Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 304
CVE-2025-11720
The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.
CVE-2025-11720
The Firefox and Firefox Focus UI for the Android custom tab feature on ...
CVE-2025-11719
Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
CVE-2025-11719
Starting in Thunderbird 143, the use of the native messaging API by we ...
CVE-2025-11718
When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.
CVE-2025-11718
When the address bar was hidden due to scrolling on Android, a malicio ...
CVE-2025-11717
When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability was fixed in Firefox 144.
CVE-2025-11717
When switching between Android apps using the card carousel Firefox sh ...
CVE-2025-11716
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
CVE-2025-11716
Links in a sandboxed iframe could open an external app on Android with ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-11720 The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144. | CVSS3: 8.1 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11720 The Firefox and Firefox Focus UI for the Android custom tab feature on ... | CVSS3: 8.1 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11719 Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | CVSS3: 9.8 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11719 Starting in Thunderbird 143, the use of the native messaging API by we ... | CVSS3: 9.8 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11718 When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11718 When the address bar was hidden due to scrolling on Android, a malicio ... | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11717 When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability was fixed in Firefox 144. | CVSS3: 9.1 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11717 When switching between Android apps using the card carousel Firefox sh ... | CVSS3: 9.1 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11716 Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11716 Links in a sandboxed iframe could open an external app on Android with ... | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу