A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel insid…
Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow f…
If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly di…
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious e…
A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting it, it could result in an out-…
Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…
A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potenti…
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with …
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirem…
The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properl…
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded for…
When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site …
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when…
The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing pr…
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the reques…
If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible wi…
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document …
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue wa…
The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could all…
Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an International…
Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…
A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread …
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due …
A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulner…
A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collection on memory that is now un…
A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. Thi…
A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This…
Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…
The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allow…
Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resources that redirect from HTTPS…