VYPR

Mozilla VPN

by Mozilla Corporation

Source repositories

CVEs (3)

  • CVE-2023-4104MedSep 11, 2023
    risk 0.00cvss 5.5epss 0.00

    An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN…

  • CVE-2020-15679HigDec 22, 2022
    risk 0.00cvss 7.6epss 0.00

    An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to cases where attacker and victim are sharing…

  • CVE-2021-29978CriAug 5, 2021
    risk 0.00cvss 9.8epss 0.03

    Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit. This vulnerability affects Mozilla VPN < 2.3.