Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 668
GHSA-583h-cvpv-jvr9
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
GHSA-w8wv-29f2-fhc6
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
GHSA-hw5m-xj65-6qh5
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
GHSA-x9jq-pqmx-gf7r
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
GHSA-762q-83qx-7jc3
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
GHSA-7fwr-rxv9-jvxf
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
GHSA-r97x-58x3-7qgg
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
GHSA-ghc9-5whm-hrvq
The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecified vectors, related to an "off-by-three" error.
GHSA-v8rx-7xrc-grgm
WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password during login to Firefox Accounts. This issue does not expose synchronization traffic directly and is limited to the process of user login to the website and the data displayed to the user once logged in. This vulnerability affects Firefox < 60.
GHSA-xf5w-2jf5-86c8
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-583h-cvpv-jvr9 Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-w8wv-29f2-fhc6 Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. | CVSS3: 8.1 | 3% Низкий | больше 4 лет назад | |
GHSA-hw5m-xj65-6qh5 Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-x9jq-pqmx-gf7r Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-762q-83qx-7jc3 Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. | CVSS3: 8.1 | 1% Низкий | больше 4 лет назад | |
GHSA-7fwr-rxv9-jvxf Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation. | 4% Низкий | больше 4 лет назад | ||
GHSA-r97x-58x3-7qgg Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1. | CVSS3: 8.1 | 2% Низкий | больше 4 лет назад | |
GHSA-ghc9-5whm-hrvq The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecified vectors, related to an "off-by-three" error. | 3% Низкий | больше 4 лет назад | ||
GHSA-v8rx-7xrc-grgm WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password during login to Firefox Accounts. This issue does not expose synchronization traffic directly and is limited to the process of user login to the website and the data displayed to the user once logged in. This vulnerability affects Firefox < 60. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-xf5w-2jf5-86c8 WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу