Количество 14
Количество 14

CVE-2025-6430
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.

CVE-2025-6430
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.

CVE-2025-6430
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
CVE-2025-6430
When a file download is specified via the `Content-Disposition` header ...
GHSA-fvqv-c5hj-jcrp
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

BDU:2025-07582
Уязвимость компонента HTTP Header Handler браузеров Mozilla Firefox, Firefox ESR, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)
ELSA-2025-10181
ELSA-2025-10181: firefox security update (IMPORTANT)
ELSA-2025-10074
ELSA-2025-10074: firefox security update (IMPORTANT)
ELSA-2025-10073
ELSA-2025-10073: firefox security update (IMPORTANT)
ELSA-2025-10072
ELSA-2025-10072: firefox security update (IMPORTANT)

SUSE-SU-2025:02368-1
Security update for MozillaThunderbird

SUSE-SU-2025:02123-1
Security update for MozillaFirefox

SUSE-SU-2025:02122-1
Security update for MozillaFirefox

SUSE-SU-2025:02339-1
Security update for MozillaFirefox, MozillaFirefox-branding-SLE
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2025-6430 When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 6.1 | 0% Низкий | 29 дней назад |
![]() | CVE-2025-6430 When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 6.1 | 0% Низкий | 29 дней назад |
![]() | CVE-2025-6430 When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 6.1 | 0% Низкий | 29 дней назад |
CVE-2025-6430 When a file download is specified via the `Content-Disposition` header ... | CVSS3: 6.1 | 0% Низкий | 29 дней назад | |
GHSA-fvqv-c5hj-jcrp When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12. | CVSS3: 6.1 | 0% Низкий | 27 дней назад | |
![]() | BDU:2025-07582 Уязвимость компонента HTTP Header Handler браузеров Mozilla Firefox, Firefox ESR, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS) | CVSS3: 6.1 | 0% Низкий | 30 дней назад |
ELSA-2025-10181 ELSA-2025-10181: firefox security update (IMPORTANT) | 10 дней назад | |||
ELSA-2025-10074 ELSA-2025-10074: firefox security update (IMPORTANT) | 23 дня назад | |||
ELSA-2025-10073 ELSA-2025-10073: firefox security update (IMPORTANT) | 23 дня назад | |||
ELSA-2025-10072 ELSA-2025-10072: firefox security update (IMPORTANT) | 23 дня назад | |||
![]() | SUSE-SU-2025:02368-1 Security update for MozillaThunderbird | 5 дней назад | ||
![]() | SUSE-SU-2025:02123-1 Security update for MozillaFirefox | 27 дней назад | ||
![]() | SUSE-SU-2025:02122-1 Security update for MozillaFirefox | 27 дней назад | ||
![]() | SUSE-SU-2025:02339-1 Security update for MozillaFirefox, MozillaFirefox-branding-SLE | 6 дней назад |
Уязвимостей на страницу