Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 427
CVE-2019-9808
If WebRTC permission is requested from documents with data: or blob: U ...
CVE-2019-9807
When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66.
CVE-2019-9807
When arbitrary text is sent over an FTP connection and a page reload i ...
CVE-2019-9806
A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) attack. This vulnerability affects Firefox < 66.
CVE-2019-9806
A vulnerability exists during authorization prompting for FTP transact ...
CVE-2019-9805
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.
CVE-2019-9805
A latent vulnerability exists in the Prio library where data may be re ...
CVE-2019-9804
In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously crafted. This is the result of an issue with the native version of Bash on macOS. *Note: This issue only affects macOS. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.
CVE-2019-9804
In Firefox Developer Tools it is possible that pasting the result of t ...
CVE-2019-9803
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources. This vulnerability affects Firefox < 66.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-9808 If WebRTC permission is requested from documents with data: or blob: U ... | CVSS3: 5.3 | 0% Низкий | больше 7 лет назад | |
CVE-2019-9807 When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66. | CVSS3: 4.3 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9807 When arbitrary text is sent over an FTP connection and a page reload i ... | CVSS3: 4.3 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9806 A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) attack. This vulnerability affects Firefox < 66. | CVSS3: 7.5 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9806 A vulnerability exists during authorization prompting for FTP transact ... | CVSS3: 7.5 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9805 A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66. | CVSS3: 9.8 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9805 A latent vulnerability exists in the Prio library where data may be re ... | CVSS3: 9.8 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9804 In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously crafted. This is the result of an issue with the native version of Bash on macOS. *Note: This issue only affects macOS. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66. | CVSS3: 9.8 | 2% Низкий | больше 7 лет назад | |
CVE-2019-9804 In Firefox Developer Tools it is possible that pasting the result of t ... | CVSS3: 9.8 | 2% Низкий | больше 7 лет назад | |
CVE-2019-9803 The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources. This vulnerability affects Firefox < 66. | CVSS3: 7.4 | 1% Низкий | больше 7 лет назад |
Уязвимостей на страницу