Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2022-31746
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
CVE-2022-31745
If array shift operations are not used, the Garbage Collector may have ...
CVE-2022-31745
If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101.
CVE-2022-31744
An attacker could have injected CSS into stylesheets accessible via in ...
CVE-2022-31744
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.
CVE-2022-31743
Firefox's HTML parser did not correctly interpret HTML comment tags, r ...
CVE-2022-31743
Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.
CVE-2022-31742
An attacker could have exploited a timing attack by sending a large nu ...
CVE-2022-31742
An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
CVE-2022-31741
A crafted CMS message could have been processed incorrectly, leading t ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-31746 Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-31745 If array shift operations are not used, the Garbage Collector may have ... | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
CVE-2022-31745 If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
CVE-2022-31744 An attacker could have injected CSS into stylesheets accessible via in ... | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-31744 An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-31743 Firefox's HTML parser did not correctly interpret HTML comment tags, r ... | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-31743 Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-31742 An attacker could have exploited a timing attack by sending a large nu ... | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-31742 An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-31741 A crafted CMS message could have been processed incorrectly, leading t ... | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу