Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Firefox CRITICAL 9.8
CVE-2025-55031

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …

Fix: 142.0+
Fix from $2,300 2025-08-19
Firefox Focus MEDIUM 6.1
CVE-2025-55032

Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowin…

Fix: 142.0+
Fix from $1,600 2025-08-19
Firefox CRITICAL 9.1
CVE-2025-54145

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR…

Fix: 141.0+
Fix from $2,300 2025-08-19
Firefox MEDIUM 5.4
CVE-2025-54144

The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal p…

Fix: 141.0+
Fix from $1,600 2025-08-19
Firefox Focus MEDIUM 6.1
CVE-2025-3859

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick u…

Fix: 138.0+
Fix from $1,600 2025-04-30
Thunderbird MEDIUM 6.3
CVE-2025-3522

Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thu…

Fix: 128.9.2 / 137.0.2+
Fix from $1,600 2025-04-15
Firefox MEDIUM 5.4
CVE-2025-27426

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in …

Fix: 136.0+
Fix from $1,600 2025-03-04
Firefox MEDIUM 5.3
CVE-2025-0244EPSS 7%

When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. …

Fix: 134.0+
Fix from $1,600 2025-01-07
Firefox MEDIUM 6.1
CVE-2024-8897EPSS 7%

Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to s…

Fix: 130.0.1+
Fix from $1,600 2024-09-17
Firefox MEDIUM 6.1
CVE-2024-8386

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofin…

Fix: 128.2 / 130.0+
Fix from $1,600 2024-09-03
Firefox HIGH 7.5
CVE-2024-4773

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfu…

Fix: 126.0+
Fix from $1,950 2024-05-14
Firefox MEDIUM 6.1
CVE-2024-0953

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi…

No fix yet
Fix from $1,600 2024-02-05
Firefox MEDIUM 6.1
CVE-2023-49061

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS…

Fix: 120.0+
Fix from $1,600 2023-11-21
Firefox MEDIUM 6.1
CVE-2023-34415

When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in t…

Fix: 114.0+
Fix from $1,600 2023-06-19
Firefox MEDIUM 6.1
CVE-2023-29540

Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <cod…

Fix: 112.0+
Fix from $1,600 2023-06-02
Firefox HIGH 8.1
CVE-2023-25734

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpecte…

Fix: 102.8 / 110.0+
Fix from $1,950 2023-06-02
Pollbot MEDIUM 6.1
CVE-2022-0637

open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6

Fix: 1.4.6+
Fix from $1,600 2023-02-16
Firefox MEDIUM 6.1
CVE-2022-45413

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be…

Fix: 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-36316

When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL ha…

Fix: 103.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-34478

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser,…

Fix: 91.11 / 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-34474

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol…

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-29912

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefo…

Fix: 91.9 / 100.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-29910

When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Fi…

Fix: 100.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2021-43532

The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows -…

Fix: 94.0+
Fix from $1,600 2021-12-08
Pollbot MEDIUM 6.1
CVE-2021-21354

Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release p…

Fix: 1.4.4+
Fix from $1,600 2021-03-08
Firefox MEDIUM 6.1
CVE-2020-26979

When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then red…

Fix: 84.0+
Fix from $1,600 2021-01-07
Firefox MEDIUM 6.1
CVE-2020-15677

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the …

Fix: 78.3 / 81.0+
Fix from $1,600 2020-10-01
Webthings Gateway MEDIUM 6.1
CVE-2020-6803

An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.

Fix: 2020-02-26+
Fix from $1,600 2020-02-28
Firefox MEDIUM 6.1
CVE-2017-5389

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests…

Fix: 51.0+
Fix from $1,600 2018-06-11
Firefox HIGH 8.8
CVE-2016-9078

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in…

Patch available
Fix from $1,950 2018-06-11