Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2023-23603
Regular expressions used to filter out forbidden properties and values ...
CVE-2023-23603
Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
CVE-2023-23602
A mishandled security check when creating a WebSocket in a WebWorker c ...
CVE-2023-23602
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
CVE-2023-23601
Navigations were being allowed when dragging a URL from a cross-origin ...
CVE-2023-23601
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
CVE-2023-23600
Per origin notification permissions were being stored in a way that di ...
CVE-2023-23600
Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109.
CVE-2023-23599
When copying a network request from the developer tools panel as a cur ...
CVE-2023-23599
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-23603 Regular expressions used to filter out forbidden properties and values ... | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-23603 Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-23602 A mishandled security check when creating a WebSocket in a WebWorker c ... | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-23602 A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-23601 Navigations were being allowed when dragging a URL from a cross-origin ... | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-23601 Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-23600 Per origin notification permissions were being stored in a way that di ... | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-23600 Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-23599 When copying a network request from the developer tools panel as a cur ... | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-23599 When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу