Where
AND
-Infinity
0
Severity
7.5
EPSS
0.13%
Race Condition
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage.

1 / 2
Source: Mozilla
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.

This bug only affects Firefox Focus. Other versions of Firefox are unaffected.

External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25743

1 / 4
Source: Red Hat
First published (updated )
Severity
7

Security Vulnerabilities fixed in Focus for iOS 123

First published (updated )
Advisory
MFSA2024-10
Severity
7

Security Vulnerabilities fixed in Focus for iOS 122

First published (updated )
Advisory
MFSA2024-09
Severity
8.1
Race Condition, XSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition.

1 / 2
Source: Mozilla
First published (updated )
Severity
7

Security Vulnerabilities fixed in Focus for iOS 126

First published (updated )
Advisory
MFSA2024-24
Severity
7

Security Vulnerabilities fixed in Focus for iOS 130

First published (updated )
Advisory
MFSA2024-42
Severity
7

Security Vulnerabilities fixed in Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, and Focus 97.3.0

First published (updated )
Advisory
MFSA2022-09
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as: Removing an XSLT parameter during processing could have led to an exploitable use-after-free issue. There were reports of attacks in the wild abusing this flaw.

1 / 5
First published (updated )
Severity
7

Security Vulnerabilities fixed in Focus for iOS 148.2

First published (updated )
Advisory
MFSA2026-18
Severity
7

Security Vulnerabilities fixed in Focus for iOS / Klar 151.3.1

First published (updated )
Advisory
MFSA2026-55
Severity
7.5
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1.

First published (updated )
Severity
7

Security Vulnerabilities fixed in Firefox 112, Firefox for Android 112, Focus for Android 112

First published (updated )
Advisory
MFSA2023-13
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash.

1 / 3
First published (updated )
Severity
8.8
Null Pointer Dereference
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 3
Source: Ubuntu
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.

1 / 4
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector.

1 / 3
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 6
Source: Ubuntu
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 4
Source: Ubuntu
First published (updated )
Severity
7.5
Double Free, Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A double-free in libwebp could have led to memory corruption and a potentially exploitable crash.

1 / 6
Source: Mozilla
First published (updated )
Severity
7.5
Race Condition
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 24 July 2024

1 / 3
Source: Ubuntu
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203