Количество 15
Количество 15

CVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

CVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.

CVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
CVE-2025-1936
jar: URLs retrieve local file content packaged in a ZIP archive. The n ...
GHSA-x4j2-c46q-7jp5
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.

BDU:2025-02600
Уязвимость компонента RegExp браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, Thunderbird ESR, позволяющая нарушителю выполнить произвольный код

RLSA-2025:2452
Important: firefox security update
ELSA-2025-2699
ELSA-2025-2699: firefox security update (IMPORTANT)
ELSA-2025-2452
ELSA-2025-2452: firefox security update (IMPORTANT)
ELSA-2025-2359
ELSA-2025-2359: firefox security update (IMPORTANT)

SUSE-SU-2025:0788-1
Security update for MozillaFirefox

SUSE-SU-2025:0783-1
Security update for MozillaFirefox

SUSE-SU-2025:0849-1
Security update for MozillaThunderbird

ROS-20250402-03
Множественные уязвимости thunderbird

ROS-20250402-02
Множественные уязвимости firefox
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад |
![]() | CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 5.4 | 0% Низкий | 5 месяцев назад |
![]() | CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад |
CVE-2025-1936 jar: URLs retrieve local file content packaged in a ZIP archive. The n ... | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
GHSA-x4j2-c46q-7jp5 jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
![]() | BDU:2025-02600 Уязвимость компонента RegExp браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, Thunderbird ESR, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.8 | 0% Низкий | 5 месяцев назад |
![]() | RLSA-2025:2452 Important: firefox security update | 8 дней назад | ||
ELSA-2025-2699 ELSA-2025-2699: firefox security update (IMPORTANT) | 5 месяцев назад | |||
ELSA-2025-2452 ELSA-2025-2452: firefox security update (IMPORTANT) | 5 месяцев назад | |||
ELSA-2025-2359 ELSA-2025-2359: firefox security update (IMPORTANT) | 5 месяцев назад | |||
![]() | SUSE-SU-2025:0788-1 Security update for MozillaFirefox | 5 месяцев назад | ||
![]() | SUSE-SU-2025:0783-1 Security update for MozillaFirefox | 5 месяцев назад | ||
![]() | SUSE-SU-2025:0849-1 Security update for MozillaThunderbird | 5 месяцев назад | ||
![]() | ROS-20250402-03 Множественные уязвимости thunderbird | CVSS3: 9.8 | 4 месяца назад | |
![]() | ROS-20250402-02 Множественные уязвимости firefox | CVSS3: 9.8 | 4 месяца назад |
Уязвимостей на страницу