Firefox vulnerabilities
CVEs whose affected-version data names the Firefox package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
153 CVEsRSS
CVE-2020-15670High· 8.8Mozilla developers reported memory safety bugs present in Firefox for Android 79
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary cod…
CVE-2020-15668Medium· 4.3A lock was missing when accessing a data structure and importing certificate information into the trust database
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
CVE-2020-15666Medium· 6.5When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerro…