$ cat cves.txt
Root cause, proof of concept, and the patch that followed.
Every vulnerability below was reported privately, reproduced, root-caused, and fixed by the vendor before it was published here. Nothing on this page is a claim you have to take on trust.
Use-after-free in RasterImage surface discard
Firefox stores decoded image surfaces in a SurfaceCache keyed by a raw, non-owning pointer to the owning image, and notifies that…
Uninitialized heap disclosure through a crafted web font
Firefox sanitizes web fonts through OTS before use.
Stored XSS in CometChat group messages
An authenticated user can inject a persistent JavaScript payload into a group chat message through the data.text parameter of the…
Fission site-isolation bypass via missing PipelineId namespace check
Under Fission each content process owns a PipelineId namespace.
Test-only FormAutofill handlers exposed in production
Firefox isolates web content in sandboxed child processes while sensitive data such as saved addresses and credit cards lives in…
5
CVEs published
9.8
Highest CVSS
2
Vendors credited
100%
Fixed before publication