Vulnerabilities > Mozilla > Firefox > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-25 | CVE-2020-6808 | Authentication Bypass by Spoofing vulnerability in Mozilla Firefox When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. | 6.5 |
2020-03-02 | CVE-2020-6798 | Cross-site Scripting vulnerability in Mozilla Thunderbird If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. | 6.1 |
2020-03-02 | CVE-2020-6797 | Improper Input Validation vulnerability in Mozilla Firefox By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. | 4.3 |
2020-02-18 | CVE-2013-5594 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding | 4.3 |
2020-01-21 | CVE-2011-2669 | Improper Certificate Validation vulnerability in Mozilla Firefox Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates. | 6.5 |
2020-01-13 | CVE-2011-2670 | Cross-site Scripting vulnerability in Mozilla Firefox Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets | 6.1 |
2020-01-08 | CVE-2019-17023 | Improper Authentication vulnerability in multiple products After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. | 6.5 |
2020-01-08 | CVE-2019-17022 | Cross-site Scripting vulnerability in multiple products When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. | 6.1 |
2020-01-08 | CVE-2019-17021 | Race Condition vulnerability in multiple products During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. | 5.3 |
2020-01-08 | CVE-2019-17020 | XXE vulnerability in multiple products If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. | 6.5 |