Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla firefox focus vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2023-6870
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
Mozilla Firefox
Mozilla Firefox Focus -
4.3
CVSSv3
CVE-2023-29533
A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> assignments, and <code>setInterval</code> calls. This could have led to user confusion a...
Mozilla Thunderbird
Mozilla Focus
Mozilla Firefox Esr
Mozilla Firefox
4.3
CVSSv3
CVE-2023-29538
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox ...
Mozilla Focus
Mozilla Firefox
3.3
CVSSv3
CVE-2020-12394
A logic flaw in our location bar implementation could have allowed a local malicious user to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.
Mozilla Firefox
NA
CVE-2024-2609
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
NA
CVE-2024-1563
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.
NA
CVE-2010-1125
The JavaScript implementation in Mozilla Firefox 3.x prior to 3.5.10 and 3.6.x prior to 3.6.4, and SeaMonkey prior to 2.0.5, allows remote malicious users to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via cer...
Mozilla Firefox 3.0.1
Mozilla Firefox 3.0.10
Mozilla Firefox 3.0.3
Mozilla Firefox 3.0.4
Mozilla Firefox 3.5.2
Mozilla Firefox 3.5.3
Mozilla Firefox 3.5.4
Mozilla Firefox 3.0.11
Mozilla Firefox 3.0.12
Mozilla Firefox 3.0.5
Mozilla Firefox 3.0.7
Mozilla Firefox 3.5.5
Mozilla Firefox 3.6
Mozilla Firefox 3.0
Mozilla Firefox 3.0.15
Mozilla Firefox 3.0.2
Mozilla Firefox 3.5
Mozilla Firefox 3.5.1
Mozilla Firefox 3.5.7
Mozilla Firefox 3.5.9
Mozilla Firefox 3.0.13
Mozilla Firefox 3.0.14
NA
CVE-2008-0416
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox prior to 2.0.0.12, Thunderbird prior to 2.0.0.12, and SeaMonkey prior to 1.1.8 allow remote malicious users to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace cha...
Mozilla Thunderbird
Mozilla Seamonkey
Mozilla Firefox
NA
CVE-2008-0593
Gecko-based browsers, including Mozilla Firefox prior to 2.0.0.12 and SeaMonkey prior to 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote malicious users to bypass the Same Origin Policy and read sensitive infor...
Mozilla Firefox 1.5.0.2
Mozilla Firefox 1.5.2
Mozilla Firefox 2.0
Mozilla Firefox 0.2
Mozilla Firefox 0.9.2
Mozilla Firefox
Mozilla Firefox 2.0.0.1
Mozilla Firefox 2.0.0.10
Mozilla Firefox 1.0.2
Mozilla Firefox 1.5.0.12
Mozilla Seamonkey 1.1.14
Mozilla Seamonkey
Mozilla Seamonkey 1.0
Mozilla Seamonkey 1.1.13
Mozilla Seamonkey 1.0.1
Mozilla Seamonkey 1.1.12
Mozilla Seamonkey 1.0.8
Mozilla Seamonkey 1.0.7
Mozilla Seamonkey 1.0.4
Mozilla Seamonkey 1.0.3
Mozilla Seamonkey 1.1.15
Mozilla Seamonkey 1.1.11
NA
CVE-2008-0594
Mozilla Firefox prior to 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote malicious users to conduct phishing attacks.
Mozilla Firefox
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »