Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 561
CVE-2021-23976
When accepting a malicious intent from other installed apps, Firefox f ...
CVE-2021-23975
The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.
CVE-2021-23975
The developer page about:memory has a Measure function for exploring w ...
CVE-2021-23974
The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.
CVE-2021-23974
The DOMParser API did not properly process '<noscript>' elements for e ...
CVE-2021-23973
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
CVE-2021-23973
When trying to load a cross-origin resource in an audio/video context ...
CVE-2021-23972
One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.
CVE-2021-23972
One phishing tactic on the web is to provide a link with HTTP Auth. Fo ...
CVE-2021-23971
When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect. This vulnerability affects Firefox < 86.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2021-23976 When accepting a malicious intent from other installed apps, Firefox f ... | CVSS3: 8.1 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23975 The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23975 The developer page about:memory has a Measure function for exploring w ... | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23974 The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23974 The DOMParser API did not properly process '<noscript>' elements for e ... | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23973 When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23973 When trying to load a cross-origin resource in an audio/video context ... | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23972 One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86. | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23972 One phishing tactic on the web is to provide a link with HTTP Auth. Fo ... | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2021-23971 When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect. This vulnerability affects Firefox < 86. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад |
Уязвимостей на страницу