Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 561
CVE-2021-43539
Failure to correctly record the location of live pointers across wasm ...
CVE-2021-43538
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
CVE-2021-43538
By misusing a race in our notification code, an attacker could have fo ...
CVE-2021-43537
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
CVE-2021-43537
An incorrect type conversion of sizes from 64bit to 32bit integers all ...
CVE-2021-43536
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
CVE-2021-43536
Under certain circumstances, asynchronous functions could have caused ...
CVE-2021-43535
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
CVE-2021-43535
A use-after-free could have occured when an HTTP2 session object was r ...
CVE-2021-43534
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2021-43539 Failure to correctly record the location of live pointers across wasm ... | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43538 By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2021-43538 By misusing a race in our notification code, an attacker could have fo ... | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
CVE-2021-43537 An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43537 An incorrect type conversion of sizes from 64bit to 32bit integers all ... | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43536 Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43536 Under certain circumstances, asynchronous functions could have caused ... | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43535 A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-43535 A use-after-free could have occured when an HTTP2 session object was r ... | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-43534 Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу