Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

github логотип

GHSA-r84f-4wj3-r6vx

больше 1 года назад

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-h267-996p-9gjc

больше 1 года назад

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8454-mw8r-4mjq

больше 1 года назад

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-5289-2q6r-6q3g

больше 1 года назад

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2025-27426

больше 1 года назад

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-27426

больше 1 года назад

Malicious websites utilizing a server-side redirect to an internal err ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-27425

больше 1 года назад

Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-27425

больше 1 года назад

Scanning certain QR codes that included text with a website URL could ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-27424

больше 1 года назад

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-27424

больше 1 года назад

Websites redirecting to a non-HTTP scheme URL could allow a website ad ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-r84f-4wj3-r6vx

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-h267-996p-9gjc

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-8454-mw8r-4mjq

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-5289-2q6r-6q3g

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-27426

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-27426

Malicious websites utilizing a server-side redirect to an internal err ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-27425

Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-27425

Scanning certain QR codes that included text with a website URL could ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-27424

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-27424

Websites redirecting to a non-HTTP scheme URL could allow a website ad ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться