Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2023-6211
If an attacker needed a user to load an insecure http: page and knew t ...
CVE-2023-6211
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.
CVE-2023-6210
When an https: web page created a pop-up from a "javascript:" URL, tha ...
CVE-2023-6210
When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.
CVE-2023-6209
Relative URLs starting with three slashes were incorrectly parsed, and ...
CVE-2023-6209
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6208
When using X11, text selected by the page using the Selection API was ...
CVE-2023-6208
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6207
Ownership mismanagement led to a use-after-free in ReadableByteStreams ...
CVE-2023-6207
Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-6211 If an attacker needed a user to load an insecure http: page and knew t ... | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-6211 If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-6210 When an https: web page created a pop-up from a "javascript:" URL, tha ... | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6210 When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6209 Relative URLs starting with three slashes were incorrectly parsed, and ... | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6209 Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6208 When using X11, text selected by the page using the Selection API was ... | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6208 When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6207 Ownership mismanagement led to a use-after-free in ReadableByteStreams ... | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-6207 Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу