Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 545
CVE-2020-15652
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
CVE-2020-15652
By observing the stack trace for JavaScript errors in web workers, it ...
CVE-2020-15651
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.
CVE-2020-15651
A unicode RTL order character in the downloaded file name can be used ...
CVE-2020-15648
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
CVE-2020-15648
Using object or embed tags, it was possible to frame other websites, e ...
CVE-2020-15647
A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.
CVE-2020-15647
A Content Provider in Firefox for Android allowed local files accessib ...
CVE-2020-15648
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
CVE-2020-15647
A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-15652 By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1. | CVSS3: 6.5 | 1% Низкий | около 6 лет назад | |
CVE-2020-15652 By observing the stack trace for JavaScript errors in web workers, it ... | CVSS3: 6.5 | 1% Низкий | около 6 лет назад | |
CVE-2020-15651 A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28. | CVSS3: 4.3 | 1% Низкий | около 6 лет назад | |
CVE-2020-15651 A unicode RTL order character in the downloaded file name can be used ... | CVSS3: 4.3 | 1% Низкий | около 6 лет назад | |
CVE-2020-15648 Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2. | CVSS3: 6.5 | 1% Низкий | около 6 лет назад | |
CVE-2020-15648 Using object or embed tags, it was possible to frame other websites, e ... | CVSS3: 6.5 | 1% Низкий | около 6 лет назад | |
CVE-2020-15647 A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android. | CVSS3: 7.4 | 1% Низкий | около 6 лет назад | |
CVE-2020-15647 A Content Provider in Firefox for Android allowed local files accessib ... | CVSS3: 7.4 | 1% Низкий | около 6 лет назад | |
CVE-2020-15648 Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2. | CVSS3: 6.5 | 1% Низкий | около 6 лет назад | |
CVE-2020-15647 A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android. | CVSS3: 7.4 | 1% Низкий | около 6 лет назад |
Уязвимостей на страницу