Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 500
CVE-2019-11725
When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68.
CVE-2019-11725
When a user navigates to site marked as unsafe by the Safebrowsing API ...
CVE-2019-11724
Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability affects Firefox < 68.
CVE-2019-11724
Application permissions give additional remote troubleshooting permiss ...
CVE-2019-11723
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.
CVE-2019-11723
A vulnerability exists during the installation of add-ons where the in ...
CVE-2019-11721
The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.
CVE-2019-11721
The unicode latin 'kra' character can be used to spoof a standard 'k' ...
CVE-2019-11720
Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.
CVE-2019-11720
Some unicode characters are incorrectly treated as whitespace during t ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-11725 When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68. | CVSS3: 6.5 | 1% Низкий | около 7 лет назад | |
CVE-2019-11725 When a user navigates to site marked as unsafe by the Safebrowsing API ... | CVSS3: 6.5 | 1% Низкий | около 7 лет назад | |
CVE-2019-11724 Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability affects Firefox < 68. | CVSS3: 6.1 | 1% Низкий | около 7 лет назад | |
CVE-2019-11724 Application permissions give additional remote troubleshooting permiss ... | CVSS3: 6.1 | 1% Низкий | около 7 лет назад | |
CVE-2019-11723 A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68. | CVSS3: 7.5 | 1% Низкий | около 7 лет назад | |
CVE-2019-11723 A vulnerability exists during the installation of add-ons where the in ... | CVSS3: 7.5 | 1% Низкий | около 7 лет назад | |
CVE-2019-11721 The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68. | CVSS3: 6.5 | 1% Низкий | около 7 лет назад | |
CVE-2019-11721 The unicode latin 'kra' character can be used to spoof a standard 'k' ... | CVSS3: 6.5 | 1% Низкий | около 7 лет назад | |
CVE-2019-11720 Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68. | CVSS3: 6.1 | 1% Низкий | около 7 лет назад | |
CVE-2019-11720 Some unicode characters are incorrectly treated as whitespace during t ... | CVSS3: 6.1 | 1% Низкий | около 7 лет назад |
Уязвимостей на страницу