Vulnerabilities > Mozilla > Firefox > 84.0

DATE CVE VULNERABILITY TITLE RISK
2021-02-26 CVE-2021-23961 Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine.
network
low complexity
mozilla debian
7.4
2021-02-26 CVE-2021-23960 Unspecified vulnerability in Mozilla Firefox
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash.
network
low complexity
mozilla
8.8
2021-02-26 CVE-2021-23959 Cross-site Scripting vulnerability in Mozilla Firefox
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar.
network
low complexity
mozilla CWE-79
6.1
2021-02-26 CVE-2021-23958 Exposure of Resource to Wrong Sphere vulnerability in Mozilla Firefox
The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information.
network
low complexity
mozilla CWE-668
6.5
2021-02-26 CVE-2021-23957 Unspecified vulnerability in Mozilla Firefox
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox.
network
low complexity
mozilla
7.4
2021-02-26 CVE-2021-23956 Unspecified vulnerability in Mozilla Firefox
An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory.
network
low complexity
mozilla
6.5
2021-02-26 CVE-2021-23955 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox
The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks.
network
low complexity
mozilla CWE-1021
6.1
2021-02-26 CVE-2021-23954 Type Confusion vulnerability in Mozilla Firefox
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash.
network
low complexity
mozilla CWE-843
8.8
2021-02-26 CVE-2021-23953 Unspecified vulnerability in Mozilla Firefox
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data.
network
low complexity
mozilla
4.3
2021-02-26 CVE-2021-23976 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins.
network
low complexity
mozilla CWE-1021
8.1