Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 500
CVE-2019-11762
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
CVE-2019-11762
If two same-origin documents set document.domain differently to become ...
CVE-2019-11761
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
CVE-2019-11761
By using a form with a data URI it was possible to gain access to the ...
CVE-2019-11760
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
CVE-2019-11760
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC ...
CVE-2019-11759
An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
CVE-2019-11759
An attacker could have caused 4 bytes of HMAC output to be written pas ...
CVE-2019-11758
Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.
CVE-2019-11758
Mozilla community member Philipp reported a memory safety bug present ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-11762 If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2019-11762 If two same-origin documents set document.domain differently to become ... | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2019-11761 By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
CVE-2019-11761 By using a form with a data URI it was possible to gain access to the ... | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
CVE-2019-11760 A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-11760 A fixed-size stack buffer could overflow in nrappkit when doing WebRTC ... | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-11759 An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. | CVSS3: 8.8 | 2% Низкий | больше 6 лет назад | |
CVE-2019-11759 An attacker could have caused 4 bytes of HMAC output to be written pas ... | CVSS3: 8.8 | 2% Низкий | больше 6 лет назад | |
CVE-2019-11758 Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2. | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад | |
CVE-2019-11758 Mozilla community member Philipp reported a memory safety bug present ... | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу