Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 225
GHSA-68m9-mw54-x3jx
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox < 115.5, and Thunderbird < 115.5.0.
GHSA-c9gw-j4mh-mj26
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox < 115.5, and Thunderbird < 115.5.0.
CVE-2023-6213
Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120.
CVE-2023-6213
Memory safety bugs present in Firefox 119. Some of these bugs showed e ...
CVE-2023-6212
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6212
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thun ...
CVE-2023-6211
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.
CVE-2023-6211
If an attacker needed a user to load an insecure http: page and knew t ...
CVE-2023-6210
When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.
CVE-2023-6210
When an https: web page created a pop-up from a "javascript:" URL, tha ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-68m9-mw54-x3jx The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox < 115.5, and Thunderbird < 115.5.0. | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-c9gw-j4mh-mj26 On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox < 115.5, and Thunderbird < 115.5.0. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-6213 Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120. | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
CVE-2023-6213 Memory safety bugs present in Firefox 119. Some of these bugs showed e ... | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
CVE-2023-6212 Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
CVE-2023-6212 Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thun ... | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
CVE-2023-6211 If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-6211 If an attacker needed a user to load an insecure http: page and knew t ... | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-6210 When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-6210 When an https: web page created a pop-up from a "javascript:" URL, tha ... | CVSS3: 6.5 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу