Showing 3 vulnerabilities on this page for Focus

Signals CISA KEV Ransomware Nuclei
Mozilla vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Firefox Focus elide URL allows address bar spoofing

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138.

CWE-451CWE-601Apr 30, 2025
CVSS6.1v3.1EPSS0.196%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Mozilla Firefox Use-After-Free Vulnerability

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CWE-416Dec 22, 2022
CVSS9.6v3.1EPSS2.35%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Mozilla Firefox Use-After-Free Vulnerability

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CWE-416Dec 22, 2022
CVSS8.8v3.1EPSS13.8%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX