
Tor-0day-JavaScript-Exploit
Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.

Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.

Proof-of-concept exploit for CVE-2015-7214 demonstrating Same-Origin Policy bypass in Firefox 42.0 via data and view-source URIs, with local and…

Hands-on lab to learn CVE-2024-4367 (Firefox PDF.js RCE) with PoC generation, vulnerable browser launch, and patched version verification.

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

Proof-of-concept exploit for CVE-2026-6770 targeting Firefox and Tor browsers, demonstrating the vulnerability and enabling security researchers to…

A vulnerability scanner for Firefox and Thunderbird that checks if your versions are out of date and susceptible to CVE-2024-9680.

Technical analysis and proof-of-concept exploit for CVE-2026-8389, a SpiderMonkey BaselineJIT type confusion vulnerability in Firefox, demonstrated…

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

PoC for CVE-2022-28281 a Mozilla Firefox Out of bounds write.

Exploit code for CVE-2016-9066

Proof-of-concept exploit code for Firefox CVEs (2022-1802, 1529, 2200) targeting version 100.0.1 on Windows, demonstrating browser vulnerability…

Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu

Proof-of-concept exploit for CVE-2022-26485 targeting Firefox 78.0 on Windows, demonstrating a remote code execution vulnerability in the browser's…

PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于…

PoC for CVE-2020-16012, a timing side channel in drawImage in Firefox & Chrome

Proof-of-concept exploit for CVE-2016-9079 targeting Firefox on Ubuntu x64, demonstrating a use-after-free vulnerability in the SVG animation…

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

CVE-2026-74970, Fission site isolation bypass in Firefox WebRender