Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2024-2614
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVE-2024-2613
Data was not properly sanitized when decoding a QUIC ACK frame; this c ...
CVE-2024-2613
Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.
CVE-2024-2612
If an attacker could find a way to trigger a particular code path in ` ...
CVE-2024-2612
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVE-2024-2611
A missing delay on when pointer lock was used could have allowed a mal ...
CVE-2024-2611
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVE-2024-2610
Using a markup injection an attacker could have stolen nonce values. T ...
CVE-2024-2610
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVE-2024-2609
The permission prompt input delay could expire while the window is not ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-2614 Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2613 Data was not properly sanitized when decoding a QUIC ACK frame; this c ... | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2613 Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2612 If an attacker could find a way to trigger a particular code path in ` ... | CVSS3: 8.1 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2612 If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. | CVSS3: 8.1 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2611 A missing delay on when pointer lock was used could have allowed a mal ... | CVSS3: 5.5 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2611 A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. | CVSS3: 5.5 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2610 Using a markup injection an attacker could have stolen nonce values. T ... | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2610 Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
CVE-2024-2609 The permission prompt input delay could expire while the window is not ... | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу