Vulnerabilities > Mozilla > Low

DATE CVE VULNERABILITY TITLE RISK
2015-09-24 CVE-2015-4508 7PK - Security Features vulnerability in Mozilla Firefox
Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.
network
high complexity
mozilla CWE-254
2.6
2015-08-08 CVE-2015-5960 Improper Access Control vulnerability in Mozilla Firefox OS
Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB interface for a mount operation.
1.9
2015-08-08 CVE-2015-5961 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox OS
The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.
low complexity
mozilla CWE-264
3.3
2015-05-21 CVE-2015-4000 Cryptographic Issues vulnerability in multiple products
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
3.7
2015-05-14 CVE-2015-2714 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.
local
low complexity
mozilla google CWE-264
2.1
2015-02-25 CVE-2015-0820 Improper Access Control vulnerability in multiple products
Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.
network
high complexity
opensuse mozilla canonical CWE-284
2.6
2014-03-25 CVE-2014-1515 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
1.9
2014-03-19 CVE-2014-1496 Improper Privilege Management vulnerability in multiple products
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
1.9
2014-03-19 CVE-2014-1504 Permissions, Privileges, and Access Controls vulnerability in multiple products
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.
network
high complexity
mozilla opensuse oracle suse CWE-264
2.6
2013-09-18 CVE-2013-1729 Information Exposure vulnerability in Mozilla Firefox
The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element.
network
high complexity
mozilla apple CWE-200
2.6