Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 304
CVE-2025-10859
Cookie storage for non-HTML temporary documents was being shared incor ...
CVE-2025-11153
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.
CVE-2025-11152
Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3.
CVE-2025-11153
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.
BDU:2025-12849
Уязвимость компонента JIT браузера Mozilla Firefox, позволяющая нарушителю выполнить произвольный код
BDU:2025-12848
Уязвимость компонента Canvas2D браузера Mozilla Firefox, связанная с недостатками разграничения доступа изолированной среды, позволяющая нарушителю выполнить произвольный код
GHSA-h6qg-7fq8-gw5h
This vulnerability affects Firefox < 143 and Thunderbird < 143.
GHSA-f2wr-3fjg-j32f
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
GHSA-wjhw-rxqj-2g2h
This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
GHSA-579p-jcg6-h5r2
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-10859 Cookie storage for non-HTML temporary documents was being shared incor ... | CVSS3: 4 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11153 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3. | CVSS3: 7.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11152 Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3. | CVSS3: 8.6 | 0% Низкий | 10 месяцев назад | |
CVE-2025-11153 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3. | 0% Низкий | 10 месяцев назад | ||
BDU:2025-12849 Уязвимость компонента JIT браузера Mozilla Firefox, позволяющая нарушителю выполнить произвольный код | CVSS3: 6.3 | 0% Низкий | 10 месяцев назад | |
BDU:2025-12848 Уязвимость компонента Canvas2D браузера Mozilla Firefox, связанная с недостатками разграничения доступа изолированной среды, позволяющая нарушителю выполнить произвольный код | CVSS3: 6.3 | 0% Низкий | 10 месяцев назад | |
GHSA-h6qg-7fq8-gw5h This vulnerability affects Firefox < 143 and Thunderbird < 143. | CVSS3: 5.4 | 0% Низкий | 11 месяцев назад | |
GHSA-f2wr-3fjg-j32f This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
GHSA-wjhw-rxqj-2g2h This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | CVSS3: 8.8 | 1% Низкий | 11 месяцев назад | |
GHSA-579p-jcg6-h5r2 Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | CVSS3: 8.8 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу