Vulnerabilities > Mozilla > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-01 CVE-2024-9398 Unspecified vulnerability in Mozilla Firefox
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed.
network
low complexity
mozilla
5.3
2024-09-17 CVE-2024-8897 Open Redirect vulnerability in Mozilla Firefox
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents.
network
low complexity
mozilla CWE-601
6.1
2024-09-06 CVE-2024-8394 Use After Free vulnerability in Mozilla Thunderbird
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash.
network
low complexity
mozilla CWE-416
6.5
2024-09-03 CVE-2024-8399 Unspecified vulnerability in Mozilla Firefox Focus 122.0
Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.
network
low complexity
mozilla
4.7
2024-09-03 CVE-2024-8386 Open Redirect vulnerability in Mozilla Firefox
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack.
network
low complexity
mozilla CWE-601
6.1
2024-09-03 CVE-2024-8388 Unspecified vulnerability in Mozilla Firefox
Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121.
network
low complexity
mozilla
5.3
2024-08-06 CVE-2024-43111 Cross-site Scripting vulnerability in Mozilla Firefox
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
network
low complexity
mozilla CWE-79
6.1
2024-08-06 CVE-2024-43112 Cross-site Scripting vulnerability in Mozilla Firefox
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
network
low complexity
mozilla CWE-79
6.1
2024-08-06 CVE-2024-43113 Cross-site Scripting vulnerability in Mozilla Firefox
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
network
low complexity
mozilla CWE-79
6.1
2024-08-06 CVE-2024-7518 Unspecified vulnerability in Mozilla Firefox
Select options could obscure the fullscreen notification dialog.
network
low complexity
mozilla
6.5