|
2451
|
8.6 |
HIGH
Network
|
mozilla
|
firefox
|
Al habilitar los Contenedores Multicuenta, las solicitudes DNS podían eludir un proxy SOCKS cuando el nombre de dominio no era válido o el proxy SOCKS no respondía. Esta vulnerabilidad afecta a Firef…
|
CWE-200
Information Exposure
|
CVE-2025-6432
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2452
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user…
|
CWE-285
Improper Authorization
|
CVE-2025-6431
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2453
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Cuando se puede abrir un enlace en una aplicación externa, Firefox para Android, por defecto, pregunta al usuario antes de hacerlo. Un atacante podría haber omitido esta pregunta, exponiendo al usuar…
|
CWE-285
Improper Authorization
|
CVE-2025-6431
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2454
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a we…
|
CWE-79
Cross-site Scripting
|
CVE-2025-6430
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2455
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
Cuando se especifica la descarga de un archivo mediante el encabezado `Content-Disposition`, esta directiva se ignora si el archivo se incluye mediante una etiqueta `` u ``, lo que podría hacer que u…
|
CWE-79
Cross-site Scripting
|
CVE-2025-6430
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2456
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restric…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2025-6429
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2457
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Firefox podría haber analizado incorrectamente una URL y reescrito el dominio youtube.com al analizar la URL especificada en una etiqueta `embed`. Esto podría haber eludido las comprobaciones de segu…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2025-6429
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2458
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks.
*This bug only affects Firefox …
|
CWE-601
Open Redirect
|
CVE-2025-6428
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2459
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Al proporcionar una URL en un parámetro de cadena de consulta de enlace, Firefox para Android seguía esa URL en lugar de la correcta, lo que podía provocar ataques de phishing. *Este error solo afect…
|
CWE-601
Open Redirect
|
CVE-2025-6428
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2460
|
9.1 |
CRITICAL
Network
|
mozilla
|
firefox
|
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. Thi…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-6427
|
2026-04-14 00:17 |
2025-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|