Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 561
GHSA-h29q-7v28-gprh
The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.
GHSA-5253-q8v4-qcg9
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
GHSA-xwxc-wc23-rvj5
Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.
GHSA-c2mm-7gpv-8xqx
Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
GHSA-94wq-jwp8-mvj5
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."
GHSA-pcv9-8f4w-qrgp
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.
GHSA-j282-cmxq-gm6v
Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header
GHSA-jpfq-gv6p-4pv8
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
GHSA-wg6h-56g7-mfvv
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
GHSA-7c9h-gj9v-x83c
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-h29q-7v28-gprh The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates. | 1% Низкий | больше 4 лет назад | ||
GHSA-5253-q8v4-qcg9 Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol. | 5% Низкий | больше 4 лет назад | ||
GHSA-xwxc-wc23-rvj5 Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end. | 1% Низкий | больше 4 лет назад | ||
GHSA-c2mm-7gpv-8xqx Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0. | 9% Низкий | больше 4 лет назад | ||
GHSA-94wq-jwp8-mvj5 Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers." | 3% Низкий | больше 4 лет назад | ||
GHSA-pcv9-8f4w-qrgp Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing. | 1% Низкий | больше 4 лет назад | ||
GHSA-j282-cmxq-gm6v Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header | 1% Низкий | больше 4 лет назад | ||
GHSA-jpfq-gv6p-4pv8 Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-wg6h-56g7-mfvv Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets | 1% Низкий | больше 4 лет назад | ||
GHSA-7c9h-gj9v-x83c A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval. | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу