← Back

Firefox Mobile

firefox_mobile

Vendor: Mozilla • 82 CVEs

CVEs (82)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
2Firefox
Firefox Mobile
Aug 19, 2026
Jul 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefo...Show more
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.Show less
1Mozilla
2Firefox
Firefox Mobile
Aug 19, 2026
May 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and...Show more
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.Show less
2Google
Mozilla
3Android
FirefoxFirefox Mobile
Apr 29, 2026
Aug 29, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the Ja...Show more
Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font.
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted PostScript font object.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or...Show more
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted header in a BDF font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the NPUSHB and NPUSHW instructions in a TrueType font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted private-dictionary data in a Type 1 font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or p...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors related to the cell table of a font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.Show less
2Freetype
Mozilla
2Firefox Mobile
Freetype
Apr 29, 2026
Apr 25, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitra...Show more
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.Show less