Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 500
CVE-2019-11719
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
CVE-2019-11719
When importing a curve25519 private key in PKCS#8format with leading 0 ...
CVE-2019-11718
Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Firefox < 68.
CVE-2019-11718
Activity Stream can display content from sent from the Snippet Service ...
CVE-2019-11717
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
CVE-2019-11717
A vulnerability exists where the caret ("^") character is improperly e ...
CVE-2019-11716
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.
CVE-2019-11716
Until explicitly accessed by script, window.globalThis is not enumerab ...
CVE-2019-11715
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
CVE-2019-11715
Due to an error while parsing page content, it is possible for properl ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-11719 When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | CVSS3: 7.5 | 2% Низкий | около 7 лет назад | |
CVE-2019-11719 When importing a curve25519 private key in PKCS#8format with leading 0 ... | CVSS3: 7.5 | 2% Низкий | около 7 лет назад | |
CVE-2019-11718 Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Firefox < 68. | CVSS3: 5.3 | 1% Низкий | около 7 лет назад | |
CVE-2019-11718 Activity Stream can display content from sent from the Snippet Service ... | CVSS3: 5.3 | 1% Низкий | около 7 лет назад | |
CVE-2019-11717 A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | CVSS3: 5.3 | 2% Низкий | около 7 лет назад | |
CVE-2019-11717 A vulnerability exists where the caret ("^") character is improperly e ... | CVSS3: 5.3 | 2% Низкий | около 7 лет назад | |
CVE-2019-11716 Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68. | CVSS3: 8.3 | 1% Низкий | около 7 лет назад | |
CVE-2019-11716 Until explicitly accessed by script, window.globalThis is not enumerab ... | CVSS3: 8.3 | 1% Низкий | около 7 лет назад | |
CVE-2019-11715 Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | CVSS3: 6.1 | 2% Низкий | около 7 лет назад | |
CVE-2019-11715 Due to an error while parsing page content, it is possible for properl ... | CVSS3: 6.1 | 2% Низкий | около 7 лет назад |
Уязвимостей на страницу