Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 500
CVE-2019-17015
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
CVE-2019-17022
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
BDU:2022-05800
Уязвимость браузера Mozilla Firefox для Windows, связанная с ошибками при обработке входных данных, позволяющая нарушителю выполнить произвольный код
BDU:2022-05733
Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с записью данных за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код
BDU:2022-05928
Уязвимость браузера Mozilla Firefox для Windows, связанная с раскрытием информации, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2022-05738
Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю раскрыть защищаемую информацию
ELSA-2019-4152
ELSA-2019-4152: nss-softokn security update (IMPORTANT)
CVE-2013-1689
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
CVE-2013-1689
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a ...
CVE-2013-1689
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-17015 During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72. | CVSS3: 8.8 | 2% Низкий | больше 6 лет назад | |
CVE-2019-17022 When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72. | CVSS3: 6.1 | 2% Низкий | больше 6 лет назад | |
BDU:2022-05800 Уязвимость браузера Mozilla Firefox для Windows, связанная с ошибками при обработке входных данных, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 1% Низкий | больше 6 лет назад | |
BDU:2022-05733 Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с записью данных за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 2% Низкий | больше 6 лет назад | |
BDU:2022-05928 Уязвимость браузера Mozilla Firefox для Windows, связанная с раскрытием информации, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 5.3 | 1% Низкий | больше 6 лет назад | |
BDU:2022-05738 Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 5.3 | 2% Низкий | больше 6 лет назад | |
ELSA-2019-4152 ELSA-2019-4152: nss-softokn security update (IMPORTANT) | 3% Низкий | больше 6 лет назад | ||
CVE-2013-1689 Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames. | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад | |
CVE-2013-1689 Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a ... | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад | |
CVE-2013-1689 Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames. | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу