Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2024-26282
Using an AMP url with a canonical element, an attacker could have exec ...
CVE-2024-26281
Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.
CVE-2024-26281
Upon scanning a JavaScript URI with the QR code scanner, an attacker c ...
SUSE-SU-2024:0579-1
Security update for mozilla-nss
SUSE-SU-2024:0578-1
Security update for mozilla-nss
GHSA-wp8h-p32h-fwvc
The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123.
GHSA-gqrh-wgmr-mm7v
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.
GHSA-8q5j-74vg-j4hr
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.
GHSA-j6qq-7xp7-c5p5
When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.
GHSA-625h-2cj8-8g77
Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-26282 Using an AMP url with a canonical element, an attacker could have exec ... | CVSS3: 7.1 | 0% Низкий | почти 2 года назад | |
CVE-2024-26281 Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123. | CVSS3: 4.7 | 0% Низкий | почти 2 года назад | |
CVE-2024-26281 Upon scanning a JavaScript URI with the QR code scanner, an attacker c ... | CVSS3: 4.7 | 0% Низкий | почти 2 года назад | |
SUSE-SU-2024:0579-1 Security update for mozilla-nss | 0% Низкий | почти 2 года назад | ||
SUSE-SU-2024:0578-1 Security update for mozilla-nss | 0% Низкий | почти 2 года назад | ||
GHSA-wp8h-p32h-fwvc The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-gqrh-wgmr-mm7v The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123. | CVSS3: 9.8 | 0% Низкий | почти 2 года назад | |
GHSA-8q5j-74vg-j4hr A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8. | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-j6qq-7xp7-c5p5 When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123. | CVSS3: 8.3 | 0% Низкий | почти 2 года назад | |
GHSA-625h-2cj8-8g77 Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123. | CVSS3: 8.1 | 1% Низкий | почти 2 года назад |
Уязвимостей на страницу