VYPR

VPN

by Mozilla Corporation

Source repositories

CVEs (4)

  • CVE-2022-0517HigDec 22, 2022
    risk 0.51cvss 7.8epss 0.00

    Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1.

  • CVE-2025-5687HigJun 11, 2025
    risk 0.44cvss 7.8epss 0.00

    A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.*. This vulnerability was fixed in Mozilla VPN 2.28.0 (macOS).

  • CVE-2023-4104MedSep 11, 2023
    risk 0.00cvss 5.5epss 0.00

    An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN…

  • CVE-2020-15679HigDec 22, 2022
    risk 0.00cvss 7.6epss 0.00

    An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to cases where attacker and victim are sharing…