Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 14 600
GHSA-m2rp-964h-h237
Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.
GHSA-r83v-rmq7-r5m4
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136.
GHSA-m793-xp46-r76w
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.
GHSA-h267-996p-9gjc
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.
GHSA-5289-2q6r-6q3g
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.
CVE-2025-27424
Websites redirecting to a non-HTTP scheme URL could allow a website ad ...

CVE-2025-27424
Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.
CVE-2025-1942
When String.toUpperCase() caused a string to get longer it was possibl ...

CVE-2025-1942
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.
CVE-2025-1941
Under certain circumstances, a user opt-in setting that Focus should r ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-m2rp-964h-h237 Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-r83v-rmq7-r5m4 When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-m793-xp46-r76w Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136. | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
GHSA-h267-996p-9gjc An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
GHSA-5289-2q6r-6q3g On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2025-27424 Websites redirecting to a non-HTTP scheme URL could allow a website ad ... | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
![]() | CVE-2025-27424 Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад |
CVE-2025-1942 When String.toUpperCase() caused a string to get longer it was possibl ... | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
![]() | CVE-2025-1942 When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад |
CVE-2025-1941 Under certain circumstances, a user opt-in setting that Focus should r ... | CVSS3: 9.1 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу