Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2022-29916
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to pro…
Firefox
91.9 / 100.0+
MEDIUM 6.5
CVE-2022-22745
Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91…
Firefox
91.5 / 96.0+
MEDIUM 6.5
CVE-2021-43536
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thun…
Firefox
91.4.0 / 95.0+
HIGH 7.4
CVE-2020-15647
A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data dis…
Firefox
68.10.1+
HIGH 7.5
CVE-2020-6830
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was b…
Firefox
25.0+
MEDIUM 5.3
CVE-2020-6812
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera…
Firefox
68.6.0 / 74.0+
MEDIUM 5.3
CVE-2019-17018
When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerabi…
Firefox
72.0+
MEDIUM 5.3
CVE-2018-12400
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows informati…
Firefox
63.0+
HIGH 7.1
CVE-2018-12397
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being…
Firefox
60.3.0 / 63.0+
HIGH 7.5
CVE-2018-5134
WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that …
Firefox
59.0+
HIGH 7.5
CVE-2018-5137
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a…
Firefox
59.0+
MEDIUM 6.5
CVE-2018-5132
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a mali…
Firefox
59.0+
MEDIUM 6.5
CVE-2018-5133
If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It…
Firefox
59.0+
MEDIUM 5.3
CVE-2018-5140
Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow f…
Firefox
59.0+
HIGH 7.5
CVE-2018-5115
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded for…
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2018-5106
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when…
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2018-5114
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document …
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2018-5118
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue wa…
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2018-5119
The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could all…
Firefox
after 57.0.4
MEDIUM 6.5
CVE-2017-7844
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which …
Firefox
57.0.1+
MEDIUM 5.3
CVE-2017-7831
A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy o…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7842
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One o…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7808
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the o…
Firefox
55.0+
MEDIUM 5.3
CVE-2017-7812
If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to …
Firefox
after 55.0.3
HIGH 7.5
CVE-2017-7759
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of l…
Firefox
54.0+
MEDIUM 5.5
CVE-2017-7768
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the s…
Firefox
52.2.0 / 54.0+
HIGH 7.5
CVE-2017-5425
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some da…
Firefox
52.0+
MEDIUM 5.5
CVE-2017-5414
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to inform…
Firefox
52.0+
HIGH 7.5
CVE-2017-5382
Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal inform…
Firefox
51.0+
HIGH 7.5
CVE-2017-5385
Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to po…
Firefox
51.0+