Mozilla Firefox For Android vulnerabilities
33 known vulnerabilities affecting mozilla/firefox_for_android.
Total CVEs
33
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL2HIGH13MEDIUM17LOW1
Vulnerabilities
Page 2 of 2
CVE-2023-29549P4MEDIUMCVSS 6.5≥ unspecified, < 1122023-06-02
CVE-2023-29549 [MEDIUM] CWE-326 CVE-2023-29549: Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incor
Under certain circumstances, a call to the bind function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvd
CVE-2023-29535P4MEDIUMCVSS 6.5≥ unspecified, < 1122023-06-02
CVE-2023-29535 [MEDIUM] CVE-2023-29535: Following a Garbage Collector compaction, weak maps may have been accessed before they were correctl
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvd
CVE-2023-29547P4MEDIUMCVSS 6.5≥ unspecified, < 1122023-06-02
CVE-2023-29547 [MEDIUM] CVE-2023-29547: When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could
When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvd
CVE-2023-29544P4MEDIUMCVSS 6.5≥ unspecified, < 1122023-06-02
CVE-2023-29544 [MEDIUM] CWE-400 CVE-2023-29544: If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector c
If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvd
CVE-2021-29953P4MEDIUMCVSS 6.1≥ unspecified, < 88.1.32021-06-24
CVE-2021-29953 [MEDIUM] CWE-79 CVE-2021-29953: A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled
A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected. Further details are being temporarily withheld to allo
nvd
CVE-2023-29540P4MEDIUMCVSS 6.1≥ unspecified, < 1122023-06-02
CVE-2023-29540 [MEDIUM] CWE-601 CVE-2023-29540: Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external
Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvd
CVE-2020-6829P4MEDIUMCVSS 5.3≥ unspecified, < 802020-10-28
CVE-2020-6829 [MEDIUM] CVE-2020-6829: When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; wh
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvd
CVE-2020-12401P4MEDIUMCVSS 4.7≥ unspecified, < 802020-10-08
CVE-2020-12401 [MEDIUM] CWE-203 CVE-2020-12401: During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time sca
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvd
CVE-2020-12400P4MEDIUMCVSS 4.7≥ unspecified, < 802020-10-08
CVE-2020-12400 [MEDIUM] CWE-203 CVE-2020-12400: When converting coordinates from projective to affine, the modular inversion was not performed in co
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvd
CVE-2023-29533P4MEDIUMCVSS 4.3≥ unspecified, < 1122023-06-02
CVE-2023-29533 [MEDIUM] CVE-2023-29533: A website could have obscured the fullscreen notification by using a combination of <code>window.ope
A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thun
nvd
CVE-2023-29538P4MEDIUMCVSS 4.3≥ unspecified, < 1122023-06-02
CVE-2023-29538 [MEDIUM] CWE-668 CVE-2023-29538: Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instea
Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvd
CVE-2020-15668P4MEDIUMCVSS 4.3≥ unspecified, < 802020-10-01
CVE-2020-15668 [MEDIUM] CWE-667 CVE-2020-15668: A lock was missing when accessing a data structure and importing certificate information into the tr
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvd
CVE-2020-15671P4LOWCVSS 3.1≥ unspecified, < 802020-10-01
CVE-2020-15671 [LOW] CWE-200 CVE-2020-15671: When typing in a password under certain conditions, a race may have occured where the InputContext w
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.
nvd
← Previous2 / 2