Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2024-5696
By manipulating the text in an `<input>` tag, an attacker could ...
CVE-2024-5696
By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5695
If an out-of-memory condition occurs at a specific point using allocat ...
CVE-2024-5695
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
CVE-2024-5694
An attacker could have caused a use-after-free in the JavaScript engin ...
CVE-2024-5694
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.
CVE-2024-5693
Offscreen Canvas did not properly track cross-origin tainting, which c ...
CVE-2024-5693
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5692
On Windows 10, when using the 'Save As' functionality, an attacker cou ...
CVE-2024-5692
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-5696 By manipulating the text in an `<input>` tag, an attacker could ... | CVSS3: 8.6 | 1% Низкий | около 2 лет назад | |
CVE-2024-5696 By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 8.6 | 1% Низкий | около 2 лет назад | |
CVE-2024-5695 If an out-of-memory condition occurs at a specific point using allocat ... | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
CVE-2024-5695 If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
CVE-2024-5694 An attacker could have caused a use-after-free in the JavaScript engin ... | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-5694 An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-5693 Offscreen Canvas did not properly track cross-origin tainting, which c ... | CVSS3: 6.1 | 1% Низкий | около 2 лет назад | |
CVE-2024-5693 Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 6.1 | 1% Низкий | около 2 лет назад | |
CVE-2024-5692 On Windows 10, when using the 'Save As' functionality, an attacker cou ... | CVSS3: 6.5 | 1% Низкий | около 2 лет назад | |
CVE-2024-5692 On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 6.5 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу