Количество 33
Количество 33
ELSA-2025-10181
ELSA-2025-10181: firefox security update (IMPORTANT)
ELSA-2025-10074
ELSA-2025-10074: firefox security update (IMPORTANT)
ELSA-2025-10073
ELSA-2025-10073: firefox security update (IMPORTANT)
ELSA-2025-10072
ELSA-2025-10072: firefox security update (IMPORTANT)

SUSE-SU-2025:02368-1
Security update for MozillaThunderbird

SUSE-SU-2025:02123-1
Security update for MozillaFirefox

SUSE-SU-2025:02122-1
Security update for MozillaFirefox

SUSE-SU-2025:02339-1
Security update for MozillaFirefox, MozillaFirefox-branding-SLE

CVE-2025-6430
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.

CVE-2025-6430
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.

CVE-2025-6430
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
CVE-2025-6430
When a file download is specified via the `Content-Disposition` header ...
GHSA-fvqv-c5hj-jcrp
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

BDU:2025-07582
Уязвимость компонента HTTP Header Handler браузеров Mozilla Firefox, Firefox ESR, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

ROS-20250707-04
Множественные уязвимости firefox

CVE-2025-6425
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.

CVE-2025-6425
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.

CVE-2025-6425
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
CVE-2025-6425
An attacker who enumerated resources from the WebCompat extension coul ...
GHSA-2h3c-qrcw-962q
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2025-10181 ELSA-2025-10181: firefox security update (IMPORTANT) | 10 дней назад | |||
ELSA-2025-10074 ELSA-2025-10074: firefox security update (IMPORTANT) | 23 дня назад | |||
ELSA-2025-10073 ELSA-2025-10073: firefox security update (IMPORTANT) | 23 дня назад | |||
ELSA-2025-10072 ELSA-2025-10072: firefox security update (IMPORTANT) | 23 дня назад | |||
![]() | SUSE-SU-2025:02368-1 Security update for MozillaThunderbird | 5 дней назад | ||
![]() | SUSE-SU-2025:02123-1 Security update for MozillaFirefox | 27 дней назад | ||
![]() | SUSE-SU-2025:02122-1 Security update for MozillaFirefox | 27 дней назад | ||
![]() | SUSE-SU-2025:02339-1 Security update for MozillaFirefox, MozillaFirefox-branding-SLE | 6 дней назад | ||
![]() | CVE-2025-6430 When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 6.1 | 0% Низкий | 29 дней назад |
![]() | CVE-2025-6430 When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 6.1 | 0% Низкий | 29 дней назад |
![]() | CVE-2025-6430 When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 6.1 | 0% Низкий | 29 дней назад |
CVE-2025-6430 When a file download is specified via the `Content-Disposition` header ... | CVSS3: 6.1 | 0% Низкий | 29 дней назад | |
GHSA-fvqv-c5hj-jcrp When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12. | CVSS3: 6.1 | 0% Низкий | 27 дней назад | |
![]() | BDU:2025-07582 Уязвимость компонента HTTP Header Handler браузеров Mozilla Firefox, Firefox ESR, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS) | CVSS3: 6.1 | 0% Низкий | 30 дней назад |
![]() | ROS-20250707-04 Множественные уязвимости firefox | CVSS3: 5.3 | 17 дней назад | |
![]() | CVE-2025-6425 An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 4.3 | 0% Низкий | 29 дней назад |
![]() | CVE-2025-6425 An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 6.1 | 0% Низкий | 29 дней назад |
![]() | CVE-2025-6425 An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | CVSS3: 4.3 | 0% Низкий | 29 дней назад |
CVE-2025-6425 An attacker who enumerated resources from the WebCompat extension coul ... | CVSS3: 4.3 | 0% Низкий | 29 дней назад | |
GHSA-2h3c-qrcw-962q An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12. | CVSS3: 4.3 | 0% Низкий | 27 дней назад |
Уязвимостей на страницу