Количество 14
Количество 14

BDU:2025-02600
Уязвимость компонента RegExp браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, Thunderbird ESR, позволяющая нарушителю выполнить произвольный код

CVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

CVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

CVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
CVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The n ...

ROS-20250402-03
Множественные уязвимости thunderbird

ROS-20250402-02
Множественные уязвимости firefox
GHSA-x4j2-c46q-7jp5
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.
ELSA-2025-2699
ELSA-2025-2699: firefox security update (IMPORTANT)
ELSA-2025-2452
ELSA-2025-2452: firefox security update (IMPORTANT)
ELSA-2025-2359
ELSA-2025-2359: firefox security update (IMPORTANT)

SUSE-SU-2025:0788-1
Security update for MozillaFirefox

SUSE-SU-2025:0783-1
Security update for MozillaFirefox

SUSE-SU-2025:0849-1
Security update for MozillaThunderbird
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2025-02600 Уязвимость компонента RegExp браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, Thunderbird ESR, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.8 | 0% Низкий | 4 месяца назад |
![]() | CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад |
![]() | CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 5.4 | 0% Низкий | 4 месяца назад |
![]() | CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад |
CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The n ... | CVSS3: 7.3 | 0% Низкий | 4 месяца назад | |
![]() | ROS-20250402-03 Множественные уязвимости thunderbird | CVSS3: 9.8 | 3 месяца назад | |
![]() | ROS-20250402-02 Множественные уязвимости firefox | CVSS3: 9.8 | 3 месяца назад | |
GHSA-x4j2-c46q-7jp5 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад | |
ELSA-2025-2699 ELSA-2025-2699: firefox security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2025-2452 ELSA-2025-2452: firefox security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2025-2359 ELSA-2025-2359: firefox security update (IMPORTANT) | 4 месяца назад | |||
![]() | SUSE-SU-2025:0788-1 Security update for MozillaFirefox | 4 месяца назад | ||
![]() | SUSE-SU-2025:0783-1 Security update for MozillaFirefox | 4 месяца назад | ||
![]() | SUSE-SU-2025:0849-1 Security update for MozillaThunderbird | 3 месяца назад |
Уязвимостей на страницу