Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 427
CVE-2018-18497
Limitations on the URIs allowed to WebExtensions by the browser.window ...
CVE-2018-18496
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.
CVE-2018-18496
When the RSS Feed preview about:feeds page is framed within another pa ...
CVE-2018-18495
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.
CVE-2018-18495
WebExtension content scripts can be loaded into about: pages in some c ...
CVE-2018-18494
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
CVE-2018-18494
A same-origin policy violation allowing the theft of cross-origin URL ...
CVE-2018-18493
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
CVE-2018-18493
A buffer overflow can occur in the Skia library during buffer offset c ...
CVE-2018-18492
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-18497 Limitations on the URIs allowed to WebExtensions by the browser.window ... | CVSS3: 6.5 | 1% Низкий | больше 7 лет назад | |
CVE-2018-18496 When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64. | CVSS3: 8.8 | 1% Низкий | больше 7 лет назад | |
CVE-2018-18496 When the RSS Feed preview about:feeds page is framed within another pa ... | CVSS3: 8.8 | 1% Низкий | больше 7 лет назад | |
CVE-2018-18495 WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64. | CVSS3: 6.5 | 2% Низкий | больше 7 лет назад | |
CVE-2018-18495 WebExtension content scripts can be loaded into about: pages in some c ... | CVSS3: 6.5 | 2% Низкий | больше 7 лет назад | |
CVE-2018-18494 A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. | CVSS3: 6.5 | 2% Низкий | больше 7 лет назад | |
CVE-2018-18494 A same-origin policy violation allowing the theft of cross-origin URL ... | CVSS3: 6.5 | 2% Низкий | больше 7 лет назад | |
CVE-2018-18493 A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. | CVSS3: 9.8 | 5% Низкий | больше 7 лет назад | |
CVE-2018-18493 A buffer overflow can occur in the Skia library during buffer offset c ... | CVSS3: 9.8 | 5% Низкий | больше 7 лет назад | |
CVE-2018-18492 A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. | CVSS3: 9.8 | 10% Низкий | больше 7 лет назад |
Уязвимостей на страницу