VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,344)

  • CVE-2022-34473MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    The HTML Sanitizer should have sanitized the href attribute of SVG <use> tags; however it incorrectly did not sanitize xlink:href attributes. This vulnerability affects Firefox < 102.

  • CVE-2022-29912MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.01

    Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29911MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.01

    An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29910MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 100.

  • CVE-2021-43544MedDec 8, 2021
    risk 0.40cvss 6.1epss 0.01

    When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other…

  • CVE-2021-43543MedDec 8, 2021
    risk 0.40cvss 6.1epss 0.01

    Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43532MedDec 8, 2021
    risk 0.40cvss 6.1epss 0.01

    The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one…

  • CVE-2021-43530MedDec 8, 2021
    risk 0.40cvss 6.1epss 0.01

    A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

  • CVE-2021-29953MedJun 24, 2021
    risk 0.40cvss 6.1epss 0.01

    A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating…

  • CVE-2021-29944MedJun 24, 2021
    risk 0.40cvss 6.1epss 0.01

    Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This…

  • CVE-2011-3656MedJun 2, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

  • CVE-2021-23959MedFeb 26, 2021
    risk 0.40cvss 6.1epss 0.01

    An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

  • CVE-2021-23955MedFeb 26, 2021
    risk 0.40cvss 6.1epss 0.01

    The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.

  • CVE-2021-23974MedFeb 26, 2021
    risk 0.40cvss 6.1epss 0.01

    The DOMParser API did not properly process '' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.

  • CVE-2020-26979MedJan 7, 2021
    risk 0.40cvss 6.1epss 0.01

    When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have…

  • CVE-2020-26978MedJan 7, 2021
    risk 0.40cvss 6.1epss 0.01

    Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

  • CVE-2020-26962MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox…

  • CVE-2020-26958MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.01

    Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox <…

  • CVE-2020-26956MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.01

    In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

  • CVE-2020-26951MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.01

    A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer.…

Page 83 of 168