Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 561
CVE-2020-26979
When a user typed a URL in the address bar or the search bar and quick ...
CVE-2020-26978
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
CVE-2020-26978
Using techniques that built on the slipstream research, a malicious we ...
CVE-2020-26976
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
CVE-2020-26976
When a HTTPS pages was embedded in a HTTP page, and there was a servic ...
CVE-2020-26974
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
CVE-2020-26974
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis o ...
CVE-2020-26973
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
CVE-2020-26973
Certain input to the CSS Sanitizer confused it, resulting in incorrect ...
CVE-2020-26972
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 84.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-26979 When a user typed a URL in the address bar or the search bar and quick ... | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26978 Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26978 Using techniques that built on the slipstream research, a malicious we ... | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26976 When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84. | CVSS3: 6.5 | 2% Низкий | больше 5 лет назад | |
CVE-2020-26976 When a HTTPS pages was embedded in a HTTP page, and there was a servic ... | CVSS3: 6.5 | 2% Низкий | больше 5 лет назад | |
CVE-2020-26974 When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6. | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26974 When flex-basis was used on a table wrapper, a StyleGenericFlexBasis o ... | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26973 Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6. | CVSS3: 8.8 | 2% Низкий | больше 5 лет назад | |
CVE-2020-26973 Certain input to the CSS Sanitizer confused it, resulting in incorrect ... | CVSS3: 8.8 | 2% Низкий | больше 5 лет назад | |
CVE-2020-26972 The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 84. | CVSS3: 9.8 | 1% Низкий | больше 5 лет назад |
Уязвимостей на страницу