Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 500
CVE-2020-6811
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
CVE-2020-6811
The 'Copy as cURL' feature of Devtools' network tab did not properly e ...
CVE-2020-6810
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin of the page and credential theft or other attacks. This vulnerability affects Firefox < 74.
CVE-2020-6810
After a website had entered fullscreen mode, it could have used a prev ...
CVE-2020-6809
When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.
CVE-2020-6809
When a Web Extension had the all-urls permission and made a fetch requ ...
CVE-2020-6808
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.location property, for example) was the originating javascript: URL which could lead to spoofing attacks; it is now correctly the URL of the originating document. This vulnerability affects Firefox < 74.
CVE-2020-6808
When a JavaScript URL (javascript:) is evaluated and the result is a s ...
CVE-2020-6807
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
CVE-2020-6807
When a device was changed while a stream was about to be destroyed, th ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-6811 The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6. | CVSS3: 8.8 | 3% Низкий | больше 6 лет назад | |
CVE-2020-6811 The 'Copy as cURL' feature of Devtools' network tab did not properly e ... | CVSS3: 8.8 | 3% Низкий | больше 6 лет назад | |
CVE-2020-6810 After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin of the page and credential theft or other attacks. This vulnerability affects Firefox < 74. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6810 After a website had entered fullscreen mode, it could have used a prev ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6809 When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6809 When a Web Extension had the all-urls permission and made a fetch requ ... | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6808 When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.location property, for example) was the originating javascript: URL which could lead to spoofing attacks; it is now correctly the URL of the originating document. This vulnerability affects Firefox < 74. | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6808 When a JavaScript URL (javascript:) is evaluated and the result is a s ... | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6807 When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6. | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад | |
CVE-2020-6807 When a device was changed while a stream was about to be destroyed, th ... | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу