Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

github логотип

GHSA-7f3m-mqm5-5x2c

около 1 года назад

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43h2-r954-f6w6

около 1 года назад

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox < 140.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-87mm-rg9r-h8wm

около 1 года назад

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-frfp-c23m-c888

около 1 года назад

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability affects Firefox < 140.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-fvqv-c5hj-jcrp

около 1 года назад

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `&lt;embed&gt;` or `&lt;object&gt;` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34r6-q8c8-23mx

около 1 года назад

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9x34-3cq7-4hf6

около 1 года назад

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-8r38-4g4q-hgvw

около 1 года назад

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-823q-pcrj-c4xv

около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-87c4-94w2-rw7j

около 1 года назад

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-7f3m-mqm5-5x2c

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-43h2-r954-f6w6

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox < 140.

CVSS3: 8.6
0%
Низкий
около 1 года назад
github логотип
GHSA-87mm-rg9r-h8wm

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-frfp-c23m-c888

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability affects Firefox < 140.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-fvqv-c5hj-jcrp

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `&lt;embed&gt;` or `&lt;object&gt;` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-34r6-q8c8-23mx

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-9x34-3cq7-4hf6

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-8r38-4g4q-hgvw

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-823q-pcrj-c4xv

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

CVSS3: 9.1
0%
Низкий
около 1 года назад
github логотип
GHSA-87c4-94w2-rw7j

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12.

CVSS3: 9.8
3%
Низкий
около 1 года назад

Уязвимостей на страницу


Поделиться