Vulnerabilities > Mozilla

DATE CVE VULNERABILITY TITLE RISK
2020-05-26 CVE-2020-12396 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers and community members reported memory safety bugs present in Firefox 75.
network
low complexity
mozilla CWE-787
critical
9.8
2020-05-26 CVE-2020-12395 Out-of-bounds Write vulnerability in multiple products
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7.
network
low complexity
mozilla canonical CWE-787
critical
9.8
2020-05-26 CVE-2020-12394 Unspecified vulnerability in Mozilla Firefox
A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element.
local
low complexity
mozilla
3.3
2020-05-26 CVE-2020-12393 OS Command Injection vulnerability in Mozilla Firefox
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website.
local
low complexity
mozilla CWE-78
7.8
2020-05-22 CVE-2020-12397 Origin Validation Error vulnerability in multiple products
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays.
network
low complexity
mozilla canonical CWE-346
4.3
2020-04-24 CVE-2020-6828 Path Traversal vulnerability in Mozilla Firefox ESR
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory.
network
low complexity
mozilla CWE-22
7.5
2020-04-24 CVE-2020-6827 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox ESR
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI.
network
low complexity
mozilla CWE-1021
4.7
2020-04-24 CVE-2020-6826 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74.
network
low complexity
mozilla CWE-787
critical
9.8
2020-04-24 CVE-2020-6825 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6.
network
low complexity
mozilla CWE-787
critical
9.8
2020-04-24 CVE-2020-6824 Session Fixation vulnerability in Mozilla Firefox
Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open.
local
low complexity
mozilla CWE-384
2.8