Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2024-26282
Using an AMP url with a canonical element, an attacker could have exec ...
CVE-2024-26282
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.
CVE-2024-26281
Upon scanning a JavaScript URI with the QR code scanner, an attacker c ...
CVE-2024-26281
Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.
SUSE-SU-2024:0579-1
Security update for mozilla-nss
SUSE-SU-2024:0578-1
Security update for mozilla-nss
GHSA-62vc-2f72-vcj3
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.
GHSA-8q5j-74vg-j4hr
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.
GHSA-372x-c6rw-v8f9
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior. *Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.
GHSA-mf2m-vhfh-2qjv
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2024-26282 Using an AMP url with a canonical element, an attacker could have exec ... | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
CVE-2024-26282 Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
CVE-2024-26281 Upon scanning a JavaScript URI with the QR code scanner, an attacker c ... | CVSS3: 4.7 | 0% Низкий | больше 2 лет назад | |
CVE-2024-26281 Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123. | CVSS3: 4.7 | 0% Низкий | больше 2 лет назад | |
SUSE-SU-2024:0579-1 Security update for mozilla-nss | 1% Низкий | больше 2 лет назад | ||
SUSE-SU-2024:0578-1 Security update for mozilla-nss | 1% Низкий | больше 2 лет назад | ||
GHSA-62vc-2f72-vcj3 Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8. | CVSS3: 8.1 | 1% Низкий | больше 2 лет назад | |
GHSA-8q5j-74vg-j4hr A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-372x-c6rw-v8f9 Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior. *Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-mf2m-vhfh-2qjv If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу