Vulnerabilities
Vulnerable Software
Mozilla:  >> Firefox  >> 58.0.2  Security Vulnerabilities
When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-10-14
The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.
CVSS Score
8.1
EPSS Score
0.003
Published
2025-10-14
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-10-14
Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3.
CVSS Score
8.6
EPSS Score
0.003
Published
2025-09-30
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.
CVSS Score
7.5
EPSS Score
0.002
Published
2025-09-30
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
CVSS Score
8.1
EPSS Score
0.003
Published
2025-09-16
Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.
CVSS Score
7.5
EPSS Score
0.003
Published
2025-09-16
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
CVSS Score
6.5
EPSS Score
0.003
Published
2025-09-16
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
CVSS Score
5.4
EPSS Score
0.003
Published
2025-09-16
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
CVSS Score
8.1
EPSS Score
0.004
Published
2025-06-24


Contact Us

Shodan ® - All rights reserved