VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,344)

  • CVE-2020-16012MedJan 8, 2021
    risk 0.28cvss 4.3epss 0.03

    Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-35111MedJan 7, 2021
    risk 0.28cvss 4.3epss 0.01

    When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This…

  • CVE-2020-26963MedDec 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introducing rate-limiting to these API calls. This vulnerability affects Firefox < 83.

  • CVE-2020-26954MedDec 9, 2020
    risk 0.28cvss 4.3epss 0.01

    When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to…

  • CVE-2020-26953MedDec 9, 2020
    risk 0.28cvss 4.3epss 0.01

    It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

  • CVE-2020-15668MedOct 1, 2020
    risk 0.28cvss 4.3epss 0.01

    A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

  • CVE-2020-15665MedOct 1, 2020
    risk 0.28cvss 4.3epss 0.01

    Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulted in an incorrect URL being shown when used in conjunction with other unexpected browser behaviors. This vulnerability affects Firefox <…

  • CVE-2020-15651MedAug 10, 2020
    risk 0.28cvss 4.3epss 0.01

    A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.

  • CVE-2020-12412MedJul 9, 2020
    risk 0.28cvss 4.3epss 0.01

    By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock icon) while controlling the page contents. This vulnerability affects Firefox < 70.

  • CVE-2020-12404MedJul 9, 2020
    risk 0.28cvss 4.3epss 0.01

    For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.

  • CVE-2020-6810MedMar 25, 2020
    risk 0.28cvss 4.3epss 0.01

    After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin…

  • CVE-2020-6797MedMar 2, 2020
    risk 0.28cvss 4.3epss 0.01

    By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application,…

  • CVE-2013-5594MedFeb 18, 2020
    risk 0.28cvss 4.3epss 0.01

    Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding

  • CVE-2019-17002MedJan 8, 2020
    risk 0.28cvss 4.3epss 0.01

    If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.

  • CVE-2019-11754MedSep 27, 2019
    risk 0.28cvss 4.3epss 0.01

    When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1.

  • CVE-2019-11749MedSep 27, 2019
    risk 0.28cvss 4.3epss 0.01

    A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting…

  • CVE-2019-11695MedJul 23, 2019
    risk 0.28cvss 4.3epss 0.01

    A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts,…

  • CVE-2019-9807MedApr 26, 2019
    risk 0.28cvss 4.3epss 0.01

    When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66.

  • CVE-2018-18511MedApr 26, 2019
    risk 0.28cvss 4.3epss 0.02

    Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

  • CVE-2018-12399MedFeb 28, 2019
    risk 0.28cvss 4.3epss 0.01

    When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability…

Page 101 of 168