Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
GHSA-6f82-r7wj-8fxf
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.
GHSA-hf5c-hjgx-rmrw
It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.
GHSA-p6gp-c388-p4cr
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.
GHSA-hjxq-w2ww-jfj3
A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.
GHSA-xc66-q4x2-cwqx
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.
GHSA-8564-m639-jh8r
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.
GHSA-xc8j-mr73-m6wv
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
GHSA-pc7c-2483-8558
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.
GHSA-p6j5-jrmm-j3w6
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.
CVE-2024-3865
Memory safety bugs present in Firefox 124. Some of these bugs showed e ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-6f82-r7wj-8fxf On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10. | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
GHSA-hf5c-hjgx-rmrw It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-p6gp-c388-p4cr There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10. | CVSS3: 3.7 | 1% Низкий | больше 2 лет назад | |
GHSA-hjxq-w2ww-jfj3 A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-xc66-q4x2-cwqx In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-8564-m639-jh8r The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xc8j-mr73-m6wv In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-pc7c-2483-8558 GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-p6j5-jrmm-j3w6 A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
CVE-2024-3865 Memory safety bugs present in Firefox 124. Some of these bugs showed e ... | CVSS3: 8.1 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу