|
![]() [ View full size screenshot ] |
| Version | Date Released | Status | Release Notes |
| 2.4.4 RC 1 | May 30, 2012 | New Release | · Fixed regression from 2.4.3rc3 causing same-site stylesheets to be checked for mime type mismatches and XSLT inclusions to be incorrectly blocked |
| 2.4.3 RC 2 | May 25, 2012 | New Release | · [ABE] IPv6 link-local addresses (fe80:/10) are not considered belonging · to the LAN anymore for the purpose of cross-zone request forgery checks · in order to safely work-around DNS misconfiguration issues in the wild · [ABE] Fixed router WEB UI fingerprinting failing on some devices · because of redirection loops · [XSS] Protection against HPP attacks exploiting URL parsing quirks · specific to ASP Classic · Fixed first application updates check failing on Nightly · [XSS] Fixed false positive regression on some file hosting sites |
| 2.4.2 | May 21, 2012 | New Release | · [ABE] IPv6 link-local addresses (fe80:/10) are not considered belonging · to the LAN anymore for the purpose of cross-zone request forgery checks · in order to safely work-around DNS misconfiguration issues in the wild · [ABE] Fixed router WEB UI fingerprinting failing on some devices · because of redirection loops · [XSS] Protection against HPP attacks exploiting URL parsing quirks · specific to ASP Classic · Fixed first application updates check failing on Nightly · [XSS] Fixed false positive regression on some file hosting sites |
| 2.4.2 RC4 | May 20, 2012 | New Release | · [XSS] Fixed regression blocking any suspect HPP attack silently |
| 2.4.2 RC2 | May 14, 2012 | New Release | · Fixed first application updates check failing on Nightly (bug 754393) |
| 2.4.1 | May 12, 2012 | New Release | · [XSS] Protection against exploitation of classic MS ASP's coalescing of same-name query parameters · [XSS] Protection against URL injections in in window.name · [XSS] Fixed case-sensitivity bug in detection of unicode escape sequences · [Surrogate] adagionet.com inclusion surrogate · Fixed "Allow sites open through bookmarks" regression · [XSS] Fixed bug in the InjectionChecker tokenization · Added inclusion type check exception to the lesscss Google Code file repository, often used as a CDN |
| 2.4.1 RC 3 | May 11, 2012 | New Release | · [XSS] Fixed bug in the InjectionChecker tokenization · Added inclusion type check exception to the lesscss Google Code file repository, often used as a CDN |
| 2.4 | May 6, 2012 | New Release | · [XSS] Improved global exception injection detection · [XSS] Fixed bug in late window.name payload checking · [Locale] Fixed broken overlay on Basque localized browsers |
| 2.4 RC 6 | Apr 30, 2012 | New Release | · [Surrogate] Skimlinks surrogate script. |
| 2.3.9 | Apr 26, 2012 | New Release | · Smart integration with the new browser-native click to play: if a plugin object is manually allowed from NoScript's UI, it gets also natively activated (noscript.smartClickToPlay about:config preference) · Improved active content identity tracking, to avoid redundant blocking steps across reloads · Fixed redirections in legacy frames not being blocked · [Surrogate] Surrogate to fix broken buttons at Uniblue e-commerce site |