Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 673
CVE-2026-9078
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.
BDU:2026-07908
Уязвимость интерфейса предварительного просмотра ссылок браузера Mozilla Firefox, позволяющая нарушителю проводить фишинг-атаки
GHSA-4c2h-7p75-v7hg
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
CVE-2026-8706
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
CVE-2026-8706
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
GHSA-c792-chx5-8443
Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.
GHSA-f4hm-8h94-gvp6
Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151.
GHSA-wg2h-wc56-7jcc
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151.
GHSA-v6hv-5rrm-2f28
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.
GHSA-96x7-hrvx-gqj6
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-9078 Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1. | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
BDU:2026-07908 Уязвимость интерфейса предварительного просмотра ссылок браузера Mozilla Firefox, позволяющая нарушителю проводить фишинг-атаки | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-4c2h-7p75-v7hg Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-8706 Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-8706 Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-c792-chx5-8443 Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
GHSA-f4hm-8h94-gvp6 Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
GHSA-wg2h-wc56-7jcc Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-v6hv-5rrm-2f28 Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
GHSA-96x7-hrvx-gqj6 Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу