🚨 CVE-2020-12400
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1623116 - (CVE-2020-12400) P-384 and P-521 implementation uses a side-channel vulnerable modular inversion function
RESOLVED (bbeurdouche) in NSS - Libraries. Last updated 2021-11-22.
🚨 CVE-2020-12401
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1631573 - (CVE-2020-12401) ECDSA Timing Countermeasure Bypass
RESOLVED (bbeurdouche) in NSS - Libraries. Last updated 2021-09-23.
🚨 CVE-2020-6829
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
🎖@cveNotify
bugzilla.mozilla.org
1631583 - (CVE-2020-6829) Side channel attack on ECDSA signature generation
RESOLVED (kjacobs.bugzilla) in NSS - Libraries. Last updated 2024-06-17.
🚨 CVE-2020-26954
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
bugzilla.mozilla.org
1657026 - (CVE-2020-26954) Any websites can run with PWA privileges on Fenix
RESOLVED (s.kaspari) in Firefox for Android - General. Last updated 2024-05-30.
🚨 CVE-2020-26955
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
bugzilla.mozilla.org
1663261 - (CVE-2020-26955) Fenix file download request shares private browsing mode cookie
RESOLVED (amejiamarmol) in Firefox for Android - General. Last updated 2024-05-30.
🚨 CVE-2020-26957
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
bugzilla.mozilla.org
1667179 - (CVE-2020-26957) OneCRL does not appear to be working in Fenix
RESOLVED (agi) in GeckoView - General. Last updated 2022-06-02.
🚨 CVE-2020-26964
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
🎖@cveNotify
bugzilla.mozilla.org
1658865 - (CVE-2020-26964) Untrusted apps can connect Fenix's remote debugging socket on older Android devices
RESOLVED (mcarare) in Firefox for Android - General. Last updated 2024-05-30.
🚨 CVE-2020-26975
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
🎖@cveNotify
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
🎖@cveNotify
bugzilla.mozilla.org
1661071 - (CVE-2020-26975) Missing restricted header check in Browser.EXTRA_HEADERS
RESOLVED (s.kaspari) in Firefox for Android - General. Last updated 2024-05-30.
🚨 CVE-2020-26977
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
🎖@cveNotify
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
🎖@cveNotify
bugzilla.mozilla.org
1676311 - (CVE-2020-26977) Spoof URL by connecting to an invalid port with a setTimeout call in the originating tab
RESOLVED (nobody) in Firefox for Android - General. Last updated 2022-11-03.
🚨 CVE-2021-29993
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.
🎖@cveNotify
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.
🎖@cveNotify
🚨 CVE-2022-26486
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
🎖@cveNotify
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
🎖@cveNotify
bugzilla.mozilla.org
1758070 - (CVE-2022-26486) UAF in Webgpu status manager [exploited in the wild]
RESOLVED (nical.bugzilla) in Core - Graphics: WebGPU. Last updated 2024-05-30.
🚨 CVE-2022-31746
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
🎖@cveNotify
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
🎖@cveNotify
bugzilla.mozilla.org
1654416 - (CVE-2022-31746) Bypass privileged internal: URL protetion through referrer
RESOLVED (nobody) in Firefox for iOS - Reader View. Last updated 2024-09-15.
🚨 CVE-2022-38474
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.
🎖@cveNotify
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.
🎖@cveNotify
bugzilla.mozilla.org
1719511 - (CVE-2022-38474) No recording notification for microphone
RESOLVED (amejiamarmol) in Firefox for Android - General. Last updated 2023-01-16.
🚨 CVE-2019-17003
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
🎖@cveNotify
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
🎖@cveNotify
bugzilla.mozilla.org
1567118 - (CVE-2019-17003) Improper parsing of QR codes in address bar leads to XSS
RESOLVED (nobody) in Firefox for iOS - Browser. Last updated 2024-05-30.
🚨 CVE-2023-29533
A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> assignments, and <code>setInterval</code> calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
🎖@cveNotify
A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> assignments, and <code>setInterval</code> calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
🎖@cveNotify
bugzilla.mozilla.org
1798219 - Run requestFullscreen and reuse window.open simultaneously in blocking event loop able to overlap fullscreen notification
VERIFIED (echen) in Core - DOM: Core & HTML. Last updated 2024-05-30.
🚨 CVE-2023-29535
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
🎖@cveNotify
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
🎖@cveNotify
bugzilla.mozilla.org
1820543 - (CVE-2023-29535) Assertion failure: this->flags() == 0, at gc/Cell.h:836
RESOLVED (jcoppeard) in Core - JavaScript: GC. Last updated 2024-05-30.
🚨 CVE-2023-29536
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
🎖@cveNotify
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
🎖@cveNotify
bugzilla.mozilla.org
1821959 - (CVE-2023-29536) MOZ_DIAGNOSTIC_ASSERT in mozjemalloc from background thread free()
RESOLVED (tcampbell) in Core - JavaScript Engine. Last updated 2024-05-30.
🚨 CVE-2023-29537
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
🎖@cveNotify
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
🎖@cveNotify
bugzilla.mozilla.org
1823365 - (CVE-2023-29537) initialization race leading to use after free in MakeGlyphAtlas()
VERIFIED (jfkthame) in Core - Graphics: Text. Last updated 2024-05-30.
🚨 CVE-2023-29538
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
🎖@cveNotify
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
🎖@cveNotify
bugzilla.mozilla.org
1685403 - (CVE-2023-29538) onLoadRequest contains translated jar:file:/// URI instead of moz-extension:///
RESOLVED (kershaw) in Core - Networking. Last updated 2025-01-15.
🚨 CVE-2023-29539
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
🎖@cveNotify
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
🎖@cveNotify
bugzilla.mozilla.org
1784348 - (CVE-2023-29539) Content-Disposition filename truncation leads to Reflected File Download
RESOLVED (smayya) in Core - Networking: HTTP. Last updated 2024-05-30.
🚨 CVE-2023-29540
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
🎖@cveNotify
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
🎖@cveNotify
bugzilla.mozilla.org
1790542 - (CVE-2023-29540) allow-top-navigation-to-custom-protocols iframe sandbox bypass using sourceMappingUrls
VERIFIED (hmanilla) in DevTools - Console. Last updated 2025-07-07.