mozilla / firefox_mobile
61 known vulnerabilities in mozilla firefox_mobile.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2022-26485 | Act now | 14.3% | 8.8 | ● | Removing an XSLT parameter during processing could have lead to an exploitable u… |
| CVE-2022-26486 | Act now | 2.3% | 9.6 | ● | An unexpected message in the WebGPU IPC framework could lead to a use-after-free… |
| CVE-2020-15670 | Medium | 1.1% | 8.8 | Mozilla developers reported memory safety bugs present in Firefox for Android 79… | |
| CVE-2020-6830 | Medium | 0.9% | 7.5 | For native-to-JS bridging, the app requires a unique token to be passed that ens… | |
| CVE-2023-29541 | Medium | 0.7% | 8.8 | Firefox did not properly handle downloads of files ending in <code>.desktop</cod… | |
| CVE-2023-29539 | Medium | 0.7% | 8.8 | When handling the filename directive in the Content-Disposition header, the file… | |
| CVE-2021-29993 | Medium | 0.7% | 8.1 | Firefox for Android allowed navigations through the `intent://` protocol, which … | |
| CVE-2023-29536 | Medium | 0.7% | 8.8 | An attacker could cause the memory manager to incorrectly free a pointer that ad… | |
| CVE-2023-29550 | Medium | 0.7% | 8.8 | Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these b… | |
| CVE-2023-29534 | Medium | 0.7% | 9.1 | Different techniques existed to obscure the fullscreen notification in Firefox a… | |
| CVE-2023-49060 | Medium | 0.6% | 9.8 | An attacker could have accessed internal pages or data by ex-filtrating a securi… | |
| CVE-2023-25747 | Medium | 0.6% | 7.5 | A potential use-after-free in libaudio was fixed by disabling the AAudio backend… | |
| CVE-2023-29537 | Medium | 0.6% | 7.5 | Multiple race conditions in the font initialization could have led to memory cor… | |
| CVE-2023-29543 | Medium | 0.5% | 8.8 | An attacker could have caused memory corruption and a potentially exploitable us… | |
| CVE-2023-29551 | Medium | 0.5% | 8.8 | Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of… | |
| CVE-2024-7523 | Medium | 0.3% | 8.1 | A select option could partially obscure security prompts. This could be used by … | |
| CVE-2026-16373 | Medium | 0.3% | 7.5 | Information disclosure in the Privacy component in Firefox for Android. This vul… | |
| CVE-2026-84135 | Medium | 0.3% | 9.8 | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefo… | |
| CVE-2026-84117 | Medium | 0.2% | 8.8 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Fir… | |
| CVE-2026-16404 | Medium | 0.2% | 7.4 | Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 1… | |
| CVE-2020-6829 | Low | 1.5% | 5.3 | When performing EC scalar point multiplication, the wNAF point multiplication al… | |
| CVE-2020-15664 | Low | 1.4% | 6.5 | By holding a reference to the eval() function from an about:blank window, a mali… | |
| CVE-2020-15666 | Low | 1.2% | 6.5 | When trying to load a non-video in an audio/video context the exact status code … | |
| CVE-2020-26964 | Low | 0.9% | 6.8 | If the Remote Debugging via USB feature was enabled in Firefox for Android on an… | |
| CVE-2020-26975 | Low | 0.9% | 6.5 | When a malicious application installed on the user's device broadcast an Intent … | |
| CVE-2020-26977 | Low | 0.9% | 6.5 | By attempting to connect a website using an unresponsive port, an attacker could… | |
| CVE-2020-15661 | Low | 0.8% | 6.5 | A rogue webpage could override the injected WKUserScript used by the logins auto… | |
| CVE-2020-26955 | Low | 0.8% | 6.5 | When a user downloaded a file in Firefox for Android, if a cookie is set, it wou… | |
| CVE-2020-12404 | Low | 0.8% | 4.3 | For native-to-JS bridging the app requires a unique token to be passed that ensu… | |
| CVE-2023-29535 | Low | 0.7% | 6.5 | Following a Garbage Collector compaction, weak maps may have been accessed befor… | |
| CVE-2023-29548 | Low | 0.7% | 6.5 | A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optim… | |
| CVE-2020-12414 | Low | 0.7% | 6.5 | IndexedDB should be cleared when leaving private browsing mode and it is not, th… | |
| CVE-2020-15662 | Low | 0.7% | 6.5 | A rogue webpage could override the injected WKUserScript used by the download fe… | |
| CVE-2020-26954 | Low | 0.6% | 4.3 | When accepting a malicious intent from other installed apps, Firefox for Android… | |
| CVE-2023-29533 | Low | 0.6% | 4.3 | A website could have obscured the fullscreen notification by using a combination… | |
| CVE-2020-26957 | Low | 0.5% | 6.5 | OneCRL was non-functional in the new Firefox for Android due to a missing servic… | |
| CVE-2020-15668 | Low | 0.5% | 4.3 | A lock was missing when accessing a data structure and importing certificate inf… | |
| CVE-2023-29546 | Low | 0.5% | 6.5 | When recording the screen while in Private Browsing on Firefox for Android the a… | |
| CVE-2020-15671 | Low | 0.5% | 3.1 | When typing in a password under certain conditions, a race may have occured wher… | |
| CVE-2023-29544 | Low | 0.4% | 6.5 | If multiple instances of resource exhaustion occurred at the incorrect time, the… | |
| CVE-2023-5758 | Low | 0.4% | 6.1 | When opening a page in reader mode, the redirect URL could have caused attacker-… | |
| CVE-2022-31746 | Low | 0.4% | 6.5 | Internal URLs are protected by a secret UUID key, which could have been leaked t… | |
| CVE-2019-17003 | Low | 0.4% | 6.1 | Scanning a QR code that contained a javascript: URL would have resulted in the J… | |
| CVE-2023-29538 | Low | 0.4% | 4.3 | Under specific circumstances a WebExtension may have received a <code>jar:file:/… | |
| CVE-2022-38474 | Low | 0.4% | 4.3 | A website that had permission to access the microphone could record audio withou… | |
| CVE-2023-29549 | Low | 0.3% | 6.5 | Under certain circumstances, a call to the <code>bind</code> function may have r… | |
| CVE-2020-12401 | Low | 0.3% | 4.7 | During ECDSA signature generation, padding applied in the nonce designed to ensu… | |
| CVE-2023-29540 | Low | 0.3% | 6.1 | Using a redirect embedded into <code>sourceMappingUrls</code> could allow for na… | |
| CVE-2023-49061 | Low | 0.3% | 6.1 | An attacker could have performed HTML template injection via Reader Mode and exf… | |
| CVE-2024-0953 | Low | 0.3% | 6.1 | When a user scans a QR Code with the QR Code Scanner feature, the user is not pr… |
Page 1 of 2
Next →