Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2023-6872
Browser tab titles were being leaked by GNOME to system logs. This cou ...
CVE-2023-6871
Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121.
CVE-2023-6871
Under certain conditions, Firefox did not display a warning when a use ...
CVE-2023-6870
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
CVE-2023-6870
Applications which spawn a Toast notification in a background thread m ...
CVE-2023-6869
A `<dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.
CVE-2023-6869
A `<dialog>` element could have been manipulated to paint content o ...
CVE-2023-6868
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.
CVE-2023-6868
In some instances, the user-agent would allow push requests which lack ...
CVE-2023-6867
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-6872 Browser tab titles were being leaked by GNOME to system logs. This cou ... | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-6871 Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
CVE-2023-6871 Under certain conditions, Firefox did not display a warning when a use ... | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
CVE-2023-6870 Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121. | CVSS3: 4.3 | 1% Низкий | около 2 лет назад | |
CVE-2023-6870 Applications which spawn a Toast notification in a background thread m ... | CVSS3: 4.3 | 1% Низкий | около 2 лет назад | |
CVE-2023-6869 A `<dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-6869 A `<dialog>` element could have been manipulated to paint content o ... | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-6868 In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
CVE-2023-6868 In some instances, the user-agent would allow push requests which lack ... | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
CVE-2023-6867 The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121. | CVSS3: 6.1 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу