Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2024-5691
By tricking the browser with a `X-Frame-Options` header, a sandboxed i ...
CVE-2024-5691
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5690
By monitoring the time certain operations take, an attacker could have ...
CVE-2024-5690
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5689
In addition to detecting when a user was taking a screenshot (XXX), a ...
CVE-2024-5689
In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.
CVE-2024-5688
If a garbage collection was triggered at the right time, a use-after-f ...
CVE-2024-5688
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5687
If a specific sequence of actions is performed when opening a new tab, ...
CVE-2024-5687
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-5691 By tricking the browser with a `X-Frame-Options` header, a sandboxed i ... | CVSS3: 4.7 | 1% Низкий | около 2 лет назад | |
CVE-2024-5691 By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 4.7 | 1% Низкий | около 2 лет назад | |
CVE-2024-5690 By monitoring the time certain operations take, an attacker could have ... | CVSS3: 4.3 | 1% Низкий | около 2 лет назад | |
CVE-2024-5690 By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 4.3 | 1% Низкий | около 2 лет назад | |
CVE-2024-5689 In addition to detecting when a user was taking a screenshot (XXX), a ... | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
CVE-2024-5689 In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
CVE-2024-5688 If a garbage collection was triggered at the right time, a use-after-f ... | CVSS3: 8.1 | 1% Низкий | около 2 лет назад | |
CVE-2024-5688 If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | CVSS3: 8.1 | 1% Низкий | около 2 лет назад | |
CVE-2024-5687 If a specific sequence of actions is performed when opening a new tab, ... | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
CVE-2024-5687 If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу