Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …
Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowin…
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR…
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal p…
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick u…
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thu…
Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in …
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. …
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to s…
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofin…
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfu…
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi…
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS…
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in t…
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <cod…
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpecte…
open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be…
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL ha…
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser,…
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol…
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefo…
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Fi…
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows -…
Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release p…
When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then red…
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the …
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests…
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in…