Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 151
CVE-2025-6430
When a file download is specified via the `Content-Disposition` header ...
CVE-2025-6429
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
CVE-2025-6429
Firefox could have incorrectly parsed a URL and rewritten it to the yo ...
CVE-2025-6428
When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.
CVE-2025-6428
When a URL was provided in a link querystring parameter, Firefox for A ...
CVE-2025-6427
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.
CVE-2025-6427
An attacker was able to bypass the `connect-src` directive of a Conten ...
CVE-2025-6426
The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
CVE-2025-6426
The executable file warning did not warn users before opening files wi ...
CVE-2025-6425
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-6430 When a file download is specified via the `Content-Disposition` header ... | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6429 Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6429 Firefox could have incorrectly parsed a URL and rewritten it to the yo ... | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6428 When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140. | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6428 When a URL was provided in a link querystring parameter, Firefox for A ... | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6427 An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140. | CVSS3: 9.1 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6427 An attacker was able to bypass the `connect-src` directive of a Conten ... | CVSS3: 9.1 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6426 The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6426 The executable file warning did not warn users before opening files wi ... | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2025-6425 An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу