Vulnerability index

Browse CVEs

81 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2022-34475 SVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via … Firefox 102.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-34473 The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however it incorrectly did not sanitiz… Firefox 102.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-31743 Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to es… Firefox 101.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-31744 An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Securit… Firefox 91.11 / 101.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-22748 Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. T… Firefox 91.5 / 96.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2021-43530 A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *… Firefox 94.0+ Fix from $1,6002021-12-08 MEDIUM 6.1 CVE-2021-43543 Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerabili… Firefox 91.4.0 / 95.0+ Fix from $1,6002021-12-08 MEDIUM 6.1 CVE-2021-43544 When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the … Firefox 95.0+ Fix from $1,6002021-12-08 MEDIUM 6.1 CVE-2021-29979 Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s prim… Hubs Cloud Mitigation only Fix from $1,6002021-08-02 MEDIUM 6.1 CVE-2021-29953 A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resu… Firefox 88.0.1 / 88.1.3+ Fix from $1,6002021-06-24 MEDIUM 6.1 CVE-2021-29944 Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTM… Firefox 88.0+ Fix from $1,6002021-06-24 MEDIUM 6.1 CVE-2011-3656 Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or… Firefox 3.6.24+ Fix from $1,6002021-06-02 MEDIUM 6.1 CVE-2021-23959 An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only… Firefox 85.0+ Fix from $1,6002021-02-26 MEDIUM 6.1 CVE-2020-26958 Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26951 A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capab… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26956 In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affect… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-15676 Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after past… Firefox 78.3 / 81.0+ Fix from $1,6002020-10-01 MEDIUM 6.1 CVE-2020-6798 If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A … Firefox 68.5.0 / 73.0+ Fix from $1,6002020-03-02 MEDIUM 6.1 CVE-2020-6804 A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication … Webthings Gateway 0.12.0+ Fix from $1,6002020-02-28 MEDIUM 6.1 CVE-2011-2670 Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets Firefox 3.6+ Fix from $1,6002020-01-13 MEDIUM 6.1 CVE-2019-17016 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could all… Firefox 68.4 / 72.0+ Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-17022 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the … Firefox 68.4 / 72.0+ Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-17001 A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-si… Firefox Mitigation only Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-17000 An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if … Firefox 70.0+ Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-11763 Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to H… Firefox 68.2 / 70.0+ Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-11744 Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to… Firefox 60.9 / 68.1+ Fix from $1,6002019-09-27 MEDIUM 6.1 CVE-2019-11741 A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded… Firefox 69.0+ Fix from $1,6002019-09-27 MEDIUM 6.1 CVE-2019-11720 Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows mal… Firefox 68.0+ Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2019-11715 Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web site… Firefox 60.8.0 / 68.0+ Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2019-11701 The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legac… Firefox 67.0+ Fix from $1,6002019-07-23