Mozilla Vulnerabilities and Affected Products
Vulnerabilities associated with Focus.
Products
Clear product- Firefox1,739 vulnerabilities
- Thunderbird1,209 vulnerabilities
- Firefox ESR712 vulnerabilities
- firefox_esr69 vulnerabilities
- Firefox for iOS54 vulnerabilities
- Firefox for Android33 vulnerabilities
- Focus for Android17 vulnerabilities
- Focus for iOS13 vulnerabilities
- Thunderbird ESR13 vulnerabilities
- Firefox and Thunderbird7 vulnerabilities
- NSS6 vulnerabilities
- Focus3 vulnerabilities
- Hubs Cloud2 vulnerabilities
- Mozilla Bleach2 vulnerabilities
- Mozilla VPN2 vulnerabilities
- WebThings Gateway2 vulnerabilities
- Bugzilla1 vulnerability
- common-voice1 vulnerability
- Convict1 vulnerability
- Firefox for1 vulnerability
- Firefox, Firefox ESR, and Thunderbird1 vulnerability
- firefox_for_ios1 vulnerability
- focus_for_ios1 vulnerability
- geckodriver1 vulnerability
- hawk1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-3859MEDIUM | Firefox Focus elide URL allows address bar spoofingWebsites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138. | CVSS6.1v3.1 | EPSS0.196% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26486CRITICAL | Mozilla Firefox Use-After-Free VulnerabilityAn unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0. CWE-416Dec 22, 2022 | CVSS9.6v3.1 | EPSS2.35% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26485HIGH | Mozilla Firefox Use-After-Free VulnerabilityRemoving an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0. CWE-416Dec 22, 2022 | CVSS8.8v3.1 | EPSS13.8% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |