Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.4 CVE-2025-0237 The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the prin… Firefox 128.6.0 / 134.0+ Fix from $1,6002025-01-07 HIGH 8.8 CVE-2023-25729 Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them wi… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 MEDIUM 6.5 CVE-2023-23604 A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have l… Firefox 109.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2022-38475 An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not … Firefox 104.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-22754 If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grant… Firefox 91.6 / 97.0+ Fix from $1,6002022-12-22 CRITICAL 10.0 CVE-2021-38503 The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navig… Firefox 91.3 / 94.0+ Fix from $2,3002021-12-08 MEDIUM 6.5 CVE-2020-15664 By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object w… Firefox 68.12 / 78.2+ Fix from $1,6002020-10-01 HIGH 7.5 CVE-2020-12391 Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that … Firefox 76.0+ Fix from $1,9502020-05-26 HIGH 7.4 CVE-2019-17014 If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-o… Firefox 71.0+ Fix from $1,9502020-01-08 MEDIUM 6.1 CVE-2019-11724 Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to … Firefox 68.0+ Fix from $1,6002019-07-23 HIGH 8.8 CVE-2018-12391 During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the pro… Firefox 60.3 / 63.0+ Fix from $1,9502019-02-28 CRITICAL 9.8 CVE-2018-12369 WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain fu… Firefox 60.1.0 / 61.0+ Fix from $2,3002018-10-18