Vulnerabilities > Mozilla > Firefox

DATE CVE VULNERABILITY TITLE RISK
2021-06-24 CVE-2021-29965 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Mozilla Firefox
A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the currently active website instead of the website that triggered the dialog.
network
low complexity
mozilla CWE-610
5.3
2021-06-24 CVE-2021-29966 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 88.
network
low complexity
mozilla CWE-787
8.8
2021-06-24 CVE-2021-29967 Out-of-bounds Write vulnerability in Mozilla Firefox ESR
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11.
network
low complexity
mozilla CWE-787
8.8
2021-06-24 CVE-2021-29968 Out-of-bounds Read vulnerability in Mozilla Firefox
When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur.
network
low complexity
mozilla CWE-125
8.1
2021-06-15 CVE-2021-30547 Out-of-bounds Write vulnerability in multiple products
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
network
low complexity
google debian fedoraproject mozilla CWE-787
8.8
2021-06-02 CVE-2011-3656 Cross-site Scripting vulnerability in Mozilla Firefox
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.
network
low complexity
mozilla CWE-79
6.1
2021-05-17 CVE-2007-5967 Unspecified vulnerability in Mozilla Firefox
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
network
low complexity
mozilla
6.5
2021-03-31 CVE-2021-23988 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 86.
network
low complexity
mozilla CWE-787
8.8
2021-03-31 CVE-2021-23987 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8.
network
low complexity
mozilla CWE-787
8.8
2021-03-31 CVE-2021-23986 Origin Validation Error vulnerability in Mozilla Firefox
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL.
network
low complexity
mozilla CWE-346
6.5