Vulnerabilities > Mozilla > Firefox > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-26 | CVE-2021-23953 | Unspecified vulnerability in Mozilla Firefox If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. | 4.3 |
2021-02-26 | CVE-2021-23975 | Missing Authorization vulnerability in Mozilla Firefox The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. | 6.5 |
2021-02-26 | CVE-2021-23974 | Unspecified vulnerability in Mozilla Firefox The DOMParser API did not properly process '<noscript>' elements for escaping. | 6.1 |
2021-02-26 | CVE-2021-23973 | Information Exposure Through an Error Message vulnerability in multiple products When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. | 6.5 |
2021-02-26 | CVE-2021-23971 | Unspecified vulnerability in Mozilla Firefox When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. | 6.5 |
2021-02-26 | CVE-2021-23970 | Reachable Assertion vulnerability in Mozilla Firefox Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. | 6.5 |
2021-02-26 | CVE-2021-23969 | As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. | 4.3 |
2021-02-26 | CVE-2021-23968 | Information Exposure Through an Error Message vulnerability in multiple products If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. | 4.3 |
2021-01-08 | CVE-2020-16012 | Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | 4.3 |
2021-01-07 | CVE-2020-35111 | Unspecified vulnerability in Mozilla Firefox ESR When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. | 4.3 |