Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2024-6613
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6612
CSP violations generated links in the console tab of the developer too ...
CVE-2024-6612
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6611
A nested iframe, triggering a cross-site navigation, could send SameSi ...
CVE-2024-6611
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6610
Form validation popups could capture escape key presses. Therefore, sp ...
CVE-2024-6610
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6609
When almost out-of-memory an elliptic curve key which was never alloca ...
CVE-2024-6609
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6608
It was possible to move the cursor using pointerlock from an iframe. T ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-6613 The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-6612 CSP violations generated links in the console tab of the developer too ... | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
CVE-2024-6612 CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
CVE-2024-6611 A nested iframe, triggering a cross-site navigation, could send SameSi ... | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
CVE-2024-6611 A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
CVE-2024-6610 Form validation popups could capture escape key presses. Therefore, sp ... | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
CVE-2024-6610 Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
CVE-2024-6609 When almost out-of-memory an elliptic curve key which was never alloca ... | CVSS3: 8.8 | 1% Низкий | около 2 лет назад | |
CVE-2024-6609 When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128. | CVSS3: 8.8 | 1% Низкий | около 2 лет назад | |
CVE-2024-6608 It was possible to move the cursor using pointerlock from an iframe. T ... | CVSS3: 4.3 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу