Mozilla / Firefox for Ios
28 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-53976 | Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the… | MEDIUM | 5.4 | Nov 26, 2024 |
| CVE-2024-53975 | Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vul… | MEDIUM | 5.4 | Nov 26, 2024 |
| CVE-2024-10004 | Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon sho… | CRITICAL | 9.1 | Oct 15, 2024 |
| CVE-2024-43111 | Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129. | CRITICAL | 9.8 | Aug 6, 2024 |
| CVE-2024-43113 | The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129. | MEDIUM | 6.1 | Aug 6, 2024 |
| CVE-2024-43112 | Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129. | MEDIUM | 6.1 | Aug 6, 2024 |
| CVE-2024-38312 | When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after ap… | MEDIUM | 6.5 | Jun 13, 2024 |
| CVE-2024-38313 | In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulne… | MEDIUM | 4.3 | Jun 13, 2024 |
| CVE-2024-31392 | If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability aff… | HIGH | 7.5 | Apr 3, 2024 |
| CVE-2024-31393 | Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox f… | MEDIUM | 4.3 | Apr 3, 2024 |
| CVE-2024-26281 | Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. T… | MEDIUM | 4.7 | Feb 22, 2024 |
| CVE-2024-26282 | Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iO… | HIGH | 7.1 | Feb 22, 2024 |
| CVE-2024-26283 | An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This… | HIGH | 7.8 | Feb 22, 2024 |
| CVE-2024-0953 | When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surpr… | MEDIUM | 6.1 | Feb 5, 2024 |
| CVE-2023-49061 | An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120. | MEDIUM | 6.1 | Nov 21, 2023 |
| CVE-2023-49060 | An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability a… | CRITICAL | 9.8 | Nov 21, 2023 |
| CVE-2023-5758 | When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack.… | MEDIUM | 6.1 | Oct 24, 2023 |
| CVE-2023-37456 | The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115. | MEDIUM | 6.5 | Jul 12, 2023 |
| CVE-2023-37455 | The permission request prompt from the site in the background tab was overlaid on top of the site in the foreground tab. This vulnerability affects Firefox for… | MEDIUM | 5.4 | Jul 12, 2023 |
| CVE-2022-31746 | Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for… | MEDIUM | 6.5 | Dec 22, 2022 |
| CVE-2022-1887 | The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101. | CRITICAL | 9.8 | Dec 22, 2022 |
| CVE-2021-29958 | When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in no… | MEDIUM | 4.3 | Jun 24, 2021 |
| CVE-2020-15651 | A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This… | MEDIUM | 4.3 | Aug 10, 2020 |
| CVE-2020-15662 | A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. Th… | MEDIUM | 6.5 | Aug 10, 2020 |
| CVE-2020-15661 | A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. T… | MEDIUM | 6.5 | Aug 10, 2020 |
Showing 1 to 25 of 28 CVEs