Vulnerability index

Browse CVEs

109 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2022-29916 Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to pro… Firefox 91.9 / 100.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-22745 Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91… Firefox 91.5 / 96.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2021-43536 Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thun… Firefox 91.4.0 / 95.0+ Fix from $1,6002021-12-08 HIGH 7.4 CVE-2020-15647 A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data dis… Firefox 68.10.1+ Fix from $1,9502020-08-10 HIGH 7.5 CVE-2020-6830 For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was b… Firefox 25.0+ Fix from $1,9502020-05-26 MEDIUM 5.3 CVE-2020-6812 The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera… Firefox 68.6.0 / 74.0+ Fix from $1,6002020-03-25 MEDIUM 5.3 CVE-2019-17018 When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerabi… Firefox 72.0+ Fix from $1,6002020-01-08 MEDIUM 5.3 CVE-2018-12400 In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows informati… Firefox 63.0+ Fix from $1,6002019-02-28 HIGH 7.1 CVE-2018-12397 A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being… Firefox 60.3.0 / 63.0+ Fix from $1,9502019-02-28 HIGH 7.5 CVE-2018-5134 WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that … Firefox 59.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5137 A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a… Firefox 59.0+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2018-5132 The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a mali… Firefox 59.0+ Fix from $1,6002018-06-11 MEDIUM 6.5 CVE-2018-5133 If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It… Firefox 59.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5140 Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow f… Firefox 59.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2018-5115 If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded for… Firefox after 57.0.4 Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2018-5106 Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when… Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5114 If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document … Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5118 The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue wa… Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5119 The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could all… Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 6.5 CVE-2017-7844 A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which … Firefox 57.0.1+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7831 A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy o… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7842 If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One o… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7808 A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the o… Firefox 55.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7812 If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to … Firefox after 55.0.3 Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-7759 Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of l… Firefox 54.0+ Fix from $1,9502018-06-11 MEDIUM 5.5 CVE-2017-7768 The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the s… Firefox 52.2.0 / 54.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-5425 The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some da… Firefox 52.0+ Fix from $1,9502018-06-11 MEDIUM 5.5 CVE-2017-5414 The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to inform… Firefox 52.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-5382 Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal inform… Firefox 51.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5385 Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to po… Firefox 51.0+ Fix from $1,9502018-06-11