Vulnerabilities > Mozilla > Firefox > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-12-08 CVE-2021-43543 Cross-site Scripting vulnerability in multiple products
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content.
network
low complexity
mozilla debian CWE-79
6.1
2021-12-08 CVE-2021-43544 Cross-site Scripting vulnerability in Mozilla Firefox
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks.
network
low complexity
mozilla CWE-79
6.1
2021-12-08 CVE-2021-43545 Excessive Iteration vulnerability in multiple products
Using the Location API in a loop could have caused severe application hangs and crashes.
network
low complexity
mozilla debian CWE-834
6.5
2021-12-08 CVE-2021-43546 Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor.
network
low complexity
mozilla debian CWE-1021
4.3
2021-11-03 CVE-2021-38491 Unspecified vulnerability in Mozilla Firefox
Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded.
network
low complexity
mozilla
6.5
2021-11-03 CVE-2021-38492 Unspecified vulnerability in Mozilla Firefox
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode.
network
low complexity
mozilla
6.5
2021-11-03 CVE-2021-38497 Origin Validation Error vulnerability in Mozilla Firefox
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks.
network
low complexity
mozilla CWE-346
6.5
2021-08-17 CVE-2021-29982 Missing Release of Resource after Effective Lifetime vulnerability in Mozilla Firefox
Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory.
network
low complexity
mozilla CWE-772
6.5
2021-08-17 CVE-2021-29983 Unspecified vulnerability in Mozilla Firefox
Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit.
network
low complexity
mozilla
6.5
2021-08-17 CVE-2021-29987 Improper Restriction of Excessive Authentication Attempts vulnerability in Mozilla Firefox
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible to trick a user into accepting a permission they did not want to.
network
low complexity
mozilla CWE-307
6.5