Skip to main content

Vendor/product archive

mozilla / firefox_mobile CVEs

Beta · best-effort

25 CVEs tagged to mozilla / firefox_mobile18 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-16404

Published Jul 21, 2026

Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

CVSS 7.4 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-16373

Published Jul 21, 2026

Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-14906

Published Jul 13, 2026

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-53900

Published Jun 16, 2026

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies int…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-53899

Published Jun 16, 2026

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site.…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2012-1144

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and m…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1143

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafte…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1142

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and m…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1141

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1140

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1139

Published Apr 25, 2012

Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1138

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1137

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1136

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and m…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1135

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1134

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and m…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1133

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and m…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1132

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1131

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap r…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1130

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1129

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1128

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memor…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1127

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1126

Published Apr 25, 2012

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and me…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1