Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 151
GHSA-6xcc-hv2v-v4r3
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134.
CVE-2025-23109
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134.
CVE-2025-23109
Long hostnames in URLs could be leveraged to obscure the actual host o ...
CVE-2025-23108
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
CVE-2025-23108
Opening Javascript links in a new tab via long-press in the Firefox iO ...
CVE-2025-23108
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
CVE-2025-23109
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134.
GHSA-928f-3rxq-5jvp
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.
GHSA-qw28-p6qx-vj78
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.
GHSA-hh4j-jwjv-8726
When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-6xcc-hv2v-v4r3 Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-23109 Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-23109 Long hostnames in URLs could be leveraged to obscure the actual host o ... | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
CVE-2025-23108 Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134. | CVSS3: 4.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-23108 Opening Javascript links in a new tab via long-press in the Firefox iO ... | CVSS3: 4.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-23108 Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134. | CVSS3: 4.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-23109 Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
GHSA-928f-3rxq-5jvp Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6. | CVSS3: 5.1 | 0% Низкий | 10 месяцев назад | |
GHSA-qw28-p6qx-vj78 Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19. | CVSS3: 6.5 | 1% Низкий | 10 месяцев назад | |
GHSA-hh4j-jwjv-8726 When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6. | CVSS3: 7.7 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу