Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2022-29916
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
CVE-2022-29915
The Performance API did not properly hide the fact whether a request c ...
CVE-2022-29915
The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.
CVE-2022-29914
When reusing existing popups Firefox would have allowed them to cover ...
CVE-2022-29914
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
CVE-2022-29912
Requests initiated through reader mode did not properly omit cookies w ...
CVE-2022-29912
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
CVE-2022-29911
An improper implementation of the new iframe sandbox keyword <code>all ...
CVE-2022-29911
An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
CVE-2022-29910
When closed or sent to the background, Firefox for Android would not p ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-29916 Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-29915 The Performance API did not properly hide the fact whether a request c ... | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
CVE-2022-29915 The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
CVE-2022-29914 When reusing existing popups Firefox would have allowed them to cover ... | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-29914 When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-29912 Requests initiated through reader mode did not properly omit cookies w ... | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-29912 Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-29911 An improper implementation of the new iframe sandbox keyword <code>all ... | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-29911 An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
CVE-2022-29910 When closed or sent to the background, Firefox for Android would not p ... | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу