Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 561
CVE-2020-26958
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
CVE-2020-26965
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility for the software keyboard to remember the typed password. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
CVE-2020-26969
Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.
CVE-2020-26959
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
openSUSE-SU-2020:2133-1
Security update for MozillaThunderbird
openSUSE-SU-2020:2022-1
Security update for MozillaThunderbird
ELSA-2020-5163
ELSA-2020-5163: thunderbird security update (IMPORTANT)
ELSA-2020-5164
ELSA-2020-5164: thunderbird security update (IMPORTANT)
SUSE-SU-2020:3418-1
Security update for MozillaThunderbird
ELSA-2020-5146
ELSA-2020-5146: thunderbird security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-26958 Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26965 Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility for the software keyboard to remember the typed password. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26969 Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83. | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-26959 During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
openSUSE-SU-2020:2133-1 Security update for MozillaThunderbird | 42% Средний | больше 5 лет назад | ||
openSUSE-SU-2020:2022-1 Security update for MozillaThunderbird | 42% Средний | почти 6 лет назад | ||
ELSA-2020-5163 ELSA-2020-5163: thunderbird security update (IMPORTANT) | 42% Средний | почти 6 лет назад | ||
ELSA-2020-5164 ELSA-2020-5164: thunderbird security update (IMPORTANT) | 42% Средний | почти 6 лет назад | ||
SUSE-SU-2020:3418-1 Security update for MozillaThunderbird | 42% Средний | почти 6 лет назад | ||
ELSA-2020-5146 ELSA-2020-5146: thunderbird security update (IMPORTANT) | 42% Средний | почти 6 лет назад |
Уязвимостей на страницу