Vulnerabilities > Mozilla > Firefox > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-03 CVE-2021-38497 Origin Validation Error vulnerability in Mozilla Firefox
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks.
network
low complexity
mozilla CWE-346
6.5
2021-08-17 CVE-2021-29982 Missing Release of Resource after Effective Lifetime vulnerability in Mozilla Firefox
Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory.
network
low complexity
mozilla CWE-772
6.5
2021-08-17 CVE-2021-29983 Unspecified vulnerability in Mozilla Firefox
Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit.
network
low complexity
mozilla
6.5
2021-08-17 CVE-2021-29987 Improper Restriction of Excessive Authentication Attempts vulnerability in Mozilla Firefox
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible to trick a user into accepting a permission they did not want to.
network
low complexity
mozilla CWE-307
6.5
2021-08-05 CVE-2021-29974 Unspecified vulnerability in Mozilla Firefox
When network partitioning was enabled, e.g.
network
low complexity
mozilla
4.3
2021-08-05 CVE-2021-29975 Unspecified vulnerability in Mozilla Firefox
Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly shown in the address bar) resulting in possible user confusion.
network
low complexity
mozilla
6.5
2021-06-24 CVE-2021-23996 Unspecified vulnerability in Mozilla Firefox
By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, resulting in a spoofing attack that could have been used for phishing or other attacks on a user.
network
low complexity
mozilla
6.5
2021-06-24 CVE-2021-23998 Insufficient Verification of Data Authenticity vulnerability in Mozilla Thunderbird
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page.
network
low complexity
mozilla CWE-345
6.5
2021-06-24 CVE-2021-24001 Exposure of Resource to Wrong Sphere vulnerability in Mozilla Firefox
A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-only configurations.
network
low complexity
mozilla CWE-668
4.3
2021-06-24 CVE-2021-29944 Cross-site Scripting vulnerability in Mozilla Firefox
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View.
network
low complexity
mozilla CWE-79
6.1