VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,344)

  • CVE-2023-32212MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.01

    An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • CVE-2023-32205MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.01

    In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • CVE-2023-29538MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox <…

  • CVE-2023-29533MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.01

    A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This…

  • CVE-2023-28159MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects…

  • CVE-2023-25750MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.

  • CVE-2023-25749MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. Firefox will now confirm with users that they want to launch an external application before doing so. *This bug only affects Firefox for…

  • CVE-2023-25748MedJun 2, 2023
    risk 0.28cvss 4.3epss 0.00

    By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects…

  • CVE-2022-46877MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.01

    By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.

  • CVE-2022-45417MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk for websites visited in Private Browsing Mode. This would not have persisted them in a state where they would run again, but it would have…

  • CVE-2022-38474MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.*This bug…

  • CVE-2022-36315MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.

  • CVE-2022-34472MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.01

    If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

  • CVE-2022-31745MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101.

  • CVE-2022-29915MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.

  • CVE-2022-26383MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.01

    When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

  • CVE-2022-26382MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects…

  • CVE-2022-22762MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This…

  • CVE-2022-22749MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.00

    When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.

  • CVE-2022-22743MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.01

    When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

Page 99 of 168