Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 225
CVE-2023-5174
If Windows failed to duplicate a handle during process creation, the s ...
CVE-2023-5173
In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.
CVE-2023-5173
In a non-standard configuration of Firefox, an integer overflow could ...
CVE-2023-5172
A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.
CVE-2023-5172
A hashtable in the Ion Engine could have been mutated while there was ...
CVE-2023-5171
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
CVE-2023-5171
During Ion compilation, a Garbage Collection could have resulted in a ...
CVE-2023-5170
In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.
CVE-2023-5170
In canvas rendering, a compromised content process could have caused a ...
CVE-2023-5169
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-5174 If Windows failed to duplicate a handle during process creation, the s ... | CVSS3: 9.8 | 0% Низкий | около 2 лет назад | |
CVE-2023-5173 In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-5173 In a non-standard configuration of Firefox, an integer overflow could ... | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-5172 A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118. | CVSS3: 9.8 | 0% Низкий | около 2 лет назад | |
CVE-2023-5172 A hashtable in the Ion Engine could have been mutated while there was ... | CVSS3: 9.8 | 0% Низкий | около 2 лет назад | |
CVE-2023-5171 During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-5171 During Ion compilation, a Garbage Collection could have resulted in a ... | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-5170 In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118. | CVSS3: 7.4 | 0% Низкий | около 2 лет назад | |
CVE-2023-5170 In canvas rendering, a compromised content process could have caused a ... | CVSS3: 7.4 | 0% Низкий | около 2 лет назад | |
CVE-2023-5169 A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу