Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 561
CVE-2020-26961
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
CVE-2020-26961
When DNS over HTTPS is in use, it intentionally filters RFC1918 and re ...
CVE-2020-26960
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
CVE-2020-26960
If the Compact() method was called on an nsTArray, the array could hav ...
CVE-2020-26959
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
CVE-2020-26959
During browser shutdown, reference decrementing could have occured on ...
CVE-2020-26958
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
CVE-2020-26958
Firefox did not block execution of scripts with incorrect MIME types w ...
CVE-2020-26956
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
CVE-2020-26956
In some cases, removing HTML elements during sanitization would keep e ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-26961 When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26961 When DNS over HTTPS is in use, it intentionally filters RFC1918 and re ... | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26960 If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. | CVSS3: 8.8 | 2% Низкий | больше 5 лет назад | |
CVE-2020-26960 If the Compact() method was called on an nsTArray, the array could hav ... | CVSS3: 8.8 | 2% Низкий | больше 5 лет назад | |
CVE-2020-26959 During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26959 During browser shutdown, reference decrementing could have occured on ... | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26958 Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26958 Firefox did not block execution of scripts with incorrect MIME types w ... | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26956 In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26956 In some cases, removing HTML elements during sanitization would keep e ... | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад |
Уязвимостей на страницу