Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2025-23109

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134.
0
Attacker Value
Unknown

CVE-2025-23108

Disclosure Date: January 11, 2025 (last updated January 12, 2025)
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
0
Attacker Value
Unknown

CVE-2024-53976

Disclosure Date: November 26, 2024 (last updated December 21, 2024)
Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
0
Attacker Value
Unknown

CVE-2024-53975

Disclosure Date: November 26, 2024 (last updated December 21, 2024)
Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.
0
Attacker Value
Unknown

CVE-2024-10004

Disclosure Date: October 15, 2024 (last updated October 16, 2024)
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
0
Attacker Value
Unknown

CVE-2024-31393

Disclosure Date: April 03, 2024 (last updated April 04, 2024)
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
0
Attacker Value
Unknown

CVE-2024-31392

Disclosure Date: April 03, 2024 (last updated April 04, 2024)
If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.
0
Attacker Value
Unknown

CVE-2024-26283

Disclosure Date: February 22, 2024 (last updated February 23, 2024)
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This vulnerability affects Firefox for iOS < 123.
0
Attacker Value
Unknown

CVE-2024-26282

Disclosure Date: February 22, 2024 (last updated February 23, 2024)
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.
0
Attacker Value
Unknown

CVE-2024-26281

Disclosure Date: February 22, 2024 (last updated February 23, 2024)
Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.
0