Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

ubuntu логотип

CVE-2020-26958

больше 5 лет назад

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-26965

больше 5 лет назад

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility for the software keyboard to remember the typed password. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2020-26969

больше 5 лет назад

Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-26959

больше 5 лет назад

During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:2133-1

больше 5 лет назад

Security update for MozillaThunderbird

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2020:2022-1

почти 6 лет назад

Security update for MozillaThunderbird

EPSS: Средний
oracle-oval логотип

ELSA-2020-5163

почти 6 лет назад

ELSA-2020-5163: thunderbird security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2020-5164

почти 6 лет назад

ELSA-2020-5164: thunderbird security update (IMPORTANT)

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2020:3418-1

почти 6 лет назад

Security update for MozillaThunderbird

EPSS: Средний
oracle-oval логотип

ELSA-2020-5146

почти 6 лет назад

ELSA-2020-5146: thunderbird security update (IMPORTANT)

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2020-26958

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26965

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility for the software keyboard to remember the typed password. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26969

Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-26959

During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2133-1

Security update for MozillaThunderbird

42%
Средний
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2022-1

Security update for MozillaThunderbird

42%
Средний
почти 6 лет назад
oracle-oval логотип
ELSA-2020-5163

ELSA-2020-5163: thunderbird security update (IMPORTANT)

42%
Средний
почти 6 лет назад
oracle-oval логотип
ELSA-2020-5164

ELSA-2020-5164: thunderbird security update (IMPORTANT)

42%
Средний
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:3418-1

Security update for MozillaThunderbird

42%
Средний
почти 6 лет назад
oracle-oval логотип
ELSA-2020-5146

ELSA-2020-5146: thunderbird security update (IMPORTANT)

42%
Средний
почти 6 лет назад

Уязвимостей на страницу


Поделиться