE-2025-8042
Firefox for Android allowed a sandboxed iframe without the `allow-down ...
CVE-2025-8042
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.
CVE-2025-8041
In the address bar, Firefox for Android truncated the display of URLs ...
CVE-2025-8041
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-9180 Same-origin policy bypass in the Graphics: Canvas2D component. This vu ... | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-9180 Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-9179 An attacker was able to perform memory corruption in the GMP process w ... | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-9179 An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-8364 A crafted URL using a blob: URI could have hidden the true origin of t ... | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
CVE-2025-8364 A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
CVE-2025-8042 Firefox for Android allowed a sandboxed iframe without the `allow-down ... | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-8042 Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2025-8041 In the address bar, Firefox for Android truncated the display of URLs ... | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2025-8041 In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу