Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2022-46875
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
CVE-2022-46874
A file with a long filename could have had its filename truncated to r ...
CVE-2022-46874
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6.
CVE-2022-46873
Because Firefox did not implement the <code>unsafe-hashes</code> CSP d ...
CVE-2022-46873
Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.
CVE-2022-46872
An attacker who compromised a content process could have partially esc ...
CVE-2022-46872
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
CVE-2022-46871
An out of date library (libusrsctp) contained vulnerabilities that cou ...
CVE-2022-46871
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.
CVE-2022-45421
Mozilla developers Andrew McCreight and Gabriele Svelto reported memor ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-46875 The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-46874 A file with a long filename could have had its filename truncated to r ... | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-46874 A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-46873 Because Firefox did not implement the <code>unsafe-hashes</code> CSP d ... | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-46873 Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-46872 An attacker who compromised a content process could have partially esc ... | CVSS3: 8.6 | 1% Низкий | больше 3 лет назад | |
CVE-2022-46872 An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6. | CVSS3: 8.6 | 1% Низкий | больше 3 лет назад | |
CVE-2022-46871 An out of date library (libusrsctp) contained vulnerabilities that cou ... | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-46871 An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-45421 Mozilla developers Andrew McCreight and Gabriele Svelto reported memor ... | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу