CVE-2025-55033
- EPSS 0.03%
- Published 19.08.2025 20:52:51
- Last modified 21.08.2025 18:38:38
Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks This vulnerability affects Focus for iOS < 142.
CVE-2025-3859
- EPSS 0.03%
- Published 30.04.2025 16:30:18
- Last modified 12.05.2025 19:43:47
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138.
CVE-2023-29551
- EPSS 0.16%
- Published 02.06.2023 17:15:13
- Last modified 08.01.2025 22:15:27
Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < ...
CVE-2023-29543
- EPSS 0.16%
- Published 02.06.2023 17:15:12
- Last modified 10.01.2025 19:15:36
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
CVE-2023-29550
- EPSS 0.14%
- Published 02.06.2023 17:15:12
- Last modified 10.01.2025 20:15:29
Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects ...
CVE-2023-29549
- EPSS 0.08%
- Published 02.06.2023 17:15:12
- Last modified 10.01.2025 20:15:29
Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for And...
CVE-2023-29548
- EPSS 0.1%
- Published 02.06.2023 17:15:12
- Last modified 10.01.2025 20:15:29
A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
CVE-2023-29547
- EPSS 0.15%
- Published 02.06.2023 17:15:12
- Last modified 10.01.2025 20:15:29
When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure co...
CVE-2023-29544
- EPSS 0.15%
- Published 02.06.2023 17:15:12
- Last modified 10.01.2025 20:15:28
If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus...
CVE-2023-29533
- EPSS 0.1%
- Published 02.06.2023 17:15:12
- Last modified 21.11.2024 07:57:14
A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> assignments, and <code>setInterval</code> calls. This could have led to user confusion and pos...