Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2022-28286
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
CVE-2022-28285
When generating the assembly code for <code>MLoadTypedArrayElementHole ...
CVE-2022-28285
When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
CVE-2022-28284
SVG's <code><use></code> element could have been used to load un ...
CVE-2022-28284
SVG's <code><use></code> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99.
CVE-2022-28283
The sourceMapURL feature in devtools was missing security checks that ...
CVE-2022-28283
The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99.
CVE-2022-28282
By using a link with <code>rel="localization"</code> a use-after-free ...
CVE-2022-28282
By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
CVE-2022-28281
If a compromised content process sent an unexpected number of WebAuthN ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-28286 Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
CVE-2022-28285 When generating the assembly code for <code>MLoadTypedArrayElementHole ... | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-28285 When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-28284 SVG's <code><use></code> element could have been used to load un ... | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-28284 SVG's <code><use></code> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-28283 The sourceMapURL feature in devtools was missing security checks that ... | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-28283 The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-28282 By using a link with <code>rel="localization"</code> a use-after-free ... | CVSS3: 6.5 | 2% Низкий | больше 3 лет назад | |
CVE-2022-28282 By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8. | CVSS3: 6.5 | 2% Низкий | больше 3 лет назад | |
CVE-2022-28281 If a compromised content process sent an unexpected number of WebAuthN ... | CVSS3: 8.8 | 3% Низкий | больше 3 лет назад |
Уязвимостей на страницу