Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 561
CVE-2021-23956
An ambiguous file picker design could have confused users who intended ...
CVE-2021-23955
The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.
CVE-2021-23955
The browser could have been confused into transferring a pointer lock ...
CVE-2021-23954
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
CVE-2021-23954
Using the new logical assignment operators in a JavaScript switch stat ...
CVE-2021-23953
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
CVE-2021-23953
If a user clicked into a specifically crafted PDF, the PDF reader coul ...
CVE-2021-23955
The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.
CVE-2021-23977
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories. Note: This issue is only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.
CVE-2021-23959
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2021-23956 An ambiguous file picker design could have confused users who intended ... | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23955 The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23955 The browser could have been confused into transferring a pointer lock ... | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23954 Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7. | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23954 Using the new logical assignment operators in a JavaScript switch stat ... | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23953 If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7. | CVSS3: 4.3 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23953 If a user clicked into a specifically crafted PDF, the PDF reader coul ... | CVSS3: 4.3 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23955 The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23977 Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories. Note: This issue is only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86. | CVSS3: 5.3 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23959 An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад |
Уязвимостей на страницу