Total
23 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-14906 | 1 Mozilla | 1 Firefox Mobile | 2026-07-14 | N/A | 5.3 MEDIUM |
| Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4. | |||||
| CVE-2026-53899 | 1 Mozilla | 1 Firefox Mobile | 2026-06-17 | N/A | 6.5 MEDIUM |
| Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0. | |||||
| CVE-2026-53900 | 1 Mozilla | 1 Firefox Mobile | 2026-06-17 | N/A | 4.3 MEDIUM |
| Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0. | |||||
| CVE-2012-3979 | 2 Google, Mozilla | 3 Android, Firefox, Firefox Mobile | 2026-06-16 | 6.8 MEDIUM | N/A |
| Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function. | |||||
| CVE-2012-1144 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font. | |||||
| CVE-2012-1143 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 4.3 MEDIUM | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font. | |||||
| CVE-2012-1142 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a font. | |||||
| CVE-2012-1141 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF font. | |||||
| CVE-2012-1140 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted PostScript font object. | |||||
| CVE-2012-1139 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font. | |||||
| CVE-2012-1138 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font. | |||||
| CVE-2012-1137 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted header in a BDF font. | |||||
| CVE-2012-1136 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field. | |||||
| CVE-2012-1135 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the NPUSHB and NPUSHW instructions in a TrueType font. | |||||
| CVE-2012-1134 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted private-dictionary data in a Type 1 font. | |||||
| CVE-2012-1133 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font. | |||||
| CVE-2012-1132 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font. | |||||
| CVE-2012-1131 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors related to the cell table of a font. | |||||
| CVE-2012-1130 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF font. | |||||
| CVE-2012-1129 | 2 Freetype, Mozilla | 2 Freetype, Firefox Mobile | 2026-06-16 | 9.3 HIGH | N/A |
| FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font. | |||||
