Mozilla Firefox For Ios vulnerabilities
36 known vulnerabilities affecting mozilla/firefox_for_ios.
Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM27UNKNOWN2
Vulnerabilities
Page 1 of 2
CVE-2022-1887P3CRITICALCVSS 9.8≥ unspecified, < 1012022-12-22
CVE-2022-1887 [CRITICAL] CWE-89 CVE-2022-1887: The search term could have been specified externally to trigger SQL injection. This vulnerability af
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
nvd
CVE-2023-49060P3CRITICALCVSS 9.8≥ unspecified, < 1202023-11-21
CVE-2023-49060 [CRITICAL] CVE-2023-49060: An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMo
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
nvd
CVE-2024-10004P3CRITICALCVSS 9.1≥ unspecified, < 131.22024-10-15
CVE-2024-10004 [CRITICAL] CWE-1021 CVE-2024-10004: Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
nvd
CVE-2024-31392P3HIGHCVSS 7.5≥ unspecified, < 1242024-04-03
CVE-2024-31392 [HIGH] CVE-2024-31392: If an insecure element was added to a page after a delay, Firefox would not replace the secure icon
If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.
nvd
CVE-2024-26283P3HIGHCVSS 7.8≥ unspecified, < 1232024-02-22
CVE-2024-26283 [HIGH] CWE-83 CVE-2024-26283: An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This vulnerability affects Firefox for iOS < 123.
nvd
CVE-2020-6830P4HIGHCVSS 7.5≥ unspecified, < 252020-05-26
CVE-2020-6830 [HIGH] CWE-200 CVE-2020-6830: For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code ca
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.
nvd
CVE-2026-8706P4MEDIUMCVSS 6.5fixed in Firefox for iOS 151
CVE-2026-8706 [MEDIUM] Mozilla Foundation Security Advisory 2026-49: CVE-2026-8706
Mozilla Foundation Security Advisory 2026-49
CVE: CVE-2026-8706
Product: Firefox for iOS
Impact: high
Fixed in: Firefox for iOS 151
mozilla
CVE-2026-53899P4MEDIUMCVSS 6.5fixed in Firefox for iOS 152
CVE-2026-53899 [MEDIUM] Mozilla Foundation Security Advisory 2026-56: CVE-2026-53899
Mozilla Foundation Security Advisory 2026-56
CVE: CVE-2026-53899
Product: Firefox for iOS
Impact: high
Fixed in: Firefox for iOS 152
mozilla
CVE-2024-26282P4HIGHCVSS 7.1≥ unspecified, < 1232024-02-22
CVE-2024-26282 [HIGH] CWE-80 CVE-2024-26282: Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.
nvd
CVE-2024-38312P4MEDIUMCVSS 6.5≥ unspecified, < 1272024-06-13
CVE-2024-38312 [MEDIUM] CWE-922 CVE-2024-38312: When browsing private tabs, some data related to location history or webpage thumbnails could be per
When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.
nvd
CVE-2026-13356P4UNKNOWNfixed in Firefox for iOS 152.3
CVE-2026-13356 Mozilla Foundation Security Advisory 2026-65: CVE-2026-13356
Mozilla Foundation Security Advisory 2026-65
CVE: CVE-2026-13356
Product: Firefox for iOS
Impact: moderate
Fixed in: Firefox for iOS 152.3
mozilla
CVE-2020-15661P4MEDIUMCVSS 6.5≥ unspecified, < 282020-08-10
CVE-2020-15661 [MEDIUM] CWE-522 CVE-2020-15661: A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit c
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.
nvd
CVE-2020-15662P4MEDIUMCVSS 6.5≥ unspecified, < 282020-08-10
CVE-2020-15662 [MEDIUM] CVE-2020-15662: A rogue webpage could override the injected WKUserScript used by the download feature, this exploit
A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS < 28.
nvd
CVE-2024-0953P4MEDIUMCVSS 6.1≥ unspecified, < 1292024-02-05
CVE-2024-0953 [MEDIUM] CWE-601 CVE-2024-0953: When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2026-9308P4MEDIUMCVSS 5.4fixed in Firefox for iOS 151.2
CVE-2026-9308 [MEDIUM] Mozilla Foundation Security Advisory 2026-53: CVE-2026-9308
Mozilla Foundation Security Advisory 2026-53
CVE: CVE-2026-9308
Product: Firefox for iOS
Impact: high
Fixed in: Firefox for iOS 151.2
mozilla
CVE-2026-9309P4MEDIUMCVSS 5.4fixed in Firefox for iOS 151.2
CVE-2026-9309 [MEDIUM] Mozilla Foundation Security Advisory 2026-53: CVE-2026-9309
Mozilla Foundation Security Advisory 2026-53
CVE: CVE-2026-9309
Product: Firefox for iOS
Impact: high
Fixed in: Firefox for iOS 151.2
mozilla
CVE-2020-12414P4MEDIUMCVSS 6.5≥ unspecified, < 272020-07-09
CVE-2020-12414 [MEDIUM] CWE-459 CVE-2020-12414: IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewC
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.
nvd
CVE-2023-37456P4MEDIUMCVSS 6.5≥ unspecified, < 1152023-07-12
CVE-2023-37456 [MEDIUM] CWE-476 CVE-2023-37456: The session restore helper crashed whenever there was no parameter sent to the message handler. This
The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.
nvd
CVE-2022-31746P4MEDIUMCVSS 6.5≥ unspecified, < 1022022-12-22
CVE-2022-31746 [MEDIUM] CWE-200 CVE-2022-31746: Internal URLs are protected by a secret UUID key, which could have been leaked to web page through t
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
nvd
CVE-2023-49061P4MEDIUMCVSS 6.1≥ unspecified, < 1202023-11-21
CVE-2023-49061 [MEDIUM] CWE-601 CVE-2023-49061: An attacker could have performed HTML template injection via Reader Mode and exfiltrated user inform
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
nvd
1 / 2Next →