Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2022-36318
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
CVE-2022-36317
When visiting a website with an overly long URL, the user interface wo ...
CVE-2022-36317
When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.
CVE-2022-36316
When using the Performance API, an attacker was able to notice subtle ...
CVE-2022-36316
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.
CVE-2022-36315
When loading a script with Subresource Integrity, attackers with an in ...
CVE-2022-36315
When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.
CVE-2022-36314
When opening a Windows shortcut from the local filesystem, an attacker ...
CVE-2022-36314
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
CVE-2022-34485
Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team r ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-36318 When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
CVE-2022-36317 When visiting a website with an overly long URL, the user interface wo ... | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-36317 When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-36316 When using the Performance API, an attacker was able to notice subtle ... | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-36316 When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-36315 When loading a script with Subresource Integrity, attackers with an in ... | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
CVE-2022-36315 When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
CVE-2022-36314 When opening a Windows shortcut from the local filesystem, an attacker ... | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-36314 When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-34485 Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team r ... | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу