Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 304
GHSA-r84f-4wj3-r6vx
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.
GHSA-h267-996p-9gjc
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.
GHSA-8454-mw8r-4mjq
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.
GHSA-5289-2q6r-6q3g
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.
CVE-2025-27426
Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.
CVE-2025-27426
Malicious websites utilizing a server-side redirect to an internal err ...
CVE-2025-27425
Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.
CVE-2025-27425
Scanning certain QR codes that included text with a website URL could ...
CVE-2025-27424
Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.
CVE-2025-27424
Websites redirecting to a non-HTTP scheme URL could allow a website ad ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-r84f-4wj3-r6vx On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8. | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
GHSA-h267-996p-9gjc An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-8454-mw8r-4mjq It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-5289-2q6r-6q3g On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2025-27426 Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
CVE-2025-27426 Malicious websites utilizing a server-side redirect to an internal err ... | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
CVE-2025-27425 Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-27425 Scanning certain QR codes that included text with a website URL could ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-27424 Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-27424 Websites redirecting to a non-HTTP scheme URL could allow a website ad ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу