Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2023-23602
A mishandled security check when creating a WebSocket in a WebWorker c ...
CVE-2023-23601
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
CVE-2023-23601
Navigations were being allowed when dragging a URL from a cross-origin ...
CVE-2023-23600
Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109.
CVE-2023-23600
Per origin notification permissions were being stored in a way that di ...
CVE-2023-23599
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
CVE-2023-23599
When copying a network request from the developer tools panel as a cur ...
CVE-2023-23598
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
CVE-2023-23598
Due to the Firefox GTK wrapper code's use of text/plain for drag data ...
CVE-2023-23597
A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This vulnerability affects Firefox < 109.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-23602 A mishandled security check when creating a WebSocket in a WebWorker c ... | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23601 Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23601 Navigations were being allowed when dragging a URL from a cross-origin ... | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23600 Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23600 Per origin notification permissions were being stored in a way that di ... | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23599 When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23599 When copying a network request from the developer tools panel as a cur ... | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23598 Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23598 Due to the Firefox GTK wrapper code's use of text/plain for drag data ... | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-23597 A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This vulnerability affects Firefox < 109. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу