The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the prin…
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them wi…
A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have l…
An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not …
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grant…
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navig…
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object w…
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that …
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-o…
Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to …
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the pro…
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain fu…