Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 14…
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability…
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could…
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential p…
A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific…
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be ap…