Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
CRITICAL 9.8 CVE-2025-55031 Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range … Firefox 142.0+ Fix from $2,3002025-08-19 MEDIUM 6.1 CVE-2025-55032 Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowin… Firefox Focus 142.0+ Fix from $1,6002025-08-19 CRITICAL 9.1 CVE-2025-54145 The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text UR… Firefox 141.0+ Fix from $2,3002025-08-19 MEDIUM 5.4 CVE-2025-54144 The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal p… Firefox 141.0+ Fix from $1,6002025-08-19 MEDIUM 6.1 CVE-2025-3859 Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick u… Firefox Focus 138.0+ Fix from $1,6002025-04-30 MEDIUM 6.3 CVE-2025-3522 Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thu… Thunderbird 128.9.2 / 137.0.2+ Fix from $1,6002025-04-15 MEDIUM 5.4 CVE-2025-27426 Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in … Firefox 136.0+ Fix from $1,6002025-03-04 MEDIUM 5.3 CVE-2025-0244EPSS 7% When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. … Firefox 134.0+ Fix from $1,6002025-01-07 MEDIUM 6.1 CVE-2024-8897EPSS 7% Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to s… Firefox 130.0.1+ Fix from $1,6002024-09-17 MEDIUM 6.1 CVE-2024-8386 If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofin… Firefox 128.2 / 130.0+ Fix from $1,6002024-09-03 HIGH 7.5 CVE-2024-4773 When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfu… Firefox 126.0+ Fix from $1,9502024-05-14 MEDIUM 6.1 CVE-2024-0953 When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi… Firefox No fix yet Fix from $1,6002024-02-05 MEDIUM 6.1 CVE-2023-49061 An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS… Firefox 120.0+ Fix from $1,6002023-11-21 MEDIUM 6.1 CVE-2023-34415 When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in t… Firefox 114.0+ Fix from $1,6002023-06-19 MEDIUM 6.1 CVE-2023-29540 Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <cod… Firefox 112.0+ Fix from $1,6002023-06-02 HIGH 8.1 CVE-2023-25734 After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpecte… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 MEDIUM 6.1 CVE-2022-0637 open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6 Pollbot 1.4.6+ Fix from $1,6002023-02-16 MEDIUM 6.1 CVE-2022-45413 Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be… Firefox 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-36316 When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL ha… Firefox 103.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-34478 The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser,… Firefox 91.11 / 102.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-34474 Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol… Firefox 102.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-29912 Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefo… Firefox 91.9 / 100.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-29910 When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Fi… Firefox 100.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2021-43532 The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows -… Firefox 94.0+ Fix from $1,6002021-12-08 MEDIUM 6.1 CVE-2021-21354 Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release p… Pollbot 1.4.4+ Fix from $1,6002021-03-08 MEDIUM 6.1 CVE-2020-26979 When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then red… Firefox 84.0+ Fix from $1,6002021-01-07 MEDIUM 6.1 CVE-2020-15677 By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the … Firefox 78.3 / 81.0+ Fix from $1,6002020-10-01 MEDIUM 6.1 CVE-2020-6803 An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in. Webthings Gateway 2020-02-26+ Fix from $1,6002020-02-28 MEDIUM 6.1 CVE-2017-5389 WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests… Firefox 51.0+ Fix from $1,6002018-06-11 HIGH 8.8 CVE-2016-9078 Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in… Firefox Patch available Fix from $1,9502018-06-11