Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
BDU:2024-00808
Уязвимость библиотеки ANGLE браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании
RLSA-2024:0105
Moderate: nss security update
ELSA-2024-0108
ELSA-2024-0108: nss security update (MODERATE)
ELSA-2024-0105
ELSA-2024-0105: nss security update (MODERATE)
GHSA-96p4-h67r-wqfm
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
GHSA-p744-68mc-9w5j
The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
GHSA-hx5f-6r56-q754
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
GHSA-5c8h-j5h5-r8w3
`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
GHSA-jhcj-v5hx-prgh
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
GHSA-3xch-57qj-5x2p
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2024-00808 Уязвимость библиотеки ANGLE браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 8.8 | 2% Низкий | больше 2 лет назад | |
RLSA-2024:0105 Moderate: nss security update | 1% Низкий | больше 2 лет назад | ||
ELSA-2024-0108 ELSA-2024-0108: nss security update (MODERATE) | 1% Низкий | больше 2 лет назад | ||
ELSA-2024-0105 ELSA-2024-0105: nss security update (MODERATE) | 1% Низкий | больше 2 лет назад | ||
GHSA-96p4-h67r-wqfm The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-p744-68mc-9w5j The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-hx5f-6r56-q754 The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-5c8h-j5h5-r8w3 `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-jhcj-v5hx-prgh Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3xch-57qj-5x2p In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу