CVE-2024-1563
- EPSS 0.32%
- Veröffentlicht 22.02.2024 15:15:08
- Zuletzt bearbeitet 27.03.2025 15:15:48
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.
CVE-2024-0606
- EPSS 0.58%
- Veröffentlicht 22.01.2024 19:15:09
- Zuletzt bearbeitet 20.06.2025 19:15:28
An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.
CVE-2024-0605
- EPSS 0.05%
- Veröffentlicht 22.01.2024 19:15:09
- Zuletzt bearbeitet 20.06.2025 19:15:28
Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the ...
CVE-2023-6870
- EPSS 0.5%
- Veröffentlicht 19.12.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 08:44:43
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
CVE-2023-29546
- EPSS 0.29%
- Veröffentlicht 19.06.2023 11:15:09
- Zuletzt bearbeitet 11.12.2024 17:15:11
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.*...
CVE-2023-29534
- EPSS 0.44%
- Veröffentlicht 19.06.2023 11:15:09
- Zuletzt bearbeitet 11.12.2024 16:15:09
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Fir...
CVE-2023-25743
- EPSS 0.08%
- Veröffentlicht 02.06.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 07:50:03
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 a...
CVE-2022-26485
- EPSS 4.45%
- Veröffentlicht 22.12.2022 20:15:22
- Zuletzt bearbeitet 06.03.2025 19:48:51
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3...
CVE-2022-26486
- EPSS 2.96%
- Veröffentlicht 22.12.2022 20:15:22
- Zuletzt bearbeitet 21.03.2025 21:09:05
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox ...