Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
GHSA-x73f-6qwm-hh3x
A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.
GHSA-pw8j-6xcp-c453
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
GHSA-h6xq-j8xx-3fv4
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.
GHSA-vw65-ccrc-xmfw
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
GHSA-7jq7-8r3x-pjjq
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
GHSA-g89w-hcgw-6g9p
Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
GHSA-3568-h36m-7jmf
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
GHSA-jx5w-px6r-88w4
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
GHSA-mvvq-wfcg-vq6m
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
GHSA-jjrm-h8pr-rf2f
An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-x73f-6qwm-hh3x A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-pw8j-6xcp-c453 A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. | CVSS3: 8.8 | 1% Низкий | около 2 лет назад | |
GHSA-h6xq-j8xx-3fv4 Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-vw65-ccrc-xmfw A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-7jq7-8r3x-pjjq In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-g89w-hcgw-6g9p Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. | CVSS3: 8.8 | 1% Низкий | около 2 лет назад | |
GHSA-3568-h36m-7jmf A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-jx5w-px6r-88w4 When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-mvvq-wfcg-vq6m A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
GHSA-jjrm-h8pr-rf2f An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122. | CVSS3: 7.5 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу