Mozilla

Firefox Mobile

85 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.67%
  • Veröffentlicht 10.08.2020 18:15:12
  • Zuletzt bearbeitet 19.08.2026 15:30:33

A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS < 28.

  • EPSS 0.85%
  • Veröffentlicht 10.08.2020 18:15:12
  • Zuletzt bearbeitet 19.08.2026 15:30:33

A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.

  • EPSS 0.67%
  • Veröffentlicht 09.07.2020 15:15:11
  • Zuletzt bearbeitet 19.08.2026 15:30:33

IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affe...

  • EPSS 0.78%
  • Veröffentlicht 09.07.2020 15:15:10
  • Zuletzt bearbeitet 19.08.2026 15:30:33

For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.

  • EPSS 0.9%
  • Veröffentlicht 26.05.2020 18:15:11
  • Zuletzt bearbeitet 19.08.2026 15:30:33

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking thi...

  • EPSS 1.88%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 16.06.2026 23:44:11

Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function.

  • EPSS 3.81%
  • Veröffentlicht 25.04.2012 10:10:18
  • Zuletzt bearbeitet 16.06.2026 23:39:06

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted heade...

  • EPSS 4.68%
  • Veröffentlicht 25.04.2012 10:10:18
  • Zuletzt bearbeitet 16.06.2026 23:39:04

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType...

  • EPSS 3.81%
  • Veröffentlicht 25.04.2012 10:10:18
  • Zuletzt bearbeitet 16.06.2026 23:39:05

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT ...

  • EPSS 3.81%
  • Veröffentlicht 25.04.2012 10:10:18
  • Zuletzt bearbeitet 16.06.2026 23:39:05

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted propert...