Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 427
CVE-2018-12402
The internal WebBrowserPersist code does not use correct origin contex ...
CVE-2018-12401
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.
CVE-2018-12401
Some special resource URIs will cause a non-exploitable crash if loade ...
CVE-2018-12400
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63.
CVE-2018-12400
In private browsing mode on Firefox for Android, favicons are cached i ...
CVE-2018-12399
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.
CVE-2018-12399
When a new protocol handler is registered, the API accepts a title arg ...
CVE-2018-12398
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
CVE-2018-12398
By using the reflected URL in some special resource URIs, such as chro ...
CVE-2018-12397
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-12402 The internal WebBrowserPersist code does not use correct origin contex ... | CVSS3: 6.5 | 1% Низкий | больше 7 лет назад | |
CVE-2018-12401 Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63. | CVSS3: 7.5 | 2% Низкий | больше 7 лет назад | |
CVE-2018-12401 Some special resource URIs will cause a non-exploitable crash if loade ... | CVSS3: 7.5 | 2% Низкий | больше 7 лет назад | |
CVE-2018-12400 In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63. | CVSS3: 5.3 | 2% Низкий | больше 7 лет назад | |
CVE-2018-12400 In private browsing mode on Firefox for Android, favicons are cached i ... | CVSS3: 5.3 | 2% Низкий | больше 7 лет назад | |
CVE-2018-12399 When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63. | CVSS3: 4.3 | 1% Низкий | больше 7 лет назад | |
CVE-2018-12399 When a new protocol handler is registered, the API accepts a title arg ... | CVSS3: 4.3 | 1% Низкий | больше 7 лет назад | |
CVE-2018-12398 By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63. | CVSS3: 6.5 | 2% Низкий | больше 7 лет назад | |
CVE-2018-12398 By using the reflected URL in some special resource URIs, such as chro ... | CVSS3: 6.5 | 2% Низкий | больше 7 лет назад | |
CVE-2018-12397 A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63. | CVSS3: 7.1 | 0% Низкий | больше 7 лет назад |
Уязвимостей на страницу