🚨 CVE-2020-15661
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.
🎖@cveNotify
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.
🎖@cveNotify
bugzilla.mozilla.org
1654131 - (CVE-2020-15661) Rogue LoginsHelper (password manager) can be injected by untrusted web contents
RESOLVED (gkeeley) in Firefox for iOS - Login Management. Last updated 2024-05-30.
🚨 CVE-2020-15662
A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS < 28.
🎖@cveNotify
A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS < 28.
🎖@cveNotify
bugzilla.mozilla.org
1653827 - (CVE-2020-15662) Rogue download handler can be injected by any web contents
RESOLVED (gkeeley) in Firefox for iOS - Browser. Last updated 2024-05-30.
🚨 CVE-2020-15664
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.
🎖@cveNotify
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1658214 - (CVE-2020-15664) InstallTrigger can take the principal from the wrong inner window when initialized
RESOLVED (kmaglione+bmo) in Toolkit - Add-ons Manager. Last updated 2024-05-30.
🚨 CVE-2020-15666
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1450853 - (CVE-2020-15666) MediaError message property leaks cross-origin response status
RESOLVED (sstreich) in Core - DOM: Security. Last updated 2024-05-30.
🚨 CVE-2020-15668
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1651520 - (CVE-2020-15668) ThreadSanitizer: data race [@ NSC_GetTokenInfo] vs. [@ NSC_CloseSession]
RESOLVED (jc) in NSS - Libraries. Last updated 2021-11-22.
🚨 CVE-2020-15670
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.
🎖@cveNotify
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.
🎖@cveNotify
🚨 CVE-2020-15671
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.
🎖@cveNotify
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1653862 - (CVE-2020-15671) Firefox save gmail password into phone dicrtionarty
VERIFIED (m_kato) in GeckoView - General. Last updated 2020-12-18.
🚨 CVE-2020-12400
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1623116 - (CVE-2020-12400) P-384 and P-521 implementation uses a side-channel vulnerable modular inversion function
RESOLVED (bbeurdouche) in NSS - Libraries. Last updated 2021-11-22.
🚨 CVE-2020-12401
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1631573 - (CVE-2020-12401) ECDSA Timing Countermeasure Bypass
RESOLVED (bbeurdouche) in NSS - Libraries. Last updated 2021-09-23.
🚨 CVE-2020-6829
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1631583 - (CVE-2020-6829) Side channel attack on ECDSA signature generation
RESOLVED (kjacobs.bugzilla) in NSS - Libraries. Last updated 2024-06-17.
🚨 CVE-2020-26954
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
bugzilla.mozilla.org
1657026 - (CVE-2020-26954) Any websites can run with PWA privileges on Fenix
RESOLVED (s.kaspari) in Firefox for Android - General. Last updated 2024-05-30.
🚨 CVE-2020-26955
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
bugzilla.mozilla.org
1663261 - (CVE-2020-26955) Fenix file download request shares private browsing mode cookie
RESOLVED (amejiamarmol) in Firefox for Android - General. Last updated 2024-05-30.
🚨 CVE-2020-26957
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
bugzilla.mozilla.org
1667179 - (CVE-2020-26957) OneCRL does not appear to be working in Fenix
RESOLVED (agi) in GeckoView - General. Last updated 2022-06-02.
🚨 CVE-2020-26964
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
bugzilla.mozilla.org
1658865 - (CVE-2020-26964) Untrusted apps can connect Fenix's remote debugging socket on older Android devices
RESOLVED (mcarare) in Firefox for Android - General. Last updated 2024-05-30.
🚨 CVE-2020-26975
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
🎖@cveNotify
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
🎖@cveNotify
bugzilla.mozilla.org
1661071 - (CVE-2020-26975) Missing restricted header check in Browser.EXTRA_HEADERS
RESOLVED (s.kaspari) in Firefox for Android - General. Last updated 2024-05-30.
🚨 CVE-2020-26977
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
🎖@cveNotify
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
🎖@cveNotify
bugzilla.mozilla.org
1676311 - (CVE-2020-26977) Spoof URL by connecting to an invalid port with a setTimeout call in the originating tab
RESOLVED (nobody) in Firefox for Android - General. Last updated 2022-11-03.
🚨 CVE-2021-29993
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.
🎖@cveNotify
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.
🎖@cveNotify
🚨 CVE-2022-26486
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
🎖@cveNotify
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
🎖@cveNotify
bugzilla.mozilla.org
1758070 - (CVE-2022-26486) UAF in Webgpu status manager [exploited in the wild]
RESOLVED (nical.bugzilla) in Core - Graphics: WebGPU. Last updated 2024-05-30.
🚨 CVE-2022-31746
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
🎖@cveNotify
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
🎖@cveNotify
bugzilla.mozilla.org
1654416 - (CVE-2022-31746) Bypass privileged internal: URL protetion through referrer
RESOLVED (nobody) in Firefox for iOS - Reader View. Last updated 2024-09-15.
🚨 CVE-2022-38474
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.
🎖@cveNotify
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.
🎖@cveNotify
bugzilla.mozilla.org
1719511 - (CVE-2022-38474) No recording notification for microphone
RESOLVED (amejiamarmol) in Firefox for Android - General. Last updated 2023-01-16.
🚨 CVE-2019-17003
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
🎖@cveNotify
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
🎖@cveNotify
bugzilla.mozilla.org
1567118 - (CVE-2019-17003) Improper parsing of QR codes in address bar leads to XSS
RESOLVED (nobody) in Firefox for iOS - Browser. Last updated 2024-05-30.