Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 427
CVE-2019-9803
The Upgrade-Insecure-Requests (UIR) specification states that if UIR i ...
CVE-2019-9802
If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an attacker, bypassing sandbox protections and allow for a potential memory read of adjacent data from the privileged Chrome process, which may include sensitive data. This vulnerability affects Firefox < 66.
CVE-2019-9802
If a Sandbox content process is compromised, it can initiate an FTP do ...
CVE-2019-9801
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
CVE-2019-9801
Firefox will accept any registered Program ID as an external protocol ...
CVE-2019-9799
Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.
CVE-2019-9799
Insufficient bounds checking of data during inter-process communicatio ...
CVE-2019-9798
On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.
CVE-2019-9798
On Android systems, Firefox can load a library from APITRACE_LIB, whic ...
CVE-2019-9797
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-9803 The Upgrade-Insecure-Requests (UIR) specification states that if UIR i ... | CVSS3: 7.4 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9802 If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an attacker, bypassing sandbox protections and allow for a potential memory read of adjacent data from the privileged Chrome process, which may include sensitive data. This vulnerability affects Firefox < 66. | CVSS3: 7.5 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9802 If a Sandbox content process is compromised, it can initiate an FTP do ... | CVSS3: 7.5 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9801 Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. | CVSS3: 5.3 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9801 Firefox will accept any registered Program ID as an external protocol ... | CVSS3: 5.3 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9799 Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66. | CVSS3: 7.5 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9799 Insufficient bounds checking of data during inter-process communicatio ... | CVSS3: 7.5 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9798 On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66. | CVSS3: 7.4 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9798 On Android systems, Firefox can load a library from APITRACE_LIB, whic ... | CVSS3: 7.4 | 1% Низкий | больше 7 лет назад | |
CVE-2019-9797 Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66. | CVSS3: 5.3 | 1% Низкий | больше 7 лет назад |
Уязвимостей на страницу