Mozilla Firefox For Ios vulnerabilities
36 known vulnerabilities affecting mozilla/firefox_for_ios.
Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM27UNKNOWN2
Vulnerabilities
Page 2 of 2
CVE-2024-43111P4MEDIUMCVSS 6.1≥ unspecified, < 1292024-08-06
CVE-2024-43111 [MEDIUM] CWE-79 CVE-2024-43111: Long pressing on a download link could potentially allow Javascript commands to be executed within t
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2024-53976P4MEDIUMCVSS 5.4≥ unspecified, < 1332024-11-26
CVE-2024-53976 [MEDIUM] CWE-1021 CVE-2024-53976: Under certain circumstances, navigating to a webpage would result in the address missing from the lo
Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
nvd
CVE-2026-14906P4MEDIUMCVSS 5.3fixed in Firefox for iOS 152.4
CVE-2026-14906 [MEDIUM] Mozilla Foundation Security Advisory 2026-66: CVE-2026-14906
Mozilla Foundation Security Advisory 2026-66
CVE: CVE-2026-14906
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 152.4
mozilla
CVE-2026-9078P4UNKNOWNfixed in Firefox for iOS 151.1
CVE-2026-9078 Mozilla Foundation Security Advisory 2026-52: CVE-2026-9078
Mozilla Foundation Security Advisory 2026-52
CVE: CVE-2026-9078
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 151.1
mozilla
CVE-2023-37455P4MEDIUMCVSS 5.4≥ unspecified, < 1152023-07-12
CVE-2023-37455 [MEDIUM] CWE-1021 CVE-2023-37455: The permission request prompt from the site in the background tab was overlaid on top of the site in
The permission request prompt from the site in the background tab was overlaid on top of the site in the foreground tab. This vulnerability affects Firefox for iOS < 115.
nvd
CVE-2024-43113P4MEDIUMCVSS 6.1≥ unspecified, < 1292024-08-06
CVE-2024-43113 [MEDIUM] CWE-79 CVE-2024-43113: The contextual menu for links could provide an opportunity for cross-site scripting attacks This vul
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2024-53975P4MEDIUMCVSS 5.4≥ unspecified, < 1332024-11-26
CVE-2024-53975 [MEDIUM] CVE-2024-53975: Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the
Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.
nvd
CVE-2023-5758P4MEDIUMCVSS 6.1≥ unspecified, < 1192023-10-25
CVE-2023-5758 [MEDIUM] CWE-79 CVE-2023-5758: When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to
When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.
nvd
CVE-2024-43112P4MEDIUMCVSS 6.1≥ unspecified, < 1292024-08-06
CVE-2024-43112 [MEDIUM] CWE-79 CVE-2024-43112: Long pressing on a download link could potentially provide a means for cross-site scripting This vul
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2026-53900P4MEDIUMCVSS 4.3fixed in Firefox for iOS 152
CVE-2026-53900 [MEDIUM] Mozilla Foundation Security Advisory 2026-56: CVE-2026-53900
Mozilla Foundation Security Advisory 2026-56
CVE: CVE-2026-53900
Product: Firefox for iOS
Impact: high
Fixed in: Firefox for iOS 152
mozilla
CVE-2024-26281P4MEDIUMCVSS 4.7≥ unspecified, < 1232024-02-22
CVE-2024-26281 [MEDIUM] CWE-79 CVE-2024-26281: Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorize
Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.
nvd
CVE-2024-31393P4MEDIUMCVSS 4.3≥ unspecified, < 1242024-04-03
CVE-2024-31393 [MEDIUM] CVE-2024-31393: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions an
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
nvd
CVE-2020-15651P4MEDIUMCVSS 4.3≥ unspecified, < 282020-08-10
CVE-2020-15651 [MEDIUM] CVE-2020-15651: A unicode RTL order character in the downloaded file name can be used to change the file's name duri
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.
nvd
CVE-2020-12404P4MEDIUMCVSS 4.3≥ unspecified, < 262020-07-09
CVE-2020-12404 [MEDIUM] CWE-79 CVE-2020-12404: For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.
nvd
CVE-2021-29958P4MEDIUMCVSS 4.3≥ unspecified, < 342021-06-24
CVE-2021-29958 [MEDIUM] CWE-862 CVE-2021-29958: When a download was initiated, the client did not check whether it was in normal or private browsing
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iOS < 34.
nvd
CVE-2024-38313P4MEDIUMCVSS 4.3≥ unspecified, < 1272024-06-13
CVE-2024-38313 [MEDIUM] CWE-451 CVE-2024-38313: In certain scenarios a malicious website could attempt to display a fake location URL bar which coul
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.
nvd
← Previous2 / 2