Mozilla / Firefox Mobile
84 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84135 | Other issue in Firefox Focus for Android | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84127 | Information disclosure in the WebExtensions component in Firefox for Android | MEDIUM | 6.5 | Sep 1, 2026 |
| CVE-2026-84117 | Privilege escalation in Firefox for Android | HIGH | 8.8 | Sep 1, 2026 |
| CVE-2026-81267 | Stalled popup navigation could allow address bar origin spoofing in Firefox for iOS | MEDIUM | 5.4 | Aug 31, 2026 |
| CVE-2026-74980 | Clickjacking issue in the Downloads component in Firefox for Android | MEDIUM | 6.5 | Aug 18, 2026 |
| CVE-2026-74975 | Spoofing issue in the Downloads component in Firefox for Android | MEDIUM | 5.4 | Aug 18, 2026 |
| CVE-2026-74951 | Clickjacking issue in Firefox for Android | MEDIUM | 6.5 | Aug 18, 2026 |
| CVE-2026-16404 | Spoofing issue in Firefox for Android | HIGH | 7.4 | Jul 21, 2026 |
| CVE-2026-16373 | Information disclosure in the Privacy component in Firefox for Android | HIGH | 7.5 | Jul 21, 2026 |
| CVE-2026-14906 | Malicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOS | MEDIUM | 5.3 | Jul 13, 2026 |
| CVE-2026-53900 | Cookie injection was possible when opening a PDF link | MEDIUM | 4.3 | Jun 16, 2026 |
| CVE-2026-53899 | Cross-origin cookies could be leaked when opening a PDF link | MEDIUM | 6.5 | Jun 16, 2026 |
| CVE-2024-43111 | Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129. | CRITICAL | 9.8 | Aug 6, 2024 |
| CVE-2024-43113 | The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129. | MEDIUM | 6.1 | Aug 6, 2024 |
| CVE-2024-43112 | Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129. | MEDIUM | 6.1 | Aug 6, 2024 |
| CVE-2024-7523 | A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only af… | HIGH | 8.1 | Aug 6, 2024 |
| CVE-2024-38312 | When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after ap… | MEDIUM | 6.5 | Jun 13, 2024 |
| CVE-2024-38313 | In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulne… | MEDIUM | 4.3 | Jun 13, 2024 |
| CVE-2024-0953 | When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surpr… | MEDIUM | 6.1 | Feb 5, 2024 |
| CVE-2023-49061 | An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120. | MEDIUM | 6.1 | Nov 21, 2023 |
| CVE-2023-49060 | An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability a… | CRITICAL | 9.8 | Nov 21, 2023 |
| CVE-2023-5758 | When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack.… | MEDIUM | 6.1 | Oct 24, 2023 |
| CVE-2023-29546 | When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive informat… | MEDIUM | 6.5 | Jun 19, 2023 |
| CVE-2023-29534 | Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoo… | CRITICAL | 9.1 | Jun 19, 2023 |
| CVE-2023-25747 | A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox f… | HIGH | 7.5 | Jun 19, 2023 |
Showing 1 to 25 of 84 CVEs