Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 151
CVE-2025-1935
A web page could trick a user into setting that site as the default ha ...
CVE-2025-1934
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
CVE-2025-1934
It was possible to interrupt the processing of a RegExp bailout and ru ...
CVE-2025-1933
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
CVE-2025-1933
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can ...
CVE-2025-1932
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
CVE-2025-1932
An inconsistent comparator in xslt/txNodeSorter could have resulted in ...
CVE-2025-1931
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
CVE-2025-1931
It was possible to cause a use-after-free in the content process side ...
CVE-2025-1930
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2025-1935 A web page could trick a user into setting that site as the default ha ... | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-1934 It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
CVE-2025-1934 It was possible to interrupt the processing of a RegExp bailout and ru ... | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
CVE-2025-1933 On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 7.6 | 0% Низкий | 8 месяцев назад | |
CVE-2025-1933 On 64-bit CPUs, when the JIT compiles WASM i32 return values they can ... | CVSS3: 7.6 | 0% Низкий | 8 месяцев назад | |
CVE-2025-1932 An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 8.1 | 0% Низкий | 8 месяцев назад | |
CVE-2025-1932 An inconsistent comparator in xslt/txNodeSorter could have resulted in ... | CVSS3: 8.1 | 0% Низкий | 8 месяцев назад | |
CVE-2025-1931 It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 7.5 | 1% Низкий | 8 месяцев назад | |
CVE-2025-1931 It was possible to cause a use-after-free in the content process side ... | CVSS3: 7.5 | 1% Низкий | 8 месяцев назад | |
CVE-2025-1930 On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу