Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
GHSA-9846-hqmr-2486
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
GHSA-9f8v-397v-w8c6
Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
CVE-2023-6873
Memory safety bugs present in Firefox 120. Some of these bugs showed e ...
CVE-2023-6873
Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
CVE-2023-6872
Browser tab titles were being leaked by GNOME to system logs. This cou ...
CVE-2023-6872
Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the browsing habits of users running in a private tab. This vulnerability affects Firefox < 121.
CVE-2023-6871
Under certain conditions, Firefox did not display a warning when a use ...
CVE-2023-6871
Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121.
CVE-2023-6870
Applications which spawn a Toast notification in a background thread m ...
CVE-2023-6870
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-9846-hqmr-2486 The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. | CVSS3: 8.8 | 20% Средний | больше 2 лет назад | |
GHSA-9f8v-397v-w8c6 Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6873 Memory safety bugs present in Firefox 120. Some of these bugs showed e ... | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6873 Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6872 Browser tab titles were being leaked by GNOME to system logs. This cou ... | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6872 Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the browsing habits of users running in a private tab. This vulnerability affects Firefox < 121. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6871 Under certain conditions, Firefox did not display a warning when a use ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-6871 Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-6870 Applications which spawn a Toast notification in a background thread m ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
CVE-2023-6870 Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу