Vulnerability index

Browse CVEs

81 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Firefox MEDIUM 6.1
CVE-2022-34475

SVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via …

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-34473

The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however it incorrectly did not sanitiz…

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-31743

Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to es…

Fix: 101.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-31744

An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Securit…

Fix: 91.11 / 101.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22748

Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. T…

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2021-43530

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *…

Fix: 94.0+
Fix from $1,600 2021-12-08
Firefox MEDIUM 6.1
CVE-2021-43543

Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerabili…

Fix: 91.4.0 / 95.0+
Fix from $1,600 2021-12-08
Firefox MEDIUM 6.1
CVE-2021-43544

When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the …

Fix: 95.0+
Fix from $1,600 2021-12-08
Hubs Cloud MEDIUM 6.1
CVE-2021-29979

Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s prim…

Mitigation only
Fix from $1,600 2021-08-02
Firefox MEDIUM 6.1
CVE-2021-29953

A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resu…

Fix: 88.0.1 / 88.1.3+
Fix from $1,600 2021-06-24
Firefox MEDIUM 6.1
CVE-2021-29944

Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTM…

Fix: 88.0+
Fix from $1,600 2021-06-24
Firefox MEDIUM 6.1
CVE-2011-3656

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or…

Fix: 3.6.24+
Fix from $1,600 2021-06-02
Firefox MEDIUM 6.1
CVE-2021-23959

An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only…

Fix: 85.0+
Fix from $1,600 2021-02-26
Firefox MEDIUM 6.1
CVE-2020-26958

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could…

Fix: 78.5 / 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.1
CVE-2020-26951

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capab…

Fix: 78.5 / 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.1
CVE-2020-26956

In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affect…

Fix: 78.5 / 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.1
CVE-2020-15676

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after past…

Fix: 78.3 / 81.0+
Fix from $1,600 2020-10-01
Firefox MEDIUM 6.1
CVE-2020-6798

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A …

Fix: 68.5.0 / 73.0+
Fix from $1,600 2020-03-02
Webthings Gateway MEDIUM 6.1
CVE-2020-6804

A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication …

Fix: 0.12.0+
Fix from $1,600 2020-02-28
Firefox MEDIUM 6.1
CVE-2011-2670

Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets

Fix: 3.6+
Fix from $1,600 2020-01-13
Firefox MEDIUM 6.1
CVE-2019-17016

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could all…

Fix: 68.4 / 72.0+
Fix from $1,600 2020-01-08
Firefox MEDIUM 6.1
CVE-2019-17022

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the …

Fix: 68.4 / 72.0+
Fix from $1,600 2020-01-08
Firefox MEDIUM 6.1
CVE-2019-17001

A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-si…

Mitigation only
Fix from $1,600 2020-01-08
Firefox MEDIUM 6.1
CVE-2019-17000

An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if …

Fix: 70.0+
Fix from $1,600 2020-01-08
Firefox MEDIUM 6.1
CVE-2019-11763

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to H…

Fix: 68.2 / 70.0+
Fix from $1,600 2020-01-08
Firefox MEDIUM 6.1
CVE-2019-11744

Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to…

Fix: 60.9 / 68.1+
Fix from $1,600 2019-09-27
Firefox MEDIUM 6.1
CVE-2019-11741

A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded…

Fix: 69.0+
Fix from $1,600 2019-09-27
Firefox MEDIUM 6.1
CVE-2019-11720

Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows mal…

Fix: 68.0+
Fix from $1,600 2019-07-23
Firefox MEDIUM 6.1
CVE-2019-11715

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web site…

Fix: 60.8.0 / 68.0+
Fix from $1,600 2019-07-23
Firefox MEDIUM 6.1
CVE-2019-11701

The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legac…

Fix: 67.0+
Fix from $1,600 2019-07-23