Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2025-23109
Disclosure Date: January 11, 2025 (last updated January 12, 2025)
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134.
0
Attacker Value
Unknown
CVE-2025-23108
Disclosure Date: January 11, 2025 (last updated January 12, 2025)
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
0
Attacker Value
Unknown
CVE-2024-53976
Disclosure Date: November 26, 2024 (last updated December 21, 2024)
Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
0
Attacker Value
Unknown
CVE-2024-53975
Disclosure Date: November 26, 2024 (last updated December 21, 2024)
Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.
0
Attacker Value
Unknown
CVE-2024-10004
Disclosure Date: October 15, 2024 (last updated October 16, 2024)
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
0
Attacker Value
Unknown
CVE-2024-31393
Disclosure Date: April 03, 2024 (last updated April 04, 2024)
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
0
Attacker Value
Unknown
CVE-2024-31392
Disclosure Date: April 03, 2024 (last updated April 04, 2024)
If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.
0
Attacker Value
Unknown
CVE-2024-26283
Disclosure Date: February 22, 2024 (last updated February 23, 2024)
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This vulnerability affects Firefox for iOS < 123.
0
Attacker Value
Unknown
CVE-2024-26282
Disclosure Date: February 22, 2024 (last updated February 23, 2024)
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.
0
Attacker Value
Unknown
CVE-2024-26281
Disclosure Date: February 22, 2024 (last updated February 23, 2024)
Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.
0