Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 500
CVE-2020-6824
Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.
CVE-2020-6824
Initially, a user opens a Private Browsing Window and generates a pass ...
CVE-2020-6823
A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.
CVE-2020-6823
A malicious extension could have called <code>browser.identity.launchW ...
CVE-2020-6822
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
CVE-2020-6822
On 32-bit builds, an out of bounds write could have occurred when proc ...
CVE-2020-6821
When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
CVE-2020-6821
When reading from areas partially or fully outside the source resource ...
CVE-2020-6820
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CVE-2020-6820
Under certain conditions, when handling a ReadableStream, a race condi ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-6824 Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75. | CVSS3: 2.8 | 0% Низкий | больше 6 лет назад | |
CVE-2020-6824 Initially, a user opens a Private Browsing Window and generates a pass ... | CVSS3: 2.8 | 0% Низкий | больше 6 лет назад | |
CVE-2020-6823 A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75. | CVSS3: 9.8 | 2% Низкий | больше 6 лет назад | |
CVE-2020-6823 A malicious extension could have called <code>browser.identity.launchW ... | CVSS3: 9.8 | 2% Низкий | больше 6 лет назад | |
CVE-2020-6822 On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75. | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6822 On 32-bit builds, an out of bounds write could have occurred when proc ... | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6821 When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6821 When reading from areas partially or fully outside the source resource ... | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6820 Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. | CVSS3: 8.1 | 6% Низкий | больше 6 лет назад | |
CVE-2020-6820 Under certain conditions, when handling a ReadableStream, a race condi ... | CVSS3: 8.1 | 6% Низкий | больше 6 лет назад |
Уязвимостей на страницу