Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
GHSA-xcm3-jhmr-9fhh
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128.
GHSA-hr59-q2gm-7hrj
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128.
GHSA-j476-hf2q-984g
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
GHSA-vr96-9xq4-q4jp
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128.
GHSA-cpm6-fp82-cq6m
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128.
GHSA-r595-x79c-68p4
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128.
GHSA-3wq7-w8r7-pmvh
Clipboard code failed to check the index on an array access. This could have lead to an out-of-bounds read. This vulnerability affects Firefox < 128.
GHSA-fj5c-r5jw-5wp8
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128.
GHSA-cpfv-mr66-74v6
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
GHSA-v6r5-wp7h-cj77
A mismatch between allocator and deallocator could have lead to memory corruption. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-xcm3-jhmr-9fhh When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128. | CVSS3: 8.8 | 1% Низкий | около 2 лет назад | |
GHSA-hr59-q2gm-7hrj A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
GHSA-j476-hf2q-984g In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13. | CVSS3: 7.4 | 1% Низкий | около 2 лет назад | |
GHSA-vr96-9xq4-q4jp It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-cpm6-fp82-cq6m CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
GHSA-r595-x79c-68p4 Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-3wq7-w8r7-pmvh Clipboard code failed to check the index on an array access. This could have lead to an out-of-bounds read. This vulnerability affects Firefox < 128. | CVSS3: 9.8 | 0% Низкий | около 2 лет назад | |
GHSA-fj5c-r5jw-5wp8 The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-cpfv-mr66-74v6 Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128. | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
GHSA-v6r5-wp7h-cj77 A mismatch between allocator and deallocator could have lead to memory corruption. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу