Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2022-34475
SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a same-origin JavaScript file containing the script to be executed. This vulnerability affects Firefox < 102.
CVE-2022-34474
Even when an iframe was sandboxed with <code>allow-top-navigation-by-u ...
CVE-2022-34474
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.
CVE-2022-34473
The HTML Sanitizer should have sanitized the <code>href</code> attribu ...
CVE-2022-34473
The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></code> tags; however it incorrectly did not sanitize <code>xlink:href</code> attributes. This vulnerability affects Firefox < 102.
CVE-2022-34472
If there was a PAC URL set and the server that hosts the PAC was not r ...
CVE-2022-34472
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
CVE-2022-34471
When downloading an update for an addon, the downloaded addon update's ...
CVE-2022-34471
When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.
CVE-2022-34470
Session history navigations may have led to a use-after-free and poten ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-34475 SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a same-origin JavaScript file containing the script to be executed. This vulnerability affects Firefox < 102. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-34474 Even when an iframe was sandboxed with <code>allow-top-navigation-by-u ... | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-34474 Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-34473 The HTML Sanitizer should have sanitized the <code>href</code> attribu ... | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-34473 The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></code> tags; however it incorrectly did not sanitize <code>xlink:href</code> attributes. This vulnerability affects Firefox < 102. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
CVE-2022-34472 If there was a PAC URL set and the server that hosts the PAC was not r ... | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-34472 If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
CVE-2022-34471 When downloading an update for an addon, the downloaded addon update's ... | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-34471 When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-34470 Session history navigations may have led to a use-after-free and poten ... | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу