Vulnerabilities > Mozilla > Firefox > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-22759 Unspecified vulnerability in Mozilla Firefox
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g.
network
low complexity
mozilla
critical
9.6
2022-12-22 CVE-2022-1887 SQL Injection vulnerability in Mozilla Firefox
The search term could have been specified externally to trigger SQL injection.
network
low complexity
mozilla CWE-89
critical
9.8
2022-12-22 CVE-2021-4140 XML Injection (aka Blind XPath Injection) vulnerability in Mozilla Firefox
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.
network
low complexity
mozilla CWE-91
critical
10.0
2022-12-22 CVE-2021-4129 Out-of-bounds Write vulnerability in Mozilla Firefox ESR
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94.
network
low complexity
mozilla CWE-787
critical
9.8
2021-12-08 CVE-2021-38503 Incorrect Authorization vulnerability in multiple products
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame.
network
low complexity
mozilla debian CWE-863
critical
10.0
2021-08-05 CVE-2021-29971 Improper Preservation of Permissions vulnerability in Mozilla Firefox
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission.
network
low complexity
mozilla CWE-281
critical
9.8
2021-01-07 CVE-2020-26972 Use After Free vulnerability in Mozilla Firefox
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to.
network
low complexity
mozilla CWE-416
critical
9.8
2020-10-22 CVE-2020-15683 Use After Free vulnerability in multiple products
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3.
network
low complexity
mozilla debian opensuse CWE-416
critical
9.8
2020-10-22 CVE-2020-15684 Use After Free vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 81.
network
low complexity
mozilla CWE-416
critical
9.8
2020-05-26 CVE-2020-12388 Improper Input Validation vulnerability in Mozilla Firefox
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape.
network
low complexity
mozilla CWE-20
critical
10.0