Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Firefox MEDIUM 5.4
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the prin…

Fix: 128.6.0 / 134.0+
Fix from $1,600 2025-01-07
Firefox HIGH 8.8
CVE-2023-25729

Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them wi…

Fix: 102.8 / 110.0+
Fix from $1,950 2023-06-02
Firefox MEDIUM 6.5
CVE-2023-23604

A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have l…

Fix: 109.0+
Fix from $1,600 2023-06-02
Firefox MEDIUM 6.5
CVE-2022-38475

An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not …

Fix: 104.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22754

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grant…

Fix: 91.6 / 97.0+
Fix from $1,600 2022-12-22
Firefox CRITICAL 10.0
CVE-2021-38503

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navig…

Fix: 91.3 / 94.0+
Fix from $2,300 2021-12-08
Firefox MEDIUM 6.5
CVE-2020-15664

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object w…

Fix: 68.12 / 78.2+
Fix from $1,600 2020-10-01
Firefox HIGH 7.5
CVE-2020-12391

Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that …

Fix: 76.0+
Fix from $1,950 2020-05-26
Firefox HIGH 7.4
CVE-2019-17014

If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-o…

Fix: 71.0+
Fix from $1,950 2020-01-08
Firefox MEDIUM 6.1
CVE-2019-11724

Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to …

Fix: 68.0+
Fix from $1,600 2019-07-23
Firefox HIGH 8.8
CVE-2018-12391

During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the pro…

Fix: 60.3 / 63.0+
Fix from $1,950 2019-02-28
Firefox CRITICAL 9.8
CVE-2018-12369

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain fu…

Fix: 60.1.0 / 61.0+
Fix from $2,300 2018-10-18