Vulnerabilities > Mozilla > Firefox > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-08 | CVE-2019-11763 | Cross-site Scripting vulnerability in multiple products Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. | 6.1 |
2020-01-08 | CVE-2019-11762 | Origin Validation Error vulnerability in multiple products If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. | 6.1 |
2020-01-08 | CVE-2019-11761 | Missing Authorization vulnerability in multiple products By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. | 5.4 |
2019-12-10 | CVE-2013-1689 | Improper Input Validation vulnerability in Mozilla Firefox Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames. | 6.5 |
2019-09-27 | CVE-2019-11754 | Unspecified vulnerability in Mozilla Firefox When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. | 4.3 |
2019-09-27 | CVE-2019-11750 | Use of Uninitialized Resource vulnerability in Mozilla Firefox A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. | 6.5 |
2019-09-27 | CVE-2019-11749 | Unspecified vulnerability in Mozilla Firefox A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. | 4.3 |
2019-09-27 | CVE-2019-11748 | Improper Preservation of Permissions vulnerability in Mozilla Firefox WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. | 6.5 |
2019-09-27 | CVE-2019-11747 | Improper Initialization vulnerability in Mozilla Firefox The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. | 6.5 |
2019-09-27 | CVE-2019-11744 | Cross-site Scripting vulnerability in Mozilla Firefox Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. | 6.1 |