CVEs (23)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4. |
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain....Show more |
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox f...Show more |
2Google Mozilla3Android FirefoxFirefox MobileApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the Ja...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font. |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or p...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |