<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.mozilla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tritter</id>
	<title>MozillaWiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.mozilla.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tritter"/>
	<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/Special:Contributions/Tritter"/>
	<updated>2026-09-11T21:14:29Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.39.10</generator>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Fingerprinting/Breakage&amp;diff=1258466</id>
		<title>Fingerprinting/Breakage</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Fingerprinting/Breakage&amp;diff=1258466"/>
		<updated>2026-08-18T18:32:45Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Created page with &amp;quot;Breakage Reports for FPP / RFP   Axes:  * Firefox vs Downstream rojects that enable RFP * Confidence: ** &amp;lt;code&amp;gt;conf_axis_a&amp;lt;/code&amp;gt; - who implicated the feature (3 = causation demonstrated, 2 = preference named, 1 = inferred) ** &amp;lt;code&amp;gt;conf_axis_b&amp;lt;/code&amp;gt; - symptom match against a documented signature (2 = precise, 1 = loose, 0 = contradicted). ** Confidence overall: *** 5 = A3 *** 4 = A2 + B2 *** 3 = A1 + B2 or A2 + B1 *** 2 = A1 + B1 *** 1 = B0 (which beats A3)  == Confide...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Breakage Reports for FPP / RFP &lt;br /&gt;
&lt;br /&gt;
Axes:&lt;br /&gt;
&lt;br /&gt;
* Firefox vs Downstream rojects that enable RFP&lt;br /&gt;
* Confidence:&lt;br /&gt;
** &amp;lt;code&amp;gt;conf_axis_a&amp;lt;/code&amp;gt; - who implicated the feature (3 = causation demonstrated, 2 = preference named, 1 = inferred)&lt;br /&gt;
** &amp;lt;code&amp;gt;conf_axis_b&amp;lt;/code&amp;gt; - symptom match against a documented signature (2 = precise, 1 = loose, 0 = contradicted).&lt;br /&gt;
** Confidence overall:&lt;br /&gt;
*** 5 = A3&lt;br /&gt;
*** 4 = A2 + B2&lt;br /&gt;
*** 3 = A1 + B2 or A2 + B1&lt;br /&gt;
*** 2 = A1 + B1&lt;br /&gt;
*** 1 = B0 (which beats A3)&lt;br /&gt;
&lt;br /&gt;
== Confidence 4-5, Firefox Only ==&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;636 rows&#039;&#039;&#039; — RFP 577, FPP 59&lt;br /&gt;
* Split at the release of Firefox 115 (2023-07-04), the first release carrying a Phase 1 protection:&lt;br /&gt;
** RFP — 424 pre-FPP, 153 post-FPP&lt;br /&gt;
** FPP — 0 pre-FPP, 59 post-FPP&lt;br /&gt;
* &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|+ Confidence 4–5 breakage reports, Firefox only&lt;br /&gt;
! url !! feature !! affiliation !! reporter !! browser !! category !! date !! date_source !! fpp_era !! confidence !! conf_axis_a !! conf_axis_b&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1394448 || RFP || external || leifeld@posteo.de || Firefox || extensions || 2017-08-28 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1394735 || RFP || external || genghizkhan91@hawkradius.com || Firefox || perf-timer || 2017-08-29 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1399279 || RFP || external || marco.perez@bluewin.ch || Firefox || window-size || 2017-09-12 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1403099 || RFP || external || kalviskajaks@gmail.com || Firefox || perf-timer || 2017-09-26 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1418537 || RFP || external || samy.sadi.contact@gmail.com || Firefox || window-size || 2017-11-18 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1428331 || RFP || external || bruno.n.pagani@gmail.com || Firefox || dpr-blurry || 2018-01-05 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1437266 || RFP || external || ke5trel@protonmail.com || Firefox || perf-timer || 2018-02-10 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1442863 || RFP || external || ke5trel@protonmail.com || Firefox || perf-timer || 2018-03-03 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1446472 || RFP || external || stebs@gmx.de || Firefox || canvas || 2018-03-16 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1448423 || RFP || external || ahx27k+c4n0glofdot50@sharklasers.com || Firefox || window-size || 2018-03-23 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1448848 || RFP || external || robbendebiene@mailbox.org || Firefox || window-size || 2018-03-26 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1454059 || RFP || external || sworddragon2@gmail.com || Firefox || media-webrtc || 2018-04-13 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1468957 || RFP || external || herbert@knavs.net || Firefox || canvas || 2018-06-15 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1511941 || RFP || external || ke5trel@protonmail.com || Firefox || perf-timer || 2018-12-04 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1527747 || RFP || internal || viktor_jaegerskuepper@freenet.de || Firefox || useragent || 2019-02-13 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1532859 || RFP || external || lilydjwg@gmail.com || Firefox || dpr-blurry || 2019-03-06 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1533787 || RFP || external || 13hurdw@gmail.com || Firefox || dpr-blurry || 2019-03-08 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1535565 || RFP || external || ke5trel@protonmail.com || Firefox || window-size || 2019-03-15 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1535568 || RFP || external || ke5trel@protonmail.com || Firefox || window-size || 2019-03-15 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1537955 || RFP || external || code@daniel.priv.no || Firefox || dpr-blurry || 2019-03-21 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1540308 || RFP || external || bugzilla-mozilla.f38@capsel.org || Firefox || canvas || 2019-03-29 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1556655 || RFP || external || ke5trel@protonmail.com || Firefox || extensions || 2019-06-04 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1569561 || RFP || external || nycex@protonmail.com || Firefox || perf-timer || 2019-07-29 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1581492 || RFP || external || ke5trel@protonmail.com || Firefox || perf-timer || 2019-09-16 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1582021 || RFP || external || sionescu+bugtrackers@cddr.org || Firefox || dpr-blurry || 2019-09-18 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1585589 || RFP || external || ke5trel@protonmail.com || Firefox || perf-timer || 2019-10-02 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1589060 || RFP || external || kkolombet@gmail.com || Firefox || perf-timer || 2019-10-16 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1598862 || RFP || external || metastork@fastmail.fm || Firefox || keyboard || 2019-11-23 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1600252 || RFP || external || martin.monperrus@gmail.com || Firefox || other || 2019-11-29 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1602719 || RFP || external || herbert@knavs.net || Firefox || other || 2019-12-10 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1602721 || RFP || external || herbert@knavs.net || Firefox || other || 2019-12-10 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1609880 || RFP || external || ke5trel@protonmail.com || Firefox || dpr-blurry || 2020-01-17 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1610691 || RFP || external || wtds.trabalho@gmail.com || Firefox || canvas || 2020-01-22 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1617506 || RFP || external || tess@zrhoffman.net || Firefox || window-size || 2020-02-24 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1618537 || RFP || external || ballum@protonmail.com || Firefox || other || 2020-02-27 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1621729 || RFP || external || herbert@knavs.net || Firefox || perf-timer || 2020-03-11 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1623368 || RFP || external || u598258@disabled.tld || Firefox || media-webrtc || 2020-03-18 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1628947 || RFP || internal || yoasif@gmail.com || Firefox || canvas || 2020-04-10 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1629630 || RFP || external || wolf+mozilla@wolfsden.cz || Firefox || keyboard || 2020-04-13 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1631301 || RFP || external || dominik@greysector.net || Firefox || keyboard || 2020-04-19 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1631673 || RFP || external || jeff.roedel.isp@gmail.com || Firefox || canvas || 2020-04-21 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1644008 || RFP || external || menaquinone@tutanota.com || Firefox || keyboard || 2020-06-07 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1649050 || RFP || external || B00ze64@hotmail.com || Firefox || window-size || 2020-06-29 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1663586 || RFP || external || ym+mozilla@ymarkus.dev || Firefox || canvas || 2020-09-08 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1667435 || RFP || external || bugzil.la@wp.pl || Firefox || keyboard || 2020-09-25 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1670942 || RFP || external || u671263@disabled.tld || Firefox || dpr-blurry || 2020-10-13 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1673149 || RFP || external || noblechuk5@web.de || Firefox || timezone || 2020-10-24 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1675833 || RFP || external || manker99@tutanota.com || Firefox || keyboard || 2020-11-06 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1676028 || RFP || external || valery@ledovskoy.com || Firefox || canvas || 2020-11-08 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1684230 || RFP || external || kevin@kevinlocke.name || Firefox || webgl || 2020-12-26 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1694599 || RFP || external || tom@r.je || Firefox || media-webrtc || 2021-02-24 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1696758 || RFP || internal || jscher2000@gmail.com || Firefox || dpr-blurry || 2021-03-06 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1713619 || RFP || external || sr1.mozbugzilla@dm.binarystore.com || Firefox || canvas || 2021-05-31 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1715774 || RFP || external || collorfrisie@hotmail.com || Firefox || canvas || 2021-06-10 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1722949 || RFP || external || bpiter@poczta.onet.pl || Firefox || timezone || 2021-07-29 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1724663 || RFP || internal || yoasif@gmail.com || Firefox || canvas || 2021-08-09 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1726524 || RFP || external || anishreddy20.ar@gmail.com || Firefox || other || 2021-08-19 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1731052 || RFP || external || ke5trel@protonmail.com || Firefox || other || 2021-09-16 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1735193 || RFP || external || tom_mozilla@misfeature.net || Firefox || captcha-antibot || 2021-10-11 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1746679 || RFP || external || voruti@gmail.com || Firefox || color-scheme || 2021-12-17 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1755832 || RFP || external || gdonval+github@gmail.com || Firefox || useragent || 2022-02-17 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1757380 || RFP || external || bugzilla.63mqc@simplelogin.co || Firefox || dpr-blurry || 2022-02-28 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1757521 || RFP || external || ai34w1@navmail.net || Firefox || other || 2022-03-01 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1771648 || RFP || external || bugra@uytun.com || Firefox || other || 2022-05-29 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1772711 || RFP || external || throwaway.m62487sjyr47@getnada.com || Firefox || perf-timer || 2022-06-04 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1776573 || RFP || external || simonas+bugzilla.mozilla.org@kazlauskas.me || Firefox || color-scheme || 2022-06-25 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1780910 || RFP || external || johnathan.conley@gmail.com || Firefox || dpr-blurry || 2022-07-23 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1790988 || RFP || external || ke5trel@protonmail.com || Firefox || window-size || 2022-09-15 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1799339 || RFP || external || aoia7rz7l@relay.firefox.com || Firefox Android/Fenix || useragent || 2022-11-06 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1805101 || RFP || external || code@moral.net.au || Firefox || captcha-antibot || 2022-12-11 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1818889 || RFP || external || thorin@torproject.org || Firefox || useragent || 2023-02-25 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1825766 || RFP || internal || rbucata@mozilla.com || Firefox || webgl || 2023-03-31 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1826051 || RFP || external || ke5trel@protonmail.com || Firefox || pointer-touch || 2023-04-03 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1828197 || RFP || external || tinker123@gmail.com || Firefox || window-size || 2023-04-14 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1835987 || RFP || external || ke5trel@protonmail.com || Firefox || timezone || 2023-05-31 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1840385 || RFP || external || ke5trel@protonmail.com || Firefox || captcha-antibot || 2023-06-26 || Bugzilla API creation_time || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1850275 || FPP || external || hctamtb@gmail.com || Firefox || fonts || 2023-08-27 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1850672 || FPP || external || 6k64x4ma@gmail.com || Firefox || fonts || 2023-08-30 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1852176 || FPP || external || delvier4@outlook.com || Firefox || fonts || 2023-09-08 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1852541 || FPP || internal || rbucata@mozilla.com || Firefox || canvas || 2023-09-11 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1856186 || FPP || external || chmielcode@gmail.com || Firefox || fonts || 2023-09-30 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1857392 || FPP || external || timdortmann@gmail.com || Firefox || fonts || 2023-10-06 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1869329 || RFP || external || gaxala1852@getmola.com || Firefox || color-scheme || 2023-12-11 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1873382 || RFP || external || mike@mikedilger.com || Firefox || media-query || 2024-01-07 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1875789 || RFP || internal || rbucata@mozilla.com || Firefox || media-webrtc || 2024-01-22 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1876149 || FPP || external || enowak@onshape.com || Firefox || canvas || 2024-01-23 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1878825 || RFP || internal || ctanase@mozilla.com || Firefox || canvas || 2024-02-06 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1881993 || FPP || external || gfmshj6ww@mozmail.com || Firefox Android/Fenix || fonts || 2024-02-26 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1883263 || FPP || external || joshas@gmail.com || Firefox || fonts || 2024-03-03 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1885101 || RFP || internal || rbucata@mozilla.com || Firefox || window-size || 2024-03-13 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1887873 || RFP || internal || ctanase@mozilla.com || Firefox || canvas || 2024-03-26 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1890933 || FPP || external || pierre-bugzilla@ossman.eu || Firefox || fonts || 2024-04-11 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1892620 || FPP || external || 20h2@tutanota.com || Firefox || fonts || 2024-04-21 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1899736 || RFP || internal || rbucata@mozilla.com || Firefox || media-webrtc || 2024-05-30 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1900247 || RFP || external || fakeid.30x@gmail.com || Firefox || canvas || 2024-06-02 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1902570 || RFP || external || patrick_matezewski1@proton.me || Firefox || fonts || 2024-06-14 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1905884 || FPP || external || zephiiyr@gmail.com || Firefox || canvas || 2024-07-02 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1914307 || RFP || external || lilydjwg@gmail.com || Firefox || other || 2024-08-22 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1917427 || RFP || external || m@brehmer-adf.de || Firefox || keyboard || 2024-09-07 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1917618 || RFP || external || ke5trel@protonmail.com || Firefox || keyboard || 2024-09-09 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1917889 || RFP || external || stephen.p.enright@gmail.com || Firefox || timezone || 2024-09-10 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1947590 || RFP || external || jinra321+bugzilla@gmail.com || Firefox || canvas || 2025-02-11 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1949930 || RFP || external || sworddragon2@gmail.com || Firefox || webgl || 2025-02-22 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1953829 || RFP || external || pridefulmizuki@gmail.com || Firefox || pointer-touch || 2025-03-13 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1956251 || FPP || internal || railioaie@mozilla.com || Firefox || fonts || 2025-03-25 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1957469 || RFP || external || thorin@torproject.org || Firefox || dpr-blurry || 2025-03-31 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1963869 || RFP || external || bugzilla.inn31@8shield.de || Firefox || window-size || 2025-05-01 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1966860 || RFP || external || thorin@torproject.org || Firefox || webgl || 2025-05-16 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1969771 || RFP || external || celenity@celenity.dev || Firefox || webgl || 2025-06-01 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1977576 || RFP || external || ke5trel@protonmail.com || Firefox || canvas || 2025-07-16 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1977889 || RFP || external || vince.rubinetti@gmail.com || Firefox || canvas || 2025-07-17 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1982336 || RFP || internal || tom@mozilla.com || Firefox || hardware-concurrency || 2025-08-11 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1985741 || RFP || external || fakeid.30x@gmail.com || Firefox Android/Fenix || other || 2025-08-28 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=1986692 || FPP || internal || railioaie@mozilla.com || Firefox || other || 2025-09-03 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=2000631 || RFP || internal || rbucata@mozilla.com || Firefox || other || 2025-11-17 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=2013696 || RFP || external || georgi.yordanov@kuleuven.be || Firefox || canvas || 2026-01-31 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=2036218 || RFP || external || azomDev@pm.me || Firefox || media-webrtc || 2026-04-30 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bugzilla.mozilla.org/show_bug.cgi?id=2056380 || RFP || external || matroosoft@gmail.com || Firefox || canvas || 2026-07-20 || Bugzilla API creation_time || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/126901 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || media-webrtc || 2023-09-10 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/128638 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || perf-timer || 2023-10-20 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/137588 || RFP || external || webcompat-bot (anonymous reporter) || Firefox Android/Fenix || media-webrtc || 2024-05-30 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/174543 || FPP || external || webcompat-bot (anonymous reporter) || Firefox Focus || fonts || 2025-08-30 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/17170 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || canvas || 2018-06-06 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/24419 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || other || 2019-01-17 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/24965 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || useragent || 2019-01-27 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/30474 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || other || 2019-05-03 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/34994 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || other || 2019-07-10 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/43861#author=webcompat-botanonymousreporter || RFP || external || webcompat-bot (anonymous reporter) || Firefox || canvas || 2019-11-03 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/48704 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || perf-timer || 2020-02-20 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/54442 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || other || 2020-06-21 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/102781 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || webgl || 2022-04-17 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/103556#author=webcompat-botanonymousreporter || RFP || external || webcompat-bot (anonymous reporter) || Firefox || other || 2022-04-30 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/111999#author=webcompat-botanonymousreporter || RFP || external || webcompat-bot (anonymous reporter) || Firefox || window-size || 2022-10-08 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/117037 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || other || 2023-01-19 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/118371 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || useragent || 2023-02-17 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/118514 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || useragent || 2023-02-19 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/120417 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || useragent || 2023-04-02 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/120583 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || captcha-antibot || 2023-04-06 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/121359 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || webgl || 2023-04-23 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/143743 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || other || 2024-11-07 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/145844 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || canvas || 2025-01-02 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/173709#author=webcompat-botanonymousreporter || RFP || external || webcompat-bot (anonymous reporter) || Firefox || other || 2025-08-26 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/37837 || RFP || external || webcompat-bot (anonymous reporter) || Firefox || canvas || 2019-08-14 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/ProtonMail/comments/e7m6y2/wrong_timestamps/#author=deleted || RFP || external || [deleted] || Firefox || timezone || 2019-12-08 || Arctic Shift comment fa1h7e8 created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/191518 || FPP || external || webcompat-bot || Firefox || fonts || 2025-11-25 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/philc/vimium/issues/4053 || RFP || external || unknown || Firefox || keyboard || 2022-05-16 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/pmndrs/react-spring/issues/664 || RFP || external || unknown || Firefox || perf-timer || 2019-05-06 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/133028#author=webcompat-bot || RFP || external || webcompat-bot || Firefox || captcha-antibot || 2024-02-04 || webcompat.com API created_at (GitHub mirror), issue body — reporter webcompat-bot is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1296571#author=unknownanonymousOP || RFP || external || unknown (anonymous OP) || Firefox || canvas || 2020-07-26 || post timestamp in page HTML, via Wayback capture 20230911090924 (https://web.archive.org/web/20230911090924id_/https://support.mozilla.org/en-US/questions/1296571) -- question by &#039;anon&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-07-26T11:02:37-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/discussions/add-an-option-to-disable-quot-recover-window-size-at-startup/m-p/36525 || RFP || external || unknown (Anonymous) || Firefox || canvas || 2023-08-03 || per-post date in page HTML, via Wayback capture 20260311040217; date order DMY (score 15; published_time=2023-08-03, modified_time=2023-08-06) -- message 36525 by &#039;Anonymous&#039;, rendered &#039;03-08-2023&#039; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mvz21z/privacyresistfingerprinting_being_true_causes/ || RFP || external || [deleted] || Firefox || canvas || 2021-04-22 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/vndwqy/after_v102_update_privacyresistfingerprinting_lowers_the/ || RFP || external || deleted || Firefox || perf-timer || 2022-06-29 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discuss.privacyguides.net/t/does-partial-resistfingerprinting-make-any-sense/18827#author=Regime6045 || RFP || external || Regime6045 || Firefox || color-scheme || 2024-06-11 || Discourse API https://discuss.privacyguides.net/t/18827.json - Regime6045 posts #1 created_at 2024-06-11T14:21:17Z and #5 2024-06-11T15:32:57Z || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discuss.privacyguides.net/t/does-partial-resistfingerprinting-make-any-sense/18827#author=Regime6045~2 || RFP || external || Regime6045 || Firefox || timezone || 2024-06-11 || Discourse API https://discuss.privacyguides.net/t/18827.json - Regime6045 posts #1 created_at 2024-06-11T14:21:17Z and #5 2024-06-11T15:32:57Z || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discuss.privacyguides.net/t/does-partial-resistfingerprinting-make-any-sense/18827#author=Regime6045~3 || RFP || external || Regime6045 || Firefox || webgl || 2024-06-11 || Discourse API https://discuss.privacyguides.net/t/18827.json - Regime6045 posts #1 created_at 2024-06-11T14:21:17Z and #5 2024-06-11T15:32:57Z || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discuss.privacyguides.net/t/does-partial-resistfingerprinting-make-any-sense/18827#author=Regime6045~4 || RFP || external || Regime6045 || Firefox || keyboard || 2024-06-11 || Discourse API https://discuss.privacyguides.net/t/18827.json - Regime6045 posts #1 created_at 2024-06-11T14:21:17Z and #5 2024-06-11T15:32:57Z || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.camp-firefox.de/forum/thema/124372-falsche-uhrzeit-falsche-version-werden-angezeigt/ || RFP || external || colonius || Firefox || timezone || 2018-02-14 || post timestamp in page HTML (WoltLab &amp;amp;lt;meta itemprop=datePublished&amp;amp;gt; / JSON-LD for opening post: 2018-02-14T19:56:10+01:00, author colonius) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://blog.voina.org/firefox-took-a-wrong-time-zone-when-resistfingerprinting-is-on/#author=voina || RFP || external || voina || Firefox || timezone || 2025-03-17 || post timestamp in page HTML (og article:published_time 2025-03-17T14:44:58+00:00) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forums.mozfr.org/viewtopic.php?t=148828 || RFP || external || medyco || Firefox || timezone || 2022-05-26 || post timestamp in page HTML (phpBB &amp;amp;lt;time datetime=2022-05-26T12:52:26+00:00&amp;amp;gt; on medyco&#039;s opening post) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://necromuralist.github.io/posts/mozilla-madness-resist-fingerprinting/ || RFP || external || necromuralist (The Cloistered Monkey) || Firefox || canvas || 2021-12-23 || post timestamp in page HTML (&amp;amp;lt;time class=published dt-published datetime=2021-12-23T13:54:12-08:00&amp;amp;gt;) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://xenforo.com/community/threads/xenforo-2-3-broken-image-uploads-in-firefox-with-privacy-resistfingerprinting-true.224623/#author=Steffen || RFP || external || Steffen || Firefox || canvas || 2024-08-21 || post timestamp in page HTML via Wayback capture 20250920111737 (XenForo post-1702230, data-author=Steffen, &amp;amp;lt;time datetime=2024-08-21T10:46:28+0100&amp;amp;gt;) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://xenforo.com/community/threads/xenforo-2-3-broken-image-uploads-in-firefox-with-privacy-resistfingerprinting-true.224623/#author=Kirby || RFP || external || Kirby || Firefox || canvas || 2025-02-25 || post timestamp in page HTML via Wayback capture 20250920111737 (XenForo post-1735325, data-author=Kirby, &amp;amp;lt;time datetime=2025-02-25T10:59:54+0000&amp;amp;gt;) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gaobin.hatenablog.com/entry/2024/03/18/151041 || RFP || external || gaobin || Firefox || timezone || 2024-03-18 || post timestamp in page HTML (JSON-LD datePublished 2024-03-18T15:10:41+09:00) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discussion.fedoraproject.org/t/firefox-profile-cant-play-netflix/64949 || RFP || external || fatka || Firefox || useragent || 2021-11-22 || Discourse API /t/64949.json - post #1 by fatka, created_at 2021-11-22T01:23:01Z || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://discussion.fedoraproject.org/t/firefox-not-recognizing-installed-google-noto-fonts-for-unicode-characters/78378 || RFP || external || kaz32 || Firefox || fonts || 2022-07-27 || Discourse API /t/78378.json - post #1 by kaz32, created_at 2022-07-27T18:13:09Z || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forums.linuxmint.com/viewtopic.php?t=380595 || RFP || external || tgp1994 || Firefox || webgl || 2022-08-27 || post timestamp in page HTML via Wayback capture 20220929132036 of the sid-bearing variant (viewtopic.php?f=231&amp;amp;amp;t=380595&amp;amp;amp;sid=...): phpBB &amp;amp;lt;time datetime=2022-08-27T20:03:09+00:00&amp;amp;gt; on tgp1994&#039;s opening post || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://unixforum.org/viewtopic.php?t=156360 || RFP || external || yoricI || Firefox || dpr-blurry || 2023-09-03 || post timestamp in page HTML (phpBB; yoricI&#039;s report post &amp;amp;lt;time datetime=2023-09-03T12:11:54+00:00&amp;amp;gt;) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.ubuntu-fr.org/viewtopic.php?id=2054964 || RFP || external || Zakhar || Firefox || useragent || 2020-07-19 || post timestamp in page HTML (FluxBB post headers; opening post &#039;Le 19/07/2020, a 20:41&#039;, all of Zakhar&#039;s posts dated 19/07/2020) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.camp-firefox.de/forum/thema/136532-fenstergr%C3%B6%C3%9Fe-beim-start/ || RFP || external || BSchw || Firefox || window-size || 2023-06-23 || post timestamp in page HTML (WoltLab datePublished 2023-06-23T07:25:50+02:00, author BSchw, opening post) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/j8uw3s/ || RFP || external || KodeBenis || Firefox || canvas || 2020-10-10 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/jkml3u/ || RFP || external || theusciutat || Firefox || canvas || 2020-10-30 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/jqqat3/ || RFP || external || jerryphoto || Firefox || canvas || 2020-11-09 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/neru1j/ || RFP || external || Dionysus04 || Firefox || canvas || 2021-05-17 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/g1xerq/ || RFP || external || JonnyRobbie || Firefox || canvas || 2020-04-15 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=carebeartears || RFP || external || carebeartears || Firefox || canvas || 2020-04-10 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=__Batz__ || RFP || external || __Batz__ || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=Pentaller || RFP || external || Pentaller || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=StandingCow || RFP || external || StandingCow || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=i_bex || RFP || external || i_bex || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=Davis_o_the_Glen || RFP || external || Davis_o_the_Glen || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=Square-Banana || RFP || external || Square-Banana || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=realBurgercat || RFP || external || realBurgercat || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=straightOuttaCrypto || RFP || external || straightOuttaCrypto || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=breadnone || RFP || external || breadnone || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=warpspeedchc || RFP || external || warpspeedchc || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=eXoRainbow || RFP || external || eXoRainbow || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=traianmechenescu || RFP || external || traianmechenescu || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=condocoupon || RFP || external || condocoupon || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=ninja85a || RFP || external || ninja85a || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=mistrpopo || RFP || external || mistrpopo || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=additionality || RFP || external || additionality || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=mr4ffe || RFP || external || mr4ffe || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=S00PERSW4G1 || RFP || external || S00PERSW4G1 || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/fy6l1z/#author=TheEastStudentCenter || RFP || external || TheEastStudentCenter || Firefox || canvas || 2020-04-10 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/p0tryk/ || RFP || external || SnooPets20 || Firefox || canvas || 2021-08-09 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/jh36bj/#author=lostinfury || RFP || external || lostinfury || Firefox || timezone || 2020-10-24 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/FirefoxCSS/comments/rbvlcz/pdf_viewer_dark_theme/ || RFP || external || PolarBearVuzi || Firefox || color-scheme || 2021-12-08 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/FirefoxCSS/comments/rbvlcz/pdf_viewer_dark_theme/#hoyonet || RFP || external || voruti || Firefox || color-scheme || 2021-12-17 || Arctic Shift comment hoyonet created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=18350500 || RFP || external || lordcorvin1 || Firefox || captcha-antibot || 2018-11-01 || HN Algolia API created_at of item 18350500 (comment authored by lordcorvin1) = 2018-11-01T00:36:05+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/FoundryVTT/comments/11sk53i/cannot_see_the_map_using_firefox/ || RFP || external || Lady_Galadri3l || Firefox || webgl || 2023-03-16 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/xbvmcj/barcodelike_image_display_errors_on_several/ || RFP || external || onemanshowHU || Firefox || canvas || 2022-09-11 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/18kbaxq/rfp_breaking_image_editors_and_screenshot_tools/ || RFP || external || Ok_Trust9729 || Firefox || canvas || 2023-12-17 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/18kbaxq/rfp_breaking_image_editors_and_screenshot_tools/#kdue572 || RFP || external || Unneverseen || Firefox || canvas || 2023-12-18 || Arctic Shift comment kdue572 created_utc || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/12xxqh0/privacyresistfingerprinting_forces_webapps_to_use/ || RFP || external || LionSuneater || Firefox || timezone || 2023-04-24 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/1kgcr99/firefox_showing_wrong_time/#n24y7s7 || RFP || external || Nebur_24 || Firefox || timezone || 2025-07-09 || Arctic Shift comment n24y7s7 created_utc || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/134q0mr/windycom_graphic_errors_w_fingerprint_protections/ || RFP || external || doom99 || Firefox || webgl || 2023-05-01 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/firefox/comments/1l2a53s/letterboxing_is_broken_after_updating_to_137/ || RFP || external || IkorJefocur || Firefox || window-size || 2025-06-03 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/120271#author=lavjamanxd || RFP || external || lavjamanxd || Firefox || webgl || 2023-03-30 || webcompat.com API created_at (GitHub mirror), issue body — reporter lavjamanxd is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/132556 || RFP || external || SarenCurrie || Firefox || media-webrtc || 2024-01-22 || webcompat.com API created_at (GitHub mirror), issue body — reporter SarenCurrie is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/134423 || RFP || external || c22 || Firefox || captcha-antibot || 2024-03-08 || webcompat.com API created_at (GitHub mirror), issue body — reporter c22 is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/134913 || RFP || external || heavyboots || Firefox || canvas || 2024-03-20 || webcompat.com API created_at (GitHub mirror), issue body — reporter heavyboots is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/188106 || RFP || external || whoami730 || Firefox || webgl || 2025-11-10 || webcompat.com API created_at (GitHub mirror), issue body — reporter whoami730 is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/76532 || RFP || external || FrisoDB || Firefox || canvas || 2021-06-08 || webcompat.com API created_at (GitHub mirror), issue body — reporter FrisoDB is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/14028 || RFP || external || jawz101 || Firefox Android/Fenix || other || 2017-12-04 || webcompat.com API created_at (GitHub mirror), issue body — reporter jawz101 is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/27384 || RFP || external || wesinator || Firefox || other || 2019-03-08 || webcompat.com API comments: earliest comment by wesinator (the issue itself was filed 2019-03-07 by webcompat-bot) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/50724 || RFP || external || mastazi || Firefox || useragent || 2020-03-25 || webcompat.com API created_at (GitHub mirror), issue body — reporter mastazi is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/53644 || RFP || external || revolutionaryking7 || Firefox || other || 2020-06-02 || webcompat.com API created_at (GitHub mirror), issue body — reporter revolutionaryking7 is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/56565 || RFP || external || astatine || Firefox || perf-timer || 2020-08-13 || webcompat.com API created_at (GitHub mirror), issue body — reporter astatine is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/71751 || RFP || external || bardiharborow || Firefox || canvas || 2021-04-24 || webcompat.com API created_at (GitHub mirror), issue body — reporter bardiharborow is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/107151 || RFP || external || brochignac || Firefox || other || 2022-07-10 || webcompat.com API comments: earliest comment by brochignac (the issue itself was filed 2022-07-09 by webcompat-bot) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/115507#author=aner-perez || RFP || external || aner-perez || Firefox || useragent || 2023-04-03 || webcompat.com API comments: earliest comment by aner-perez (the issue itself was filed 2022-12-15 by kdashg) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/120690 || RFP || external || liamengland1 || Firefox || useragent || 2023-04-09 || webcompat.com API created_at (GitHub mirror), issue body — reporter liamengland1 is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/122135#author=kuehlriegecom || RFP || external || kuehlriegecom || Firefox || timezone || 2023-05-11 || webcompat.com API created_at (GitHub mirror), issue body — reporter kuehlriegecom is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/130786 || RFP || external || shtstorm || Firefox || canvas || 2023-12-07 || webcompat.com API comments: earliest comment by shtstorm (the issue itself was filed 2023-12-07 by webcompat-bot) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/132678 || RFP || external || actualwitch || Firefox || media-webrtc || 2024-01-25 || webcompat.com API created_at (GitHub mirror), issue body — reporter actualwitch is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/144836 || FPP || external || Gitoffthelawn || Firefox || other || 2024-12-04 || webcompat.com API created_at (GitHub mirror), issue body — reporter Gitoffthelawn is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/148135 || FPP || external || CuervoCarlos || Firefox || fonts || 2025-02-06 || webcompat.com API created_at (GitHub mirror), issue body — reporter CuervoCarlos is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/148135#issuecomment-2952086017 || FPP || external || MasterInQuestion || Firefox || fonts || 2025-06-07 || webcompat.com API comments: comment by MasterInQuestion (manifest comment id 2952086017 not present; ids seen: 2655896117,2952937768) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/148359 || FPP || external || Openstreetmapler || Firefox || fonts || 2025-02-11 || webcompat.com API created_at (GitHub mirror), issue body — reporter Openstreetmapler is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/169551 || RFP || external || starfoxdot64 || Firefox || canvas || 2025-07-31 || webcompat.com API created_at (GitHub mirror), issue body — reporter starfoxdot64 is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/176042 || RFP || external || lll-Death-lll || Firefox || canvas || 2025-09-08 || webcompat.com API created_at (GitHub mirror), issue body — reporter lll-Death-lll is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/192305 || RFP || external || lbedford || Firefox || other || 2025-11-30 || webcompat.com API created_at (GitHub mirror), issue body — reporter lbedford is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/199533 || RFP || external || rickgitdone || Firefox || other || 2026-01-20 || webcompat.com API comments: earliest comment by rickgitdone (the issue itself was filed 2026-01-09 by webcompat-bot) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/229904 || FPP || external || tomac4t || Firefox || captcha-antibot || 2026-07-28 || webcompat.com API created_at (GitHub mirror), issue body — reporter tomac4t is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1374798 || RFP || external || yumii || Firefox || canvas || 2022-04-20 || post timestamp in page HTML, via Wayback capture 20230609175042 (https://web.archive.org/web/20230609175042id_/https://support.mozilla.org/en-US/questions/1374798) -- question by &#039;yumii&#039;, &amp;amp;lt;time datetime=&amp;quot;2022-04-20T07:46:48-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1291925 || RFP || external || Masss || Firefox || canvas || 2020-06-19 || post timestamp in page HTML, via Wayback capture 20220925160933 (https://web.archive.org/web/20220925160933id_/https://support.mozilla.org/en-US/questions/1291925) -- question by &#039;Masss&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-06-19T23:10:37-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1322787 || RFP || external || user3452858 || Firefox || canvas || 2021-01-21 || post timestamp in page HTML, via Wayback capture 20211110135402 (https://web.archive.org/web/20211110135402id_/https://support.mozilla.org/en-US/questions/1322787) -- question by &#039;user3452858&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-01-21T22:15:37-08:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1415633 || RFP || external || GottobetheFox || Firefox || canvas || 2023-06-11 || post timestamp in page HTML, via Wayback capture 20250602180453 (https://web.archive.org/web/20250602180453id_/https://support.mozilla.org/en-US/questions/1415633) -- question by &#039;GottobetheFox&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-06-11T07:47:18-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://reddit.com/r/firefox/comments/jmbaqb/rendering_bug_certain_things_render_as_squares/ || RFP || external || lugia19 || Firefox || canvas || 2020-11-01 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/element-hq/element-web/issues/23936 || RFP || external || karolyi || Firefox || canvas || 2022-12-07 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mozilla-services/screenshots/issues/4039 || RFP || external || nrobinaubertin || Firefox || canvas || 2018-01-30 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/chrisrzhou/react-wordcloud/issues/44 || RFP || external || eeue56 || Firefox || canvas || 2020-04-06 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/tailor-cms/author/pull/696 || RFP || external || underscope || Firefox || canvas || 2026-07-07 || GitHub REST API created_at || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/NoelDeMartin/umai/issues/29 || FPP || external || jonocodes || Firefox || canvas || 2025-04-09 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/nodeca/pica/issues/244 || FPP || external || mylastore || Firefox || canvas || 2024-05-21 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://community.cloudflare.com/t/graphics-messed-up-in-games/263191 || RFP || external || seriousitykilledthec || Firefox || canvas || 2021-04-23 || Discourse API /t/263191.json - post #1 by seriousitykilledthec, created_at 2021-04-23T17:01:36Z || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://reddit.com/r/firefox/comments/mgbid4/super_specific_to_speedcloudflarenet_but_what/ || RFP || external || Dekugon || Firefox Android/Fenix || perf-timer || 2021-03-30 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/gitlab-com/gl-infra/production-engineering/-/issues/14234 || RFP || external || quyse || Firefox || captcha-antibot || 2021-09-22 || GitLab v4 API created_at (issue body) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=18615391 || RFP || external || mastazi || Firefox || captcha-antibot || 2018-12-06 || HN Algolia API created_at of item 18615391 (story authored by mastazi) = 2018-12-06T04:23:34+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=25066631 || RFP || external || mrmozero || Firefox || captcha-antibot || 2020-11-12 || HN Algolia API created_at of item 25066631 (story authored by mrmozero) = 2020-11-12T05:03:13+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://reddit.com/r/firefox/comments/ar63ii/web_whatsapp_shows_blankwhite_image/ || RFP || external || Injinear || Firefox || canvas || 2019-02-16 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/p2r3/ha.mr/issues/16 || FPP || external || eternal-sorrow || Firefox || canvas || 2026-08-14 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/firefox-corrupts-any-image-i-paste-in-on-both-linux-and-windows/83459 || RFP || external || gigabit942007 || Firefox || canvas || 2021-07-21 || Discourse API created_at for post #1 by gigabit942007 (https://discourse.mozilla.org/t/83459.json) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/firefox-corrupts-any-image-i-paste-in-on-both-linux-and-windows/83459/5 || RFP || external || slyt || Firefox || canvas || 2024-08-30 || Discourse API created_at for post #5 by slyt (https://discourse.mozilla.org/t/83459.json) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/how-to-detect-privacy-resistfingerprinting/111798 || RFP || external || juraj.masiar || Firefox || canvas || 2023-03-04 || Discourse API created_at for post #1 by juraj.masiar (https://discourse.mozilla.org/t/111798.json) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1432072#author=ShaandroSarkar || FPP || external || Shaandro Sarkar || Firefox || fonts || 2023-11-25 || post timestamp in page HTML, via Wayback capture 20250126175321 (https://web.archive.org/web/20250126175321id_/https://support.mozilla.org/en-US/questions/1432072) -- question by &#039;Shaandro Sarkar&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-11-25T15:54:34-08:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1432072#author=sqwishy || FPP || external || sqwishy || Firefox || fonts || 2023-12-06 || post timestamp in page HTML, via Wayback capture 20250126175321 (https://web.archive.org/web/20250126175321id_/https://support.mozilla.org/en-US/questions/1432072) -- answer 1622492 by &#039;sqwishy&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-12-06T09:40:38.448869-08:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1427883 || FPP || external || Benedykt Jaworski || Firefox || fonts || 2023-10-17 || post timestamp in page HTML, via Wayback capture 20251112003616 (https://web.archive.org/web/20251112003616id_/https://support.mozilla.org/en-US/questions/1427883) -- question by &#039;Benedykt Jaworski&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-10-17T05:12:42-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1423387#author=stewartsvg || FPP || external || stewartsvg || Firefox || fonts || 2023-09-08 || post timestamp in page HTML, via Wayback capture 20260316194343 (https://web.archive.org/web/20260316194343id_/https://support.mozilla.org/en-US/questions/1423387) -- question by &#039;stewartsvg&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-09-08T06:02:36-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1423387#author=ColintHart || FPP || external || Colin &#039;t Hart || Firefox || fonts || 2023-10-25 || post timestamp in page HTML, via Wayback capture 20260316194343 (https://web.archive.org/web/20260316194343id_/https://support.mozilla.org/en-US/questions/1423387) -- answer 1613749 by &#039;Colin &#039;t Hart&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-10-25T23:29:37-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/discussions/custom-font-firefox-119-0/m-p/52277#author=StAlfonzo || FPP || external || StAlfonzo || Firefox || fonts || 2023-11-04 || per-post date in page HTML, via Wayback capture 20250620204622; date order MDY (score 18; published_time=2024-02-26, modified_time=2024-02-26) -- message 44143 by &#039;StAlfonzo&#039;, rendered &#039;11-04-2023&#039; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/discussions/custom-font-firefox-119-0/m-p/52277#author=Ladan || FPP || external || Ladan || Firefox || fonts || 2024-02-26 || per-post date in page HTML, via Wayback capture 20250620204622; date order MDY (score 18; published_time=2024-02-26, modified_time=2024-02-26) -- message 52277 by &#039;Ladan&#039;, rendered &#039;02-26-2024&#039; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/discussions/private-browsing-window-does-not-use-user-setting-fonts/td-p/41846 || FPP || external || hen_mzl_feedbk || Firefox || fonts || 2023-10-12 || per-post date in page HTML, via Wayback capture 20260113022529; date order DMY (score 18; published_time=2023-10-12, modified_time=2023-11-01) -- message 41846 by &#039;hen_mzl_feedbk&#039;, rendered &#039;12-10-2023&#039; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/209636 || FPP || external || CuervoCarlos (via webcompat reporter) || Firefox || fonts || 2026-02-26 || webcompat.com API comments: earliest comment by CuervoCarlos (the issue itself was filed 2026-02-26 by webcompat-bot) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/162398 || FPP || external || nawan95 || Firefox || fonts || 2025-06-18 || webcompat.com API created_at (GitHub mirror), issue body — reporter nawan95 is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/ioBroker/ioBroker.admin/issues/2399 || FPP || external || stevenengland || Firefox || fonts || 2024-03-04 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/iiuni/projektzapisy/issues/1625 || FPP || external || lgpawel || Firefox || fonts || 2023-12-29 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discussion.fedoraproject.org/t/forced-font-substitutions/144160 || FPP || external || akane || Firefox || fonts || 2025-02-05 || Discourse API /t/144160.json - post #1 by akane, created_at 2025-02-05T22:27:03Z || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discussion.fedoraproject.org/t/microsoft-login-page-not-using-correct-font-even-though-theyre-installed/119068 || FPP || external || bingo90 || Firefox || fonts || 2024-06-05 || Discourse API /t/119068.json - post #1 by bingo90, created_at 2024-06-05T01:23:50Z || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discussion.fedoraproject.org/t/issue-with-monospace-fonts-in-firefox-on-fedora-silverblue/100528 || FPP || external || hyperreal || Firefox || fonts || 2023-12-29 || Discourse API /t/100528.json - post #1 by hyperreal, created_at 2023-12-29T22:19:20Z || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/njs-guy/bst-graph/issues/4 || FPP || external || njs-guy || Firefox || fonts || 2024-01-28 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/system-fonts/modern-font-stacks/issues/22 || FPP || external || kdekooter || Firefox || fonts || 2024-01-26 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/bobbybwoy/my-minesweeper/issues/2 || FPP || external || bobbybwoy || Firefox || fonts || 2026-01-25 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1297208 || RFP || external || ikumf || Firefox || timezone || 2020-07-30 || post timestamp in page HTML, via Wayback capture 20250814232326 (https://web.archive.org/web/20250814232326id_/https://support.mozilla.org/en-US/questions/1297208) -- question by &#039;ikumf&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-07-30T06:40:06-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1253204 || RFP || external || MichaelTheHobbit || Firefox || timezone || 2019-03-14 || post timestamp in page HTML, via Wayback capture 20250208230934 (https://web.archive.org/web/20250208230934id_/https://support.mozilla.org/en-US/questions/1253204) -- question by &#039;MichaelTheHobbit&#039;, &amp;amp;lt;time datetime=&amp;quot;2019-03-14T22:10:01-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1191823#author=ilgs || RFP || external || ilgs || Firefox || timezone || 2017-11-29 || post timestamp in page HTML, via Wayback capture 20251010012526 (https://web.archive.org/web/20251010012526id_/https://support.mozilla.org/en-US/questions/1191823) -- question by &#039;ilgs&#039;, &amp;amp;lt;time datetime=&amp;quot;2017-11-29T20:26:59-08:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1198372 || RFP || external || josiahjrutledge || Firefox || timezone || 2018-01-05 || post timestamp in page HTML, via Wayback capture 20250818090126 (https://web.archive.org/web/20250818090126id_/https://support.mozilla.org/en-US/questions/1198372) -- question by &#039;josiahjrutledge&#039;, &amp;amp;lt;time datetime=&amp;quot;2018-01-05T08:28:13-08:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1238935 || RFP || external || Scotto121 || Firefox || timezone || 2018-10-31 || post timestamp in page HTML, via Wayback capture 20190924090704 (https://web.archive.org/web/20190924090704id_/https://support.mozilla.org/en-US/questions/1238935) -- question by &#039;Scotto121&#039;, &amp;amp;lt;time datetime=&amp;quot;2018-10-31T08:46:31-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1351493 || RFP || external || Marianne || Firefox || timezone || 2021-09-22 || post timestamp in page HTML, via Wayback capture 20250408195219 (https://web.archive.org/web/20250408195219id_/https://support.mozilla.org/en-US/questions/1351493) -- question by &#039;Marianne&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-09-22T13:51:43-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1426184 || RFP || external || mad-model || Firefox || timezone || 2023-10-03 || post timestamp in page HTML, via Wayback capture 20250125152748 (https://web.archive.org/web/20250125152748id_/https://support.mozilla.org/en-US/questions/1426184) -- question by &#039;mad-model&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-10-03T21:49:37-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1288587 || RFP || external || sam41rocks || Firefox || timezone || 2020-05-27 || post timestamp in page HTML, via Wayback capture 20230923234343 (https://web.archive.org/web/20230923234343id_/https://support.mozilla.org/en-US/questions/1288587) -- question by &#039;sam41rocks&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-05-27T21:49:14-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1376159 || RFP || external || mikewp || Firefox || timezone || 2022-05-05 || post timestamp in page HTML, via Wayback capture 20240724230505 (https://web.archive.org/web/20240724230505id_/https://support.mozilla.org/en-US/questions/1376159) -- question by &#039;mikewp&#039;, &amp;amp;lt;time datetime=&amp;quot;2022-05-05T06:54:49-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1283036 || RFP || external || user2392987 || Firefox || useragent || 2020-03-28 || post timestamp in page HTML, via Wayback capture 20210830083258 (https://web.archive.org/web/20210830083258id_/https://support.mozilla.org/en-US/questions/1283036) -- question by &#039;user2392987&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-03-28T14:34:47-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mattermost/mattermost/issues/8419 || RFP || external || ghost || Firefox || timezone || 2018-03-07 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/7aj9om/wrong_timezone_only_in_one_profile_firefox_570b13/ || RFP || external || ZenekZelman || Firefox || timezone || 2017-11-03 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/8a1ksw/websites_think_im_in_the_wrong_timezone/#author=GALACTON || RFP || external || GALACTON || Firefox || timezone || 2018-04-05 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/tkio2v/since_i_got_back_from_my_trip_my_timezone_is_wrong/ || RFP || external || glop4short || Firefox || timezone || 2022-03-23 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/ewvnm1/firefox_clock_utc_set_to_different_timezone_than/ || RFP || external || TejasNacido || Firefox || timezone || 2020-01-31 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/lsbzb8/wrong_timezone_within_browser/ || RFP || external || err0r__ || Firefox || timezone || 2021-02-25 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/9sgyho/wrong_timezone/#author=yoeyHD || RFP || external || yoeyHD || Firefox || timezone || 2018-10-29 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/ogxsya/privacyresistfingerprinting_how_to_override/ || RFP || external || schklom || Firefox || timezone || 2021-07-09 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/8pfp0e/resist_fingerprinting_disabling_timezone_sync/ || RFP || external || crow-man || Firefox || timezone || 2018-06-08 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/sonarr/comments/138ir3t/times_will_be_off_with_firefox_if_you_have_resist/ || RFP || external || CallMeGooglyBear || Firefox || timezone || 2023-05-05 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/PrivacyGuides/comments/t6ow6t/fixing_time_zone_with_resist_fingerprinting/ || RFP || external || caznable || Firefox || timezone || 2022-03-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/ProtonMail/comments/e7m6y2/wrong_timestamps/#author=liperaj || RFP || external || liperaj || Firefox Android/Fenix || timezone || 2019-12-08 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/ProtonMail/comments/e7m6y2/wrong_timestamps/#author=planedrop || RFP || external || planedrop || Firefox || timezone || 2020-03-02 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1o7nsit/resist_fingerprinting_exemptions_solution/ || RFP || external || Murky_Study_5526 || Firefox || timezone || 2025-10-15 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/donetick/donetick/issues/247 || RFP || external || SRoy89 || Firefox || timezone || 2025-06-29 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/pi-hole/pi-hole/issues/4594 || RFP || external || WineBottles || Firefox || timezone || 2022-02-01 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/blakeblackshear/frigate/issues/2513 || RFP || external || oztourer || Firefox || timezone || 2021-12-23 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/codeths/ethsbell-rewrite/issues/77 || RFP || external || spaghetus || Firefox || timezone || 2021-09-21 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/WesleyBranton/Grandfather-Clock/issues/13 || RFP || external || WesleyBranton || Firefox || timezone || 2021-05-20 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/sopelj/lovelace-kanji-clock-card/issues/15 || RFP || external || sopelj || Firefox || timezone || 2024-07-27 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/tutao/tutanota/issues/3338 || RFP || external || slrslr || Firefox || timezone || 2021-08-03 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/nextcloud/server/issues/19006 || RFP || external || junglira || Firefox || timezone || 2020-01-19 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mozilla/notes/issues/1499 || RFP || external || berenddeschouwer || Firefox Android/Fenix || timezone || 2019-09-08 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/zombieFox/nightTab/issues/105#author=iam-cult || RFP || external || iam-cult || Firefox || timezone || 2021-01-07 || GitHub issue page embedded JSON: earliest comment by iam-cult || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/deshaw/jupyterlab-execute-time/issues/89 || RFP || external || loikein || Firefox || timezone || 2023-06-19 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=18590478 || RFP || external || amaccuish || Firefox || timezone || 2018-12-03 || HN Algolia API created_at of item 18590478 (comment authored by amaccuish) = 2018-12-03T17:15:08+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=47871167#author=snailmailman || RFP || external || snailmailman || Firefox || timezone || 2026-04-23 || HN Algolia API created_at of item 47871167 (comment authored by snailmailman) = 2026-04-23T00:58:50+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=48347466 || RFP || external || jeroenhd || Firefox || timezone || 2026-05-31 || HN Algolia API created_at of item 48347466 (comment authored by jeroenhd) = 2026-05-31T17:14:34+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=46027288 || RFP || external || capitainenemo || Firefox || timezone || 2025-11-23 || HN Algolia API created_at of item 46027288 (comment authored by capitainenemo) = 2025-11-23T21:01:04+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=27111027 || RFP || external || neckardt || Firefox || timezone || 2021-05-10 || HN Algolia API created_at of item 27111027 (comment authored by neckardt) = 2021-05-10T21:21:08+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=27049640 || RFP || external || cmg || Firefox || timezone || 2021-05-05 || HN Algolia API created_at of item 27049640 (comment authored by cmg) = 2021-05-05T13:37:56+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=25376878 || RFP || external || sobellian || Firefox || timezone || 2020-12-10 || HN Algolia API created_at of item 25376878 (comment authored by sobellian) = 2020-12-10T18:43:10+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=24067004 || RFP || external || stuartd || Firefox || timezone || 2020-08-06 || HN Algolia API created_at of item 24067004 (comment authored by stuartd) = 2020-08-06T00:17:51+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=23678098 || RFP || external || johnkpaul || Firefox || timezone || 2020-06-29 || HN Algolia API created_at of item 23678098 (comment authored by johnkpaul) = 2020-06-29T14:50:34+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=21735079 || RFP || external || arjunbajaj || Firefox || timezone || 2019-12-08 || HN Algolia API created_at of item 21735079 (comment authored by arjunbajaj) = 2019-12-08T09:33:47+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=21727787 || RFP || external || Nas808 || Firefox || timezone || 2019-12-07 || HN Algolia API created_at of item 21727787 (comment authored by Nas808) = 2019-12-07T01:20:48+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=17090141 || RFP || external || threecheese || Firefox || timezone || 2018-05-17 || HN Algolia API created_at of item 17090141 (comment authored by threecheese) = 2018-05-17T10:29:56+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=22246267 || RFP || external || skitter || Firefox || timezone || 2020-02-05 || HN Algolia API created_at of item 22246267 (comment authored by skitter) = 2020-02-05T12:46:41+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=29168008 || RFP || external || jamestanderson || Firefox || useragent || 2021-11-09 || HN Algolia API created_at of item 29168008 (comment authored by jamestanderson) = 2021-11-09T21:52:01+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/hj36mf/applied_privacy_settings_now_my_firefox_has_the/ || RFP || external || firefoxpluginmaker || Firefox || timezone || 2020-07-01 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/shikorism/tissue/issues/1708 || RFP || external || Al-aighumaisa || Firefox || timezone || 2026-04-11 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/uBlockOrigin/uBlock-issues/issues/2364 || RFP || external || JohnyP36 || Firefox || locale || 2022-11-16 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/tvheadend/tvheadend/issues/1629 || RFP || external || tv21 || Firefox || timezone || 2024-02-06 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/home-assistant/frontend/issues/3990 || RFP || external || themediapot || Firefox || timezone || 2019-10-12 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/nextcloud/calendar/issues/711 || RFP || external || georgehrke || Firefox || timezone || 2018-01-30 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/bitwarden/clients/issues/14016 || RFP || external || iMusynx || Firefox || window-size || 2025-03-27 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/bitwarden/clients/issues/16255 || RFP || external || AtlasC0R3 || Firefox || window-size || 2025-09-02 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/piroor/treestyletab/issues/3698 || RFP || external || bughit || Firefox || window-size || 2025-01-11 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/ericchase/addon--maximize-all-windows/issues/4 || RFP || external || e-t-l || Firefox || window-size || 2021-06-07 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/immich-app/immich/issues/8569 || RFP || external || hrdl-github || Firefox || dpr-blurry || 2024-04-06 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/SillyTavern/Extension-Live2d/pull/18 || RFP || external || dynameow || Firefox || dpr-blurry || 2026-08-02 || GitHub REST API created_at || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/misskey-dev/misskey/issues/13582 || RFP || external || spirillen || Firefox || canvas || 2024-03-17 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/fengyuanchen/compressorjs/issues/177 || RFP || external || cheong12001 || Firefox || canvas || 2023-07-13 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/lrsjng/kjua/issues/26 || RFP || external || KirbyDE || Firefox || canvas || 2025-08-13 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/woltapp/blurhash/issues/237 || RFP || external || madebr || Firefox || canvas || 2023-03-29 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/louislam/uptime-kuma/issues/3554 || RFP || external || obfusk || Firefox || canvas || 2023-08-09 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/sienori/Tab-Session-Manager/issues/1192 || RFP || external || MagicalDrizzle || Firefox || canvas || 2023-05-10 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/online-go/online-go.com/issues/1429 || RFP || external || phikal || Firefox || canvas || 2021-03-17 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/vega/vega/issues/4129 || RFP || external || mleibman || Firefox || canvas || 2025-09-12 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/tentone/geo-three/issues/97 || FPP || external || tour3d || Firefox || canvas || 2025-05-13 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/openstreetmap/openstreetmap-website/issues/6245 || RFP || external || oblyn || Firefox || canvas || 2025-07-25 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mozmorris/react-webcam/issues/398 || RFP || external || clementpoiret || Firefox || canvas || 2024-01-19 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/InventivetalentDev/MineRender/issues/133 || RFP || external || QuickWrite || Firefox || canvas || 2022-04-30 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/fingerprintjs/fingerprintjs/issues/882 || RFP || external || chuanhhoang || Firefox || canvas || 2023-03-30 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/fingerprintjs/fingerprintjs/pull/1134 || FPP || external || primarch42 || Firefox || canvas || 2026-01-22 || GitHub REST API created_at || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/openfrontio/OpenFrontIO/pull/4324 || RFP || external || evanpelle || Firefox || webgl || 2026-06-18 || GitHub REST API created_at || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/niivue/niivue/issues/582 || RFP || external || neurolabusc || Firefox || webgl || 2023-05-01 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/lfm-org/lfm/pull/42#author=tommimarkus || FPP || external || tommimarkus || Firefox || fonts || 2026-04-20 || GitHub REST API created_at || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/rstudio/rstudio/issues/4240 || RFP || external || ronblum || Firefox || keyboard || 2019-01-29 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/jgraph/drawio/issues/1248 || RFP || external || schnerring || Firefox || keyboard || 2020-10-22 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/schomery/privacy-settings/issues/115 || RFP || external || DrOakfield || Firefox || keyboard || 2019-02-07 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/translate-tools/linguist/issues/360 || RFP || external || t3dium || Firefox || keyboard || 2023-05-30 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/gdh1995/vimium-c/issues/1086 || RFP || external || 2b || Firefox || keyboard || 2024-01-31 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/gdh1995/vimium-c/issues/365 || RFP || external || tirphana || Firefox || color-scheme || 2021-06-06 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/system2k/NodeWorldOfText/issues/89 || RFP || external || system2k || Firefox || keyboard || 2024-08-29 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/tomgroenwoldt/keyglide-feedback/issues/30 || RFP || external || quantenzitrone || Firefox || keyboard || 2026-02-01 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/flytaly/multitran-extension/issues/1 || RFP || external || shvchk || Firefox || keyboard || 2020-10-24 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/MALSync/MALSync/issues/2383 || RFP || external || lemonadeforlife || Firefox || keyboard || 2024-04-22 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/FreshRSS/FreshRSS/issues/6120 || RFP || external || jsspen || Firefox || keyboard || 2024-02-21 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/jetkvm/kvm/issues/1305 || RFP || external || henrysprone || Firefox || keyboard || 2026-03-16 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/TheFantasticWarrior/chrome-extension-imagus/issues/67 || FPP || external || MrFr1day || Firefox || keyboard || 2024-03-13 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/dessant/buster/issues/168 || RFP || external || thebigmira || Firefox || captcha-antibot || 2020-05-08 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/WordPress/gutenberg/pull/30979 || RFP || external || gwwar || Firefox || perf-timer || 2021-04-19 || GitHub REST API created_at || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/aframevr/aframe/issues/4793#author=samuel-zuk || RFP || external || samuel-zuk || Firefox || perf-timer || 2021-02-11 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) — reporter is the issue author || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/not-fl3/miniquad/issues/612 || RFP || external || mochou-p || Firefox || perf-timer || 2026-03-27 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mozilla-mobile/fenix/issues/25530 || RFP || external || slashdragos || Firefox Android/Fenix || perf-timer || 2022-06-05 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/philc/vimium/pull/3701 || RFP || external || kamkudla || Firefox || perf-timer || 2020-10-27 || GitHub REST API created_at || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/ppeccin/WebMSX/issues/32 || RFP || external || oh-ren || Firefox || perf-timer || 2018-03-06 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/bigbluebutton/bigbluebutton/issues/11139 || RFP || external || knarrff || Firefox || media-webrtc || 2021-01-12 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/robert-belleman/360Composer/issues/28 || RFP || external || Derkades || Firefox || media-webrtc || 2023-05-30 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/ccd0/4chan-x/issues/1672 || RFP || external || ccd0 || Firefox || captcha-antibot || 2017-11-20 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mozilla/multi-account-containers/issues/2392 || RFP || external || Kurotaku-sama || Firefox || color-scheme || 2022-07-21 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/rugk/website-dark-mode-switcher/issues/48 || RFP || external || alexmo1997 || Firefox || color-scheme || 2022-01-04 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mbnuqw/sidebery/issues/1790 || RFP || external || k4yt3x || Firefox || color-scheme || 2024-09-08 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mbnuqw/sidebery/issues/997 || RFP || external || Xuerian || Firefox || color-scheme || 2023-03-22 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mozilla/addons/issues/13582 || RFP || internal || tomrittervg || Firefox || extensions || 2019-11-06 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/HorlogeSkynet/thunderbird-user.js/issues/43 || RFP || external || boredsquirrel || Firefox || extensions || 2024-01-20 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/laurent22/joplin/issues/8060 || RFP || external || wiwwo || Firefox || extensions || 2023-04-18 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/HorlogeSkynet/thunderbird-user.js/issues/19 || RFP || external || giving-sesame || Firefox || useragent || 2022-05-21 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/philc/vimium/pull/4000 || RFP || external || gdh1995 || Firefox || useragent || 2022-01-30 || GitHub REST API created_at || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/lusakasa/saka-key/pull/337 || RFP || external || Seanld || Firefox || useragent || 2022-02-24 || GitHub REST API created_at || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/229907 || FPP || external || tomac4t || Firefox || other || 2026-07-28 || webcompat.com API created_at (GitHub mirror), issue body — reporter tomac4t is the issue author || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/airjp73/kifu-io/issues/1 || RFP || external || MooToYouToo || Firefox || other || 2020-10-05 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/addon-page-wrongly-identifies-my-firefox-version-and-therefore-wrongly-prohibits-me-from-downloading-addons/22322 || RFP || external || Raiden || Firefox || extensions || 2017-11-22 || Discourse API created_at for post #1 by Raiden (https://discourse.mozilla.org/t/22322.json) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/error-in-retrieving-firefox-version-number/23437 || RFP || external || kalibos || Firefox || extensions || 2017-12-14 || Discourse API created_at for post #1 by kalibos (https://discourse.mozilla.org/t/23437.json) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/privacy-resistfingerprinting-true-causes-extension-popup-to-think-its-mobile/24080 || RFP || external || erik || Firefox || window-size || 2018-01-04 || Discourse API created_at for post #1 by erik (https://discourse.mozilla.org/t/24080.json) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/browser-detection-incorrect/48787 || RFP || external || gavinr || Firefox || extensions || 2019-11-19 || Discourse API created_at for post #1 by gavinr (https://discourse.mozilla.org/t/48787.json) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/useragent-string/93164 || RFP || external || priyanshugarg219 || Firefox || useragent || 2022-02-15 || Discourse API created_at for post #1 by priyanshugarg219 (https://discourse.mozilla.org/t/93164.json) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://discourse.mozilla.org/t/ebay-kleinanzeigen-ich-sage-nach-5-jahren-ff-good-bye/113208/2 || RFP || external || waterfox || Firefox || captcha-antibot || 2023-06-15 || Discourse API created_at for post #2 by waterfox (https://discourse.mozilla.org/t/113208.json) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1330258 || RFP || external || Simon || Firefox || keyboard || 2021-03-22 || post timestamp in page HTML, via Wayback capture 20240806171926 (https://web.archive.org/web/20240806171926id_/https://support.mozilla.org/en-US/questions/1330258) -- question by &#039;Simon&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-03-22T19:43:19-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1340822 || RFP || external || adnanasif2003 || Firefox || canvas || 2021-06-15 || post timestamp in page HTML, via Wayback capture 20250802063300 (https://web.archive.org/web/20250802063300id_/https://support.mozilla.org/en-US/questions/1340822) -- question by &#039;adnanasif2003&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-06-15T15:55:13-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1296571#author=xkaskade || RFP || external || xkaskade || Firefox || canvas || 2020-10-10 || post timestamp in page HTML, via Wayback capture 20230911090924 (https://web.archive.org/web/20230911090924id_/https://support.mozilla.org/en-US/questions/1296571) -- answer 1357180 by &#039;xkaskade&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-10-10T20:20:51-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1367117 || RFP || external || lng.ng || Firefox || canvas || 2022-02-06 || post timestamp in page HTML, via Wayback capture 20240901142441 (https://web.archive.org/web/20240901142441id_/https://support.mozilla.org/bm/questions/1367117) -- question by &#039;lng.ng&#039;, &amp;amp;lt;time datetime=&amp;quot;2022-02-06T20:39:48-08:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1409910 || RFP || external || felixbrakel || Firefox || color-scheme || 2023-04-03 || post timestamp in page HTML, via Wayback capture 20260518111740 (https://web.archive.org/web/20260518111740id_/https://support.mozilla.org/en-US/questions/1409910) -- question by &#039;felixbrakel&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-04-03T01:35:42-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1418875 || RFP || external || awilli || Firefox || color-scheme || 2023-07-19 || post timestamp in page HTML, via Wayback capture 20250806221023 (https://web.archive.org/web/20250806221023id_/https://support.mozilla.org/zu/questions/1418875) -- question by &#039;awilli&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-07-19T22:24:02-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1342191 || RFP || external || Bonzai Incorporated || Firefox || color-scheme || 2021-06-28 || post timestamp in page HTML, via Wayback capture 20250413142052 (https://web.archive.org/web/20250413142052id_/https://support.mozilla.org/en-US/questions/1342191) -- question by &#039;Bonzai Incorporated&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-06-28T07:46:05-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1495894 || RFP || external || unclesasha28 || Firefox || timezone || 2025-02-26 || post timestamp in page HTML, via Wayback capture 20250523064238 (https://web.archive.org/web/20250523064238id_/https://support.mozilla.org/en-US/questions/1495894) -- question by &#039;unclesasha28&#039;, &amp;amp;lt;time datetime=&amp;quot;2025-02-26T09:55:06.397079-08:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1387530 || RFP || external || ElveySync || Firefox || timezone || 2022-08-27 || post timestamp in page HTML, via Wayback capture 20231005035433 (https://web.archive.org/web/20231005035433id_/https://support.mozilla.org/de/questions/1387530) -- question by &#039;ElveySync&#039;, &amp;amp;lt;time datetime=&amp;quot;2022-08-27T19:46:16-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1349456 || RFP || external || per33 || Firefox || canvas || 2021-09-03 || post timestamp in page HTML, via Wayback capture 20240714225056 (https://web.archive.org/web/20240714225056id_/https://support.mozilla.org/en-US/questions/1349456) -- question by &#039;per33&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-09-03T17:08:37-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1565813 || RFP || external || John || Firefox || canvas || 2026-02-14 || post timestamp in page HTML, via Wayback capture 20260518193145 (https://web.archive.org/web/20260518193145id_/https://support.mozilla.org/de/questions/1565813) -- question by &#039;John&#039;, &amp;amp;lt;time datetime=&amp;quot;2026-02-14T20:41:35.842997-08:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1301461 || RFP || external || TidusWulf || Firefox || canvas || 2020-08-27 || post timestamp in page HTML, via Wayback capture 20251110072214 (https://web.archive.org/web/20251110072214id_/https://support.mozilla.org/en-US/questions/1301461) -- question by &#039;TidusWulf&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-08-27T07:35:06-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1323089 || RFP || external || Mistful || Firefox || canvas || 2021-01-24 || post timestamp in page HTML, via Wayback capture 20221005004914 (https://web.archive.org/web/20221005004914id_/https://support.mozilla.org/en-US/questions/1323089) -- question by &#039;Mistful&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-01-24T13:07:01-08:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1370019 || RFP || external || Doomwad765 || Firefox || canvas || 2022-03-07 || post timestamp in page HTML, via Wayback capture 20230614064224 (https://web.archive.org/web/20230614064224id_/https://support.mozilla.org/en-US/questions/1370019) -- question by &#039;Doomwad765&#039;, &amp;amp;lt;time datetime=&amp;quot;2022-03-07T03:02:22-08:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1351371 || RFP || external || marshall929 || Firefox || canvas || 2021-09-21 || post timestamp in page HTML, via Wayback capture 20230823014455 (https://web.archive.org/web/20230823014455id_/https://support.mozilla.org/en-US/questions/1351371) -- question by &#039;marshall929&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-09-21T13:59:40-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1345186 || RFP || external || awesome.darek || Firefox || canvas || 2021-07-27 || post timestamp in page HTML, via Wayback capture 20240915044631 (https://web.archive.org/web/20240915044631id_/https://support.mozilla.org/gl/questions/1345186) -- question by &#039;awesome.darek&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-07-27T06:18:41-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1362790 || RFP || external || crystalizedxd || Firefox || canvas || 2021-12-31 || post timestamp in page HTML, via Wayback capture 20220529095444 (https://web.archive.org/web/20220529095444id_/https://support.mozilla.org/en-US/questions/1362790) -- question by &#039;crystalizedxd&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-12-31T05:25:15-08:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1380441 || RFP || external || Shnoulle || Firefox || canvas || 2022-06-20 || post timestamp in page HTML, via Wayback capture 20250622010127 (https://web.archive.org/web/20250622010127id_/https://support.mozilla.org/en-US/questions/1380441) -- question by &#039;Shnoulle&#039;, &amp;amp;lt;time datetime=&amp;quot;2022-06-20T02:43:29-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1267343 || RFP || external || knapec.tomas || Firefox || window-size || 2019-08-24 || post timestamp in page HTML, via Wayback capture 20191114054152 (https://web.archive.org/web/20191114054152id_/https://support.mozilla.org/en-US/questions/1267343) -- question by &#039;knapec.tomas&#039;, &amp;amp;lt;time datetime=&amp;quot;2019-08-24T03:30:12-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1292991 || RFP || external || isatinov || Firefox || window-size || 2020-06-29 || post timestamp in page HTML, via Wayback capture 20260313123148 (https://web.archive.org/web/20260313123148id_/https://support.mozilla.org/en-US/questions/1292991) -- question by &#039;isatinov&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-06-29T03:52:43-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1432560 || RFP || external || X33 || Firefox || window-size || 2023-11-30 || post timestamp in page HTML, via Wayback capture 20260420100953 (https://web.archive.org/web/20260420100953id_/https://support.mozilla.org/en-US/questions/1432560) -- question by &#039;X33&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-11-30T13:44:01.810172-08:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1261112 || RFP || external || Tommaso Santojanni (ascanio1) || Firefox || window-size || 2019-06-06 || post timestamp in page HTML, via Wayback capture 20210601151210 (https://web.archive.org/web/20210601151210id_/https://support.mozilla.org/en-US/questions/1261112) -- question by &#039;Tommaso Santojanni&#039;, &amp;amp;lt;time datetime=&amp;quot;2019-06-06T06:15:42-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1268720#author=danilo.derosa.dd || RFP || external || danilo.derosa.dd || Firefox || window-size || 2019-09-12 || post timestamp in page HTML, via Wayback capture 20250331213606 (https://web.archive.org/web/20250331213606id_/https://support.mozilla.org/en-US/questions/1268720) -- question by &#039;danilo.derosa.dd&#039;, &amp;amp;lt;time datetime=&amp;quot;2019-09-12T19:49:32-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1330250 || RFP || external || JT96 || Firefox || window-size || 2021-03-23 || post timestamp in page HTML, via Wayback capture 20231021210419 (https://web.archive.org/web/20231021210419id_/https://support.mozilla.org/en-US/questions/1330250) -- question by &#039;JT96&#039;, &amp;amp;lt;time datetime=&amp;quot;2021-03-23T00:38:59-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1287998 || RFP || external || M || Firefox || window-size || 2020-05-22 || post timestamp in page HTML, via Wayback capture 20260422231252 (https://web.archive.org/web/20260422231252id_/https://support.mozilla.org/en-US/questions/1287998) -- question by &#039;M&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-05-22T23:33:28-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1286129 || RFP || external || Rocket || Firefox || fonts || 2020-05-05 || post timestamp in page HTML, via Wayback capture 20250525161155 (https://web.archive.org/web/20250525161155id_/https://support.mozilla.org/en-US/questions/1286129) -- question by &#039;Rocket&#039;, &amp;amp;lt;time datetime=&amp;quot;2020-05-05T03:21:50-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1433118#author=SouravKumarPaul || FPP || external || Sourav Kumar Paul || Firefox || fonts || 2023-12-06 || post timestamp in page HTML, via Wayback capture 20260417013728 (https://web.archive.org/web/20260417013728id_/https://support.mozilla.org/en-US/questions/1433118) -- question by &#039;Sourav Kumar Paul&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-12-06T03:54:39.382259-08:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1426612#author=Tibrella || FPP || external || Tibrella || Firefox || fonts || 2023-10-06 || post timestamp in page HTML, via Wayback capture 20260116043021 (https://web.archive.org/web/20260116043021id_/https://support.mozilla.org/en-US/questions/1426612) -- question by &#039;Tibrella&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-10-06T21:19:54-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1426612#author=hey10 || FPP || external || hey10 || Firefox || fonts || 2023-10-30 || post timestamp in page HTML, via Wayback capture 20260116043021 (https://web.archive.org/web/20260116043021id_/https://support.mozilla.org/en-US/questions/1426612) -- answer 1615021 by &#039;hey10&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-10-30T18:33:22-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1472063 || FPP || external || unknown (account deleted) || Firefox || fonts || 2024-10-30 || post timestamp in page HTML, via Wayback capture 20260705020223 (https://web.archive.org/web/20260705020223id_/https://support.mozilla.org/en-US/questions/1472063) -- question by &#039;None&#039;, &amp;amp;lt;time datetime=&amp;quot;2024-10-30T19:56:44.804562+00:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1444041#author=Al || RFP || external || Al || Firefox || media-webrtc || 2024-04-04 || post timestamp in page HTML, via Wayback capture 20260309095949 (https://web.archive.org/web/20260309095949id_/https://support.mozilla.org/en-US/questions/1444041) -- question by &#039;Al&#039;, &amp;amp;lt;time datetime=&amp;quot;2024-04-04T12:42:32.970970-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1444041#author=Al~2 || FPP || external || Al || Firefox || canvas || 2024-04-04 || post timestamp in page HTML, via Wayback capture 20260309095949 (https://web.archive.org/web/20260309095949id_/https://support.mozilla.org/en-US/questions/1444041) -- answer 1645651 by &#039;Al&#039;, &amp;amp;lt;time datetime=&amp;quot;2024-04-04T12:45:54.116683-07:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1432524 || FPP || external || DMW || Firefox || canvas || 2023-11-30 || post timestamp in page HTML, via Wayback capture 20251107015017 (https://web.archive.org/web/20251107015017id_/https://support.mozilla.org/en-US/questions/1432524) -- question by &#039;DMW&#039;, &amp;amp;lt;time datetime=&amp;quot;2023-11-30T08:52:19.598684-08:00&amp;quot;&amp;amp;gt; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1380852 || RFP || external || address201 || Firefox || useragent || 2022-06-24 || post timestamp in page HTML, via Wayback capture 20251118115735 (https://web.archive.org/web/20251118115735id_/https://support.mozilla.org/de/questions/1380852) -- question by &#039;address201&#039;, &amp;amp;lt;time datetime=&amp;quot;2022-06-24T04:16:44-07:00&amp;quot;&amp;amp;gt; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forums.mozillazine.org/viewtopic.php?f=7&amp;amp;amp;t=3035765 || RFP || external || share666 || Firefox || extensions || 2017-11-22 || phpBB &#039;Posted &amp;amp;lt;date&amp;amp;gt;&#039; timestamp in page HTML, via Wayback (https://web.archive.org/web/20191001032901id_/http://forums.mozillazine.org/viewtopic.php?f=7&amp;amp;amp;t=3035765) -- post p14779262 by &#039;share666&#039; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/discussions/window-size-problem-with-privacy-resistfingerprinting-enabled/m-p/75469 || RFP || external || Francesco1 || Firefox || window-size || 2024-10-26 || per-post date in page HTML, via Wayback capture 20251211162638; date order DMY (score 18; published_time=2024-10-26, modified_time=2024-10-26) -- message 75469 by &#039;Francesco1&#039;, rendered &#039;26-10-2024&#039; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/discussions/firefox-error-privacy-resistfingerprinting/m-p/98115 || RFP || external || Witchdoctor || Firefox || timezone || 2025-06-06 || per-post date in page HTML, via Wayback capture 20260122084223; date order DMY (score 18; published_time=2025-06-06, modified_time=2025-06-06) -- message 98115 by &#039;Witchdoctor&#039;, rendered &#039;06-06-2025&#039; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/discussions/is-all-of-privacy-resistfingerprinting-incorporated-into/m-p/23569 || RFP || external || HammondJones || Firefox || window-size || 2023-01-24 || per-post date in page HTML, via Wayback capture 20240622040342; date order MDY (score 18; published_time=2023-01-24, modified_time=2023-01-29) -- message 23569 by &#039;HammondJones&#039;, rendered &#039;01-24-2023&#039; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/ideas/firefox-browser-should-have-randomized-fingerprint/idi-p/30647 || RFP || external || wutongtaiwan || Firefox || window-size || 2023-10-11 || per-post date in page HTML, via Wayback capture 20251217040612; date order DMY (score 18; published_time=2023-04-30, modified_time=2025-06-24) -- message 41783 by &#039;wutongtaiwan&#039;, rendered &#039;11-10-2023&#039; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://connect.mozilla.org/t5/discussions/improving-the-firefox-privacy-resistfingerprinting/m-p/75246 || RFP || external || Antonio_Harris || Firefox || perf-timer || 2024-10-23 || per-post date in page HTML, via Wayback capture (nearest capture); date order MDY (score 8; published_time=2024-10-24, modified_time=2024-10-23) -- message 75246 by &#039;Antonio_Harris&#039;, rendered &#039;10-23-2024&#039; || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forums.mozillazine.org/viewtopic.php?t=3034375 || RFP || external || John Liebson || Firefox || window-size || 2017-10-19 || phpBB &#039;Posted &amp;amp;lt;date&amp;amp;gt;&#039; timestamp in page HTML, via Wayback (https://web.archive.org/web/20191008id_/http://forums.mozillazine.org/viewtopic.php?f=38&amp;amp;amp;t=3034375) -- post p14771728 by &#039;John Liebson&#039; || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forums.mozillazine.org/viewtopic.php?p=14758752 || RFP || external || 13wolfblake37 || Firefox || timezone || 2017-08-02 || bracketed from neighbouring phpBB post ids in Wayback: p=14758698 -&amp;amp;gt; 2017-08-02 (capture 20200930093953) and p=14758786 -&amp;amp;gt; 2017-08-03 (capture 20190820051727); phpBB post ids are sequential, so p=14758752 falls on 2017-08-02 or 2017-08-03. Aug 2 taken from the human-supplied thread transcript in breakage_analysis/user_supplied/mozillazine-14758752.txt, which is inside the bracket. || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/questions/78809418/why-does-canvas-todataurl-and-canvas-toblob-produce-corrupt-images-on-firefo || RFP || external || Nuno || Firefox || canvas || 2024-07-30 || Stack Exchange API creation_date for question 78809418 = 2024-07-30T00:39Z, owner Nuno || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/a/58984080 || RFP || external || Kyle Coots || Firefox || canvas || 2019-11-21 || Stack Exchange API creation_date for answer 58984080 = 2019-11-21T21:32Z, owner Kyle Coots (answer, not question, as the row&#039;s reporter is the answerer) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/questions/69655210/firefox-not-detecting-alt-key-on-keydown || RFP || external || Isla || Firefox || keyboard || 2021-10-21 || Stack Exchange API creation_date for question 69655210 = 2021-10-21T02:42Z, owner Isla || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/questions/66447420/capture-alt-ctrl-or-shift-in-firefox || RFP || external || user6299344 || Firefox || keyboard || 2021-03-02 || Stack Exchange API creation_date for question 66447420 = 2021-03-02T21:27Z, owner user6299344 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/questions/55138700/date-object-in-firefox-always-returns-milliseconds-rounded-to-hundreds#author=lamka02sk || RFP || external || lamka02sk || Firefox || perf-timer || 2019-03-13 || Stack Exchange API creation_date for question 55138700 = 2019-03-13T09:44Z, owner lamka02sk || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/questions/55138700/date-object-in-firefox-always-returns-milliseconds-rounded-to-hundreds#author=lamka02sk~2 || RFP || external || lamka02sk || Firefox || timezone || 2019-04-23 || Stack Exchange API creation_date for answer 55819504 = 2019-04-23, owner lamka02sk || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/a/48167552 || RFP || external || cam8001 || Firefox || useragent || 2018-01-09 || Stack Exchange API creation_date for answer 48167552 = 2018-01-09T11:47Z, owner cam8001 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/questions/49286957/all-the-websites-detect-wrong-os-and-browser-version-of-my-computer-why || RFP || external || Vector Rilke || Firefox || useragent || 2018-03-14 || Stack Exchange API creation_date for question 49286957 = 2018-03-14T20:18Z, owner Vector Rilke || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://superuser.com/questions/1512512/stop-firefox-from-spoofing-my-timezone || RFP || external || keddad || Firefox || timezone || 2019-12-25 || Stack Exchange API creation_date for superuser question 1512512 = 2019-12-25T20:39Z, owner keddad || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://askubuntu.com/questions/1252089/gmail-in-firefox-showing-time-in-utc-but-not-in-chromium || RFP || external || Archisman Panigrahi || Firefox || timezone || 2020-06-20 || Stack Exchange API creation_date for askubuntu question 1252089 = 2020-06-20T03:51Z, owner Archisman Panigrahi || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://unix.stackexchange.com/questions/563249/gnu-icecat-always-on-utc || RFP || external || danuker || Firefox || timezone || 2020-01-21 || Stack Exchange API creation_date for unix question 563249 = 2020-01-21T16:42Z, owner danuker || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://superuser.com/questions/1610744/how-do-i-get-around-resistfingerprinting-setting-my-preferred-firefox-theme-to-l || RFP || external || craymichael || Firefox || color-scheme || 2020-12-17 || Stack Exchange API creation_date for superuser question 1610744 = 2020-12-17T20:41Z, owner craymichael || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://superuser.com/questions/1578804/firefox-esr-on-linux-showing-windows-10-user-agent-and-will-not-change || RFP || external || Kebam || Firefox || useragent || 2020-08-18 || Stack Exchange API creation_date for superuser question 1578804 = 2020-08-18T16:43Z, owner Kebam || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://superuser.com/questions/1268321/cannot-install-addon-because-the-site-reports-im-on-ff52-while-im-using-ff57 || RFP || external || SPRBRN || Firefox || extensions || 2017-11-14 || Stack Exchange API creation_date for superuser question 1268321 = 2017-11-14T17:21Z, owner SPRBRN || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://superuser.com/questions/1699210/why-cannot-i-adjust-the-window-size-of-firefox || RFP || external || William || Firefox || window-size || 2022-01-14 || Stack Exchange API creation_date for superuser question 1699210 = 2022-01-14T08:33Z, owner William || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://askubuntu.com/questions/1525803/firefox-v-130-running-ubuntu-22-04-4-lts-opens-small-window || RFP || external || Quarty || Firefox || window-size || 2024-09-05 || Stack Exchange API creation_date for askubuntu question 1525803 = 2024-09-05T17:11Z, owner Quarty || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://askubuntu.com/questions/1175969/how-to-set-firefox-to-open-as-a-maximized-window || RFP || external || Sr8120 || Firefox || window-size || 2019-09-23 || Stack Exchange API creation_date for askubuntu question 1175969 = 2019-09-23T06:07Z, owner Sr8120 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://unix.stackexchange.com/a/648394 || RFP || external || jcklmp || Firefox || other || 2021-05-06 || Stack Exchange API creation_date for unix answer 648394 = 2021-05-06T10:29Z, owner jcklmp || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://unix.stackexchange.com/questions/402446/wrong-version-of-firefox-in-mozilla-addons-linux-mint-18-2 || RFP || external || selarcrum || Firefox || extensions || 2017-11-04 || Stack Exchange API creation_date for unix question 402446 = 2017-11-04T02:18Z, owner selarcrum || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://tor.stackexchange.com/questions/20681/new-tor-version-problem || RFP || external || Jeremiah B. Froege || Firefox || window-size || 2019-12-03 || Stack Exchange API creation_date for tor question 20681 = 2019-12-03T18:19Z, owner Jeremiah B. Froege || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=48347383 || RFP || external || jeroenhd || Firefox Android/Fenix || captcha-antibot || 2026-05-31 || HN Algolia API created_at of item 48347383 (comment authored by jeroenhd) = 2026-05-31T17:05:56+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=44670609 || RFP || external || jeroenhd || Firefox || canvas || 2025-07-24 || HN Algolia API created_at of item 44670609 (comment authored by jeroenhd) = 2025-07-24T13:44:27+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=45397506#author=capitainenemo || RFP || external || capitainenemo || Firefox || webgl || 2025-09-27 || HN Algolia API created_at of item 45397506 (comment authored by capitainenemo) = 2025-09-27T17:02:47+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=41867245 || RFP || external || BiteCode_dev || Firefox || canvas || 2024-10-17 || HN Algolia API created_at of item 41867245 (comment authored by BiteCode_dev) = 2024-10-17T07:26:40+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=35243692 || RFP || external || vesinisa || Firefox || canvas || 2023-03-21 || HN Algolia API created_at of item 35243692 (comment authored by vesinisa) = 2023-03-21T08:21:03+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=35243446 || RFP || external || chaosite || Firefox || canvas || 2023-03-21 || HN Algolia API created_at of item 35243446 (comment authored by chaosite) = 2023-03-21T07:38:32+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=35547825 || RFP || external || mishu2 || Firefox || canvas || 2023-04-12 || HN Algolia API created_at of item 35547825 (comment authored by mishu2) = 2023-04-12T22:20:12+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=19618737 || RFP || external || muxator || Firefox || canvas || 2019-04-09 || HN Algolia API created_at of item 19618737 (comment authored by muxator) = 2019-04-09T20:40:25+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=21728595 || RFP || external || decebalus1 || Firefox || timezone || 2019-12-07 || HN Algolia API created_at of item 21728595 (comment authored by decebalus1) = 2019-12-07T05:08:06+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=34576158 || RFP || external || efreak || Firefox || timezone || 2023-01-30 || HN Algolia API created_at of item 34576158 (comment authored by efreak) = 2023-01-30T05:35:30+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=31483024#author=orbital-decay~2 || RFP || external || orbital-decay || Firefox || keyboard || 2022-05-23 || HN Algolia API created_at of item 31483024 (comment authored by orbital-decay) = 2022-05-23T18:23:48+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=36431799 || RFP || external || giancarlostoro || Firefox || captcha-antibot || 2023-06-22 || HN Algolia API created_at of item 36431799 (comment authored by giancarlostoro) = 2023-06-22T13:24:36+00:00 || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://lobste.rs/c/2b7zta || RFP || external || toastal || Firefox || color-scheme || 2024-06-16 || Lobsters JSON API https://lobste.rs/c/2b7zta.json created_at 2024-06-16T08:04:35-05:00, commenting_user toastal || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://stackoverflow.com/a/48167552#comment-mins || RFP || external || mins || Firefox || useragent || 2018-04-28 || Stack Exchange API /posts/48167552/comments creation_date = 2018-04-28T14:50Z, comment 87171616, owner mins || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/16thnb3/font_fingerprinting_protection_in_firefox_118s/#author=astrumc || FPP || external || astrumc || Firefox || fonts || 2023-09-27 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/16thnb3/font_fingerprinting_protection_in_firefox_118s/#author=korinokiri || FPP || external || korinokiri || Firefox || fonts || 2023-10-20 || Arctic Shift comment created_utc (earliest comment by reporter) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1idzijr/policiesjson_not_working_for/ || FPP || external || Bingo90909 || Firefox || fonts || 2025-01-30 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1ucyonq/cant_display_baybayin_with_enhanced_tracking/ || FPP || external || Zero-ELEC || Firefox || fonts || 2026-06-22 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/qts23n/fingerprinting_via_privacyresistfingerprinting/ || RFP || external || Eejs || Firefox || window-size || 2021-11-14 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1kuxh39/are_they_intentionally_trying_to_stop_us_using/#author=Track6076 || RFP || external || Track6076 || Firefox || color-scheme || 2025-05-25 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1kuxh39/are_they_intentionally_trying_to_stop_us_using/#author=Unholy_Saint0666 || RFP || external || Unholy_Saint0666 || Firefox || color-scheme || 2025-10-04 || Arctic Shift comment created_utc (earliest comment by reporter) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/qhz2gd/i_have_privacyresistfingerprinting_set_to_true/ || RFP || external || anh0516 || Firefox || dpr-blurry || 2021-10-28 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mjwfv7/experience_with_privacyresistfingerprinting/#author=JohnDnk || RFP || external || JohnDnk || Firefox || timezone || 2021-04-04 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mjwfv7/experience_with_privacyresistfingerprinting/#author=quickbaa~2 || RFP || external || quickbaa || Firefox || fonts || 2021-04-04 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/t334aq/why_does_privacyresistfingerprinting_break_so/#author=weneeddiscriminators || RFP || external || weneeddiscriminators || Firefox || canvas || 2022-02-28 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/t334aq/why_does_privacyresistfingerprinting_break_so/#author=beermad || RFP || external || beermad || Firefox || canvas || 2022-02-28 || Arctic Shift comment created_utc (earliest comment by reporter) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/w3y4yz/question_about_privacyresistfingerprinting/ || RFP || external || Trunks8257 || Firefox || color-scheme || 2022-07-20 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/12gi729/firefox_wont_show_special_characters_such_as/ || RFP || external || MouseNo8255 || Firefox || fonts || 2023-04-09 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1768mcf/privacyresistfingerprinting_keeps_resetting/#author=NeighratorP || RFP || external || NeighratorP || Firefox || fonts || 2023-10-12 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/189yw74/strict_mode_prevents_loading_locallyinstalled_fonts/ || FPP || external || mqee || Firefox || fonts || 2023-12-03 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1pevyar/all_images_i_upload_to_firefox_are_corrupted/ || RFP || external || 0roxess || Firefox || canvas || 2025-12-05 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/cl85yt/whatsapp_web_do_not_show_qr_code_in_firefox/ || RFP || external || REIS0 || Firefox || canvas || 2019-08-02 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mmqg5e/firefox_not_showing_map_in_zillow/ || RFP || external || CorsairVelo || Firefox || canvas || 2021-04-08 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/linux4noobs/comments/k7ode0/my_system_is_set_to_use_pst_pacific_standard_time/ || RFP || external || TheAndroBoy || Firefox || timezone || 2020-12-06 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/tutanota/comments/m6wa54/configure_timezone_within_tutanota_calendar/ || RFP || external || bitpixl || Firefox || timezone || 2021-03-17 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/1isgjmd/_/mdj20tf || RFP || external || wandering_cat_ninja || Firefox || timezone || 2025-02-19 || Arctic Shift comment mdj20tf created_utc || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/1gf6rdz/_/luiw65s || RFP || external || ninjila || Firefox || timezone || 2024-10-30 || Arctic Shift comment luiw65s created_utc || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mjwfv7/experience_with_privacyresistfingerprinting/#author=rimohnid || RFP || external || rimohnid || Firefox || timezone || 2021-04-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/shjmxx/_/hy6pap6 || RFP || external || AcidicAndHostile || Firefox || timezone || 2022-02-24 || Arctic Shift comment hy6pap6 created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/t182b2/cant_get_firefox_to_launch_maximized/ || RFP || external || Steamtrigger42 || Firefox || window-size || 2022-02-25 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/u4pncv/question_privacyresistfingerprinting/ || RFP || external || Doesbadges || Firefox || window-size || 2022-04-16 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/v2i1i0/firefox_1010/ || RFP || external || longtimeskulker445 || Firefox || window-size || 2022-06-01 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/90i7qe/_/e2rodjd || RFP || external || kyiami_ || Firefox || window-size || 2018-07-21 || Arctic Shift comment e2rodjd created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/g4ifx5/_/fnzwatf || RFP || external || neverlanddd77 || Firefox || window-size || 2020-04-20 || Arctic Shift comment fnzwatf created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/qshvjd/google_docs_blurry_text_and_resistfingerprinting/ || RFP || external || LoPanDidNothingWrong || Firefox || dpr-blurry || 2021-11-12 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/12mf5l0/_/jgfiecu || RFP || external || Mision-Anti-ad7273 || Firefox || dpr-blurry || 2023-04-16 || Arctic Shift comment jgfiecu created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/t7x56j/problem_with_take_a_sceenshot_tool/ || RFP || external || k_champ || Firefox || dpr-blurry || 2022-03-06 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/wo58cl/any_way_to_keep_perpage_zoom_levels_without_turning_off/ || RFP || external || p00pinb00ts || Firefox || dpr-blurry || 2022-08-14 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/qmmrws/privacyresistfingerprinting_to_enable_is_broking_webgl/ || RFP || external || xarrup || Firefox || webgl || 2021-11-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/FoundryVTT/comments/k1pquy/a_fix_for_weird_firefox_performance_problems/ || RFP || external || Antrix225 || Firefox || webgl || 2020-11-26 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/jtcpld/google_earth_loading_forever/ || RFP || external || y2kfud || Firefox || webgl || 2020-11-13 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/lb2xqf/my_current_firefox_profile_has_terrible_performance/ || RFP || external || LimEJET || Firefox || perf-timer || 2021-02-02 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1065y4u/60hz_only_on_macbook_m1_pro/ || RFP || external || hughmungouschungus || Firefox || perf-timer || 2023-01-08 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/wd0ujb/update_103_improves_performance_on_highrefresh_rate/ || RFP || external || lbtrzw || Firefox || perf-timer || 2022-07-31 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/vr1tds/setting_exemptions_properly_for/ || RFP || external || personman44 || Firefox || perf-timer || 2022-07-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/ye6xyf/is_possible_increase_the_hz_to_144_while_browsing_on/ || RFP || external || Altair12311 || Firefox || perf-timer || 2022-10-26 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/shjmxx/_/hy6pap6#netflix || RFP || external || AcidicAndHostile || Firefox || media-webrtc || 2022-02-24 || Arctic Shift comment hy6pap6 created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1331sf1/use_speech_synthesis_while_resistfingerprinting_is_enabled/ || RFP || external || moronic_autist || Firefox || media-webrtc || 2023-04-29 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/fymnsk/_/fn7ufvo || RFP || external || letmebehealthy || Firefox || other || 2020-04-12 || Arctic Shift comment fn7ufvo created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/uq8y36/generaloverride_preferences_are_broken_in_new_esr/ || RFP || external || MelodicRecognition7 || Firefox || useragent || 2022-05-15 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/a0dvrh/stuck_in_google_captcha_hell_try_disabling_resistfingerprinting/ || RFP || external || es94hup || Firefox || captcha-antibot || 2018-11-25 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/zfyrov/_/izfpjep || RFP || external || mana-addict4652 || Firefox || captcha-antibot || 2022-12-08 || Arctic Shift comment izfpjep created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mgbid4/super_specific_to_speedcloudflarenet_but_what_data/ || RFP || external || Dekugon || Firefox || other || 2021-03-30 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/16v6lfa/resistfingerprinting_forcing_prefscolorscheme_light/ || RFP || external || privacyguy123 || Firefox || color-scheme || 2023-09-29 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1pa3qk6/privacy_and_dark_mode/ || RFP || external || PotentialAd8895 || Firefox || color-scheme || 2025-11-30 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mjwfv7/experience_with_privacyresistfingerprinting/#darkmode || RFP || external || rimohnid || Firefox || color-scheme || 2021-04-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/brtnnc/v67_override_the_colors_specified_by_the_page/ || RFP || external || Hqjjciy6sJr || Firefox || color-scheme || 2019-05-22 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/uy4rjb/website_appearance_not_working_when_enabled/ || RFP || external || voyage218 || Firefox || color-scheme || 2022-05-26 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1o7nsit/resist_fingerprinting_exemptions_solution/#lightmode || RFP || external || Murky_Study_5526 || Firefox || color-scheme || 2025-10-15 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/q1y5ms/_/hfio509 || RFP || external || chiraagnataraj || Firefox || extensions || 2021-10-05 || Arctic Shift comment hfio509 created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/wbi76v/anyone_know_why_ff_renders_some_graphics_like_this/ || RFP || external || MehMcMurdoch || Firefox || canvas || 2022-07-29 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/hj38m1/_/fwjvhkf || RFP || external || KateBeckinsale_PM_Me || Firefox || canvas || 2020-07-01 || Arctic Shift comment fwjvhkf created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/134q0mr/windycom_graphic_errors_w_fingerprint_protections/ || RFP || external || doom99 || Firefox || canvas || 2023-05-01 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/hzw88u/google_photos_completely_bricked/ || RFP || external || Nootey || Firefox || canvas || 2020-07-29 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/nnp5yg/problem_with_image_sharing_on_messaging_platforms/ || RFP || external || i_rahit_karma || Firefox || canvas || 2021-05-29 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/vr98fo/firefox_doesnt_show_font_correctly/ || RFP || external || parsa261 || Firefox || fonts || 2022-07-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/t5a90z/way_to_use_installed_fonts_without_disabling/ || RFP || external || R4360 || Firefox || fonts || 2022-03-02 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/jp9l4b/firefox_developer_edition_doesnt_seem_to_recognize/ || RFP || external || Manuel225599 || Firefox || keyboard || 2020-11-06 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mgryf1/resistfingerprinting_breaking_modifier_keys_for/ || RFP || external || Nolzi || Firefox || keyboard || 2021-03-30 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/bxtmqb/starting_firefox_maximized_windows_10_also_typing/ || RFP || external || whats_it_to_you77 || Firefox || keyboard || 2019-06-07 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/lsbcln/firefox_custom_font_and_resistfingerprinting/ || RFP || external || howyay || Firefox || locale || 2021-02-25 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/discordapp/comments/krp9th/issue_discord_web_doesnt_allow_firefox_v8401_to/ || RFP || external || Alex2002ita || Firefox || media-webrtc || 2021-01-06 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/g3cbpq/problem_when_using_jitsi_in_firefox_related_to/ || RFP || external || DrPirahnoid || Firefox || media-webrtc || 2020-04-17 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/7rlt3p/watch_netflix_on_firefox_with_custom_privacy/ || RFP || external || redcoy || Firefox || media-webrtc || 2018-01-19 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/6t1zhs/psa_suggested_privacy_related_aboutconfig_tweak/ || RFP || external || AJtfM7zT4tJdaZsm || Firefox || media-webrtc || 2017-08-11 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/fye1on/youtube_turned_lower_half_of_video_to_white_when/ || RFP || external || Kumo-Doushin || Firefox || media-webrtc || 2020-04-10 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/ggjdbe/firefox_how_do_i_turn_off_resist_fingerprint_for_a/ || RFP || external || GeniusUnleashed || Firefox || canvas || 2020-05-09 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/PrivacyGuides/comments/qegmje/fingerprinting_protection_messes_with_hcaptcha/ || RFP || external || HapHappablap || Firefox || captcha-antibot || 2021-10-23 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/htpitf/in_firefox_privacyresistfingerprinting_true/ || RFP || external || twice4k || Firefox || captcha-antibot || 2020-07-18 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/12i3elk/best_buy_is_now_blocking_firefox_users_with/ || RFP || external || homophone_police || Firefox || useragent || 2023-04-11 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/7nlws0/i_cant_install_noscript_without_turning/ || RFP || external || NumberOneKorean || Firefox || extensions || 2018-01-02 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/79811h/critical_firefox_addons_suddenly_incompatible/ || RFP || external || userkp5743608 || Firefox || extensions || 2017-10-28 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/techsupport/comments/7roxvw/new_build_firefox_addon_says_i_have_ff_52_but_i/ || RFP || external || theclassicwolf_ || Firefox || extensions || 2018-01-20 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/7jns25/firefox_57_fingerprinting_protection/ || RFP || external || TigerMaskWW3 || Firefox || extensions || 2017-12-14 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/browsers/comments/qjvw11/everything_is_now_in_light_mode_after_changing/ || RFP || external || CHEATCOD3S || Firefox || color-scheme || 2021-10-31 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/pq68l5/hardened_firefox_how_to_allow_websites_to_detect/ || RFP || external || G4PRO || Firefox || color-scheme || 2021-09-17 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/memp1f/native_dark_mode_for_websites_not_working/ || RFP || external || BBaoVanC || Firefox || color-scheme || 2021-03-27 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/dmhq4e/privacyresistfingerprinting_prefercolorscheme/ || RFP || external || kmanfred || Firefox || color-scheme || 2019-10-24 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/texyc8/firefox_override_resistfingerprinting_to_keep_a/ || RFP || external || Docop1 || Firefox || color-scheme || 2022-03-15 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mwdqs1/firefox_88_made_my_firefox_home_white/ || RFP || external || Nolzi || Firefox || color-scheme || 2021-04-22 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/ji0yqq/when_enabling_privacyresistfingerprinting_dark/ || RFP || external || unbeatable_101 || Firefox || color-scheme || 2020-10-25 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/dbfx8s/how_can_i_launch_firefox_maximized_with/ || RFP || external || tedomedo || Firefox || window-size || 2019-09-30 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/bxtmqb/starting_firefox_maximized_windows_10_also_typing/#window || RFP || external || whats_it_to_you77 || Firefox || window-size || 2019-06-07 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/FirefoxCSS/comments/c7t8cc/need_help_with_userchromecss_new_method_of/ || RFP || external || Distelzombie || Firefox || window-size || 2019-07-01 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/FirefoxCSS/comments/c2ap3b/how_to_modify_the_letterbox_color/ || RFP || external || chiraagnataraj || Firefox || window-size || 2019-06-19 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/loeida/any_way_to_set_privacyresistfingerprinting_window/ || RFP || external || TheGreatGetter || Firefox || window-size || 2021-02-20 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/7xp0ij/can_anything_be_done_to_stop_fingerprinting_by/ || RFP || external || Glerbbb || Firefox || window-size || 2018-02-15 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/ap9t1n/privacyresistfingerprinting_kills_overall_animation/ || RFP || external || codebam || Firefox || perf-timer || 2019-02-10 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/dx717c/privacyresistfingerprinting_true_makes_webgl_demos/ || RFP || external || seiji_hiwatari || Firefox || perf-timer || 2019-11-16 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/nscgnv/fingerprinting/ || RFP || external || EducationalWeek5590 || Firefox || perf-timer || 2021-06-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/vo6fe1/since_i_added_an_extra_clock_to_taskbar_webbrowser/ || RFP || external || Zloty_Diament || Firefox || timezone || 2022-06-30 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/fvue9m/firefox_issues_after_aboutconfig_adjustments/ || RFP || external || miaaaauuu || Firefox || timezone || 2020-04-06 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/hn9x5o/firefox_display_wrong_time_because_of/ || RFP || external || straightab || Firefox || timezone || 2020-07-08 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/hfpa3q/correct_time_zone_without_disabling/ || RFP || external || ultrapassado || Firefox || timezone || 2020-06-25 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/87dls6/how_important_is_privacyresistfingerprinting_and/ || RFP || external || h1sdudeness || Firefox || timezone || 2018-03-26 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/7tqvpr/privacyresistfingerprinting_timezone/#author=bamboogle || RFP || external || bamboogle || Firefox || timezone || 2018-01-29 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/tutanota/comments/gtuzjg/timezone_manual_setting_in_web_app/ || RFP || external || Earth_Believer || Firefox || timezone || 2020-05-31 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/tutanota/comments/spw1kd/change_time_zone_manually/ || RFP || external || ImpressiveFishing551 || Firefox || timezone || 2022-02-11 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/ProtonMail/comments/168n7kp/request_add_manual_timezone_override_in_mail_app/ || RFP || external || hhhtylerw || Firefox || timezone || 2023-09-03 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/g8xiht/browser_time_zone_not_in_sync/ || RFP || external || Caedos00 || Firefox || timezone || 2020-04-27 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/1dg52c0/avast_antitrack/ || RFP || external || Ok-Ocelot-8580 || Firefox || timezone || 2024-06-15 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/Ubuntu/comments/y48jxf/how_do_i_stop_images_and_text_from_displaying_as/ || RFP || external || aphot-c || Firefox || canvas || 2022-10-14 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/hmwxn9/which_firefox_aboutconfig_result_in_broken_image/ || RFP || external || GunnyMcGunsmith || Firefox || canvas || 2020-07-07 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/ProtonMail/comments/av43ey/2fa_qr_code_not_showing/ || RFP || external || CorrosiveRadiation || Firefox || canvas || 2019-02-26 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacytoolsIO/comments/lx9ksc/help_privacyresistfingerprinting_breaks_some/ || RFP || external || Rumcajs23 || Firefox || other || 2021-03-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/mk0x5a/css_animations_laggy_with_resist_fingerprinting/ || RFP || external || Valuable_Doughnut683 || Firefox || perf-timer || 2021-04-04 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/12i3elk/_/jfy1rsz || RFP || external || ScoopDat || Firefox || perf-timer || 2023-04-12 || Arctic Shift comment jfy1rsz created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/mjwfv7/_/gtdpjd9 || RFP || external || JohnDnk || Firefox || captcha-antibot || 2021-04-04 || Arctic Shift comment gtdpjd9 created_utc || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/y7tvvn/resist_fingerprinting_conflicts_with_dark_reader/ || RFP || external || fightertoad || Firefox || color-scheme || 2022-10-19 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1je0yrp/firefox_pdf_viewer_and_resist_fingerprinting_option/ || RFP || external || twinnxx || Firefox || color-scheme || 2025-03-18 || Arctic Shift post created_utc (reporter is the OP) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/ccr33s/firefox_qr_codes_not_showing/ || RFP || external || cinek2 || Firefox || canvas || 2019-07-13 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/keztky/firefox_uses_the_wrong_font/#author=Euthanasia-Waltz || RFP || external || Euthanasia-Waltz || Firefox || fonts || 2020-12-17 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/PrivacyGuides/comments/up2abc/firefox_resist_fingerprinting_exceptions/ || RFP || external || xenomorph-85 || Firefox || other || 2022-05-13 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/l0m3y2/changing_tabs_reset_the_zoom_level/ || RFP || external || Katsono || Firefox || dpr-blurry || 2021-01-19 || Arctic Shift post created_utc (reporter is the OP) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.inductiveautomation.com/t/forgotten-test-resistfingerprinting-button-background-color/72320 || RFP || external || automatisation || Firefox || other || 2023-04-11 || Discourse API /t/72320.json - post #1 by automatisation, created_at 2023-04-11T18:01:10Z || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://discussions.apple.com/thread/253950050 || RFP || external || alaricd || Firefox || canvas || 2022-06-06 || post timestamp in page HTML (JSON-LD dateCreated 2022-06-06T07:56:38-0700 / article:published_time 1654527398738, author alaricd; page also prints &#039;Posted on Jun 6, 2022 7:56 AM&#039;) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/covid19india/covid19india.github.io/issues/2042 || RFP || external || esrk || Firefox || other || 2020-06-03 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/zhukov/webogram/issues/1710 || RFP || external || Adrixan || Firefox || canvas || 2018-06-21 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/schomery/privacy-settings/issues/124 || RFP || external || Sp3r4z || Firefox || other || 2020-04-10 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/schomery/privacy-settings/issues/107 || RFP || external || iliketacos1 || Firefox || extensions || 2018-03-25 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mozilla/addons/issues/716 || RFP || external || chunacatsunflower || Firefox || extensions || 2018-05-15 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Trimps/Trimps.github.io/issues/231 || RFP || external || NLZ || Firefox || keyboard || 2021-03-30 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/jupyterlab/jupyterlab/issues/10278 || RFP || external || djangoliv || Firefox || other || 2021-05-21 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/laurent22/joplin/issues/8046 || RFP || external || junoslukan || Firefox || extensions || 2023-04-12 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/tetrio/issues/issues/1336 || RFP || external || eternal-sorrow || Firefox || webgl || 2024-07-28 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/bigbluebutton/bigbluebutton/issues/9841 || RFP || external || Socob || Firefox || media-webrtc || 2020-06-14 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/martin-t/rec-wars/issues/1 || RFP || external || martin-t || Firefox || perf-timer || 2020-08-20 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/KonaeAkira/raphael-rs/issues/163 || RFP || external || yoshiweegee || Firefox || window-size || 2025-05-06 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/eclipse-theia/theia/issues/7173 || RFP || external || Luzifer || Firefox || perf-timer || 2020-02-18 || GitHub issue page embedded JSON (JSON-LD datePublished / GraphQL createdAt) || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://support.mozilla.org/en-US/questions/1201297 || RFP || external || unknown (SUMO question owner) || Firefox || keyboard || 2018-01-23 || bracketed from adjacent SUMO question ids in Wayback: q1201275 asked 2018-01-23 (capture 20211208044321) and q1201309 asked 2018-01-23 (capture 20191210062214). SUMO question ids are sequential, so q1201297 was asked between them -- i.e. also on 2018-01-23. || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/schmednrick19.bsky.social/post/3kapv6og5yf2v || RFP || external || schmednrick19.bsky.social || Firefox || canvas || 2023-10-01 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=schmednrick19.bsky.social rkey=3kapv6og5yf2v = 2023-10-01T22:00:30.902000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/questioning.bsky.social/post/3kqbye7rvgj2x || RFP || external || questioning.bsky.social || Firefox || canvas || 2024-04-17 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=questioning.bsky.social rkey=3kqbye7rvgj2x = 2024-04-17T00:03:07.641000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/bitecode.dev/post/3l4iueto6dv2d || RFP || external || bitecode.dev || Firefox || canvas || 2024-09-19 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=bitecode.dev rkey=3l4iueto6dv2d = 2024-09-19T10:42:51.549000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/arathunku.com/post/3l7ff6netl22d || RFP || external || arathunku.com || Firefox || canvas || 2024-10-26 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=arathunku.com rkey=3l7ff6netl22d = 2024-10-26T05:48:32.846000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/boreddan.bsky.social/post/3lan43ftdrk2p || RFP || external || boreddan.bsky.social || Firefox || canvas || 2024-11-11 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=boreddan.bsky.social rkey=3lan43ftdrk2p = 2024-11-11T00:52:10.501000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/andrewstanish.com/post/3ldt7hbzxsc24 || RFP || external || andrewstanish.com || Firefox || canvas || 2024-12-21 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=andrewstanish.com rkey=3ldt7hbzxsc24 = 2024-12-21T15:24:03.766000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/ohmyrichard.bsky.social/post/3lkavbgjars2s || RFP || external || ohmyrichard.bsky.social || Firefox || canvas || 2025-03-13 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=ohmyrichard.bsky.social rkey=3lkavbgjars2s = 2025-03-13T10:30:15.820000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/caralho.org/post/3lut3taphek2b || RFP || external || caralho.org || Firefox || canvas || 2025-07-25 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=caralho.org rkey=3lut3taphek2b = 2025-07-25T22:27:27.731000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/tommis.fi/post/3lyp5y26ghk2a || RFP || external || tommis.fi || Firefox || canvas || 2025-09-13 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=tommis.fi rkey=3lyp5y26ghk2a = 2025-09-13T06:36:03.695000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/woofularunit.bsky.social/post/3m2awnyfvks2d || RFP || external || woofularunit.bsky.social || Firefox || canvas || 2025-10-03 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=woofularunit.bsky.social rkey=3m2awnyfvks2d = 2025-10-03T01:38:17.023000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/meltbananas.bsky.social/post/3mdvyf6xnyk2k || RFP || external || meltbananas.bsky.social || Firefox || canvas || 2026-02-02 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=meltbananas.bsky.social rkey=3mdvyf6xnyk2k = 2026-02-02T23:21:48.547000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/simplyhexagon.com/post/3mjkrcmfzwc2w || RFP || external || simplyhexagon.com || Firefox || canvas || 2026-04-15 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=simplyhexagon.com rkey=3mjkrcmfzwc2w = 2026-04-15T20:46:58.438000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/lot49.com/post/3mjnajgyd7k2r || RFP || external || lot49.com || Firefox || canvas || 2026-04-16 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=lot49.com rkey=3mjnajgyd7k2r = 2026-04-16T20:24:33.230000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/beezball.bsky.social/post/3mj7x52txu22v || RFP || external || beezball.bsky.social || Firefox || canvas || 2026-04-11 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=beezball.bsky.social rkey=3mj7x52txu22v = 2026-04-11T13:31:57.571000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/jnero.bsky.social/post/3mka2u3yjls2u || RFP || external || jnero.bsky.social || Firefox || canvas || 2026-04-24 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=jnero.bsky.social rkey=3mka2u3yjls2u = 2026-04-24T08:03:43.380000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/mogadontrenchcoat.bsky.social/post/3mmx57sc73c2o || RFP || external || mogadontrenchcoat.bsky.social || Firefox || canvas || 2026-05-28 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=mogadontrenchcoat.bsky.social rkey=3mmx57sc73c2o = 2026-05-28T23:07:40.512000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/newyorksfinest.bsky.social/post/3m6dfirvmic2j || RFP || external || newyorksfinest.bsky.social || Firefox || canvas || 2025-11-23 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=newyorksfinest.bsky.social rkey=3m6dfirvmic2j = 2025-11-23T22:49:54.542000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/anandphilipc.sigmoid.social.ap.brid.gy/post/3li5c3zgpx562 || RFP || external || anandphilipc@sigmoid.social || Firefox || canvas || 2025-02-14 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=anandphilipc.sigmoid.social.ap.brid.gy rkey=3li5c3zgpx562 = 2025-02-14T13:18:44+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://lemm.ee/post/62483494 || RFP || external || Lemmling@lemm.ee || Firefox || timezone || 2025-04-26 || Lemmy API via a federated copy: https://lemmy.world/api/v3/resolve_object?q=https://lemm.ee/post/62483494 -&amp;amp;gt; post.published 2025-04-26T19:33:55Z, ap_id https://lemm.ee/post/62483494, creator Lemmling@lemm.ee || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://lemmy.jlh.name/comment/3917236 || RFP || external || jlh@lemmy.jlh.name || Firefox || timezone || 2024-08-29 || lemmy.jlh.name does not resolve in DNS (instance offline); read the federated copy via lemmy.world /api/v3/resolve_object (ap_id https://lemmy.jlh.name/comment/3917236, creator jlh) published = 2024-08-29T00:03:02.606892+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://fedibird.com/@tesaguri/112924351807505479 || RFP || external || tesaguri@fedibird.com || Firefox || timezone || 2024-08-08 || Mastodon fedibird.com /api/v1/statuses/112924351807505479 created_at = 2024-08-08T03:47:44.255000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/jmhardin.bsky.social/post/3lp5m5zmesk24 || RFP || external || jmhardin.bsky.social || Firefox || window-size || 2025-05-14 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=jmhardin.bsky.social rkey=3lp5m5zmesk24 = 2025-05-14T18:15:16.870000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://fedibird.com/@tesaguri/113447005405407486 || RFP || external || tesaguri@fedibird.com || Firefox || window-size || 2024-11-08 || Mastodon fedibird.com /api/v1/statuses/113447005405407486 created_at = 2024-11-08T11:05:25.267000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/akaipixels.bsky.social/post/3ll7gyz2fbc2j || RFP || external || akaipixels.bsky.social || Firefox || color-scheme || 2025-03-25 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=akaipixels.bsky.social rkey=3ll7gyz2fbc2j = 2025-03-25T14:07:32.770000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/pulusound.fi/post/3maarrmt33s2t || RFP || external || pulusound.fi || Firefox || color-scheme || 2025-12-18 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=pulusound.fi rkey=3maarrmt33s2t = 2025-12-18T08:42:00.147000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://awful.systems/comment/9832554 || RFP || external || ebu@awful.systems || Firefox || color-scheme || 2025-12-24 || Lemmy API https://awful.systems/api/v3/comment/list?parent_id=9832554 -&amp;amp;gt; comment 9832554 published 2025-12-24T18:36:50Z, creator ebu || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/backslash-phi.bsky.social/post/3ljbhr27n4c24 || RFP || external || backslash-phi.bsky.social || Firefox || webgl || 2025-02-28 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=backslash-phi.bsky.social rkey=3ljbhr27n4c24 = 2025-02-28T22:35:55.518000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://lemmy.ml/comment/12740070 || RFP || external || ipkpjersi@lemmy.ml || Firefox || other || 2024-08-03 || Lemmy /api/v3/comment?id=12740070 published (creator ipkpjersi) = 2024-08-03T15:30:12.195120+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://fedibird.com/@U_cauda_elongata/114194210344189923 || RFP || external || U_cauda_elongata@fedibird.com || Firefox || media-webrtc || 2025-03-20 || Mastodon fedibird.com /api/v1/statuses/114194210344189923 created_at = 2025-03-20T10:09:27.803000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/atypicalhippy.bsky.social/post/3mg4mfpwsmk2a || FPP || external || atypicalhippy.bsky.social || Firefox || canvas || 2026-03-03 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=atypicalhippy.bsky.social rkey=3mg4mfpwsmk2a = 2026-03-03T01:26:22.867000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/kochich.bsky.social/post/3mba4jlrdy22m || RFP || external || kochich.bsky.social || Firefox || canvas || 2025-12-30 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=kochich.bsky.social rkey=3mba4jlrdy22m = 2025-12-30T19:46:53.175000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/tresleches0.bsky.social/post/3msqptboppc2m || RFP || external || tresleches0.bsky.social || Firefox || canvas || 2026-08-10 || Bluesky com.atproto.repo.getRecord value.createdAt for repo=tresleches0.bsky.social rkey=3msqptboppc2m = 2026-08-10T18:23:13.210000+00:00 || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Confidence 4/5 Downstream Browsers ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;406 rows&#039;&#039;&#039; — RFP 383, FPP 10, BOTH 12, UNCLEAR 1.&lt;br /&gt;
These are &#039;&#039;&#039;real RFP breakage reports, but a different population&#039;&#039;&#039;: LibreWolf, Tor&lt;br /&gt;
Browser, Mullvad Browser, arkenfox-configured Firefox, Mull/IronFox and others ship RFP&lt;br /&gt;
enabled by default, so these users never opted in. Sorted by browser, then date.&lt;br /&gt;
&lt;br /&gt;
* LibreWolf — 274&lt;br /&gt;
* Tor Browser — 40&lt;br /&gt;
* Firefox (arkenfox user.js) — 31&lt;br /&gt;
* Mullvad Browser — 31&lt;br /&gt;
* Mull / IronFox (Android) — 19&lt;br /&gt;
* Zen Browser — 6&lt;br /&gt;
* CachyOS Browser / Phoenix — 2&lt;br /&gt;
* Floorp — 2&lt;br /&gt;
* Waterfox — 1&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Caveat — the dates in this table are not verified.&#039;&#039;&#039; Consequently &amp;lt;code&amp;gt;fpp_era&amp;lt;/code&amp;gt; below is &#039;&#039;&#039;indicative only&#039;&#039;&#039;, and 22 rows have no usable date at all.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|+ Confidence 4–5 breakage reports — downstream browsers (RFP on by default)&lt;br /&gt;
! url !! feature !! affiliation !! reporter !! browser !! category !! date !! date_source !! fpp_era !! confidence !! conf_axis_a !! conf_axis_b&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/CachyOS/CachyOS-Browser-Settings/issues/19 || RFP || external || nowhereandgoodbye || CachyOS Browser / Phoenix || timezone || 2025-01-19 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1ngjh5o/how_do_i_get_rid_of_these_weird_bars/ || RFP || external || palti0r || CachyOS Browser / Phoenix || window-size || 2025-09-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/278 || RFP || external || crssi || Firefox (arkenfox user.js) || extensions || 2017-11-21 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/pyllyukko/user.js/issues/333 || RFP || external || unknown || Firefox (arkenfox user.js) || extensions || 2018-01-01 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/445 || RFP || external || bitpixl || Firefox (arkenfox user.js) || canvas || 2018-06-06 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/pyllyukko/user.js/issues/443 || RFP || external || elbaro || Firefox (arkenfox user.js) || keyboard || 2019-01-27 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/640 || RFP || external || Chippel || Firefox (arkenfox user.js) || canvas || 2019-02-08 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1106 || RFP || external || ghost || Firefox (arkenfox user.js) || color-scheme || 2021-01-30 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1119 || RFP || external || bakgwei || Firefox (arkenfox user.js) || useragent || 2021-02-17 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1253 || RFP || external || SakhG || Firefox (arkenfox user.js) || captcha-antibot || 2021-09-18 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1321 || RFP || external || anonimno1 || Firefox (arkenfox user.js) || useragent || 2022-01-06 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1371 || RFP || external || strongBurger || Firefox (arkenfox user.js) || canvas || 2022-02-13 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1394 || RFP || external || BwntyHntr || Firefox (arkenfox user.js) || keyboard || 2022-03-15 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/element-hq/element-call/issues/396 || RFP || external || opusforlife2 || Firefox (arkenfox user.js) || media-webrtc || 2022-06-11 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1567 || RFP || external || randomscumbag || Firefox (arkenfox user.js) || captcha-antibot || 2022-10-19 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1568 || RFP || external || Rafee-M || Firefox (arkenfox user.js) || perf-timer || 2022-10-22 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1618 || RFP || external || partingscientist || Firefox (arkenfox user.js) || window-size || 2023-01-19 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1621 || RFP || external || lovfi || Firefox (arkenfox user.js) || window-size || 2023-02-02 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1636 || RFP || external || practik || Firefox (arkenfox user.js) || dpr-blurry || 2023-02-26 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1704#author=docplastic || RFP || external || docplastic || Firefox (arkenfox user.js) || other || 2023-08-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1717 || BOTH || external || Thorin-II || Firefox (arkenfox user.js) || other || 2023-09-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1766 || RFP || external || d3athg0d || Firefox (arkenfox user.js) || extensions || 2023-11-20 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/yokoffing/Betterfox/discussions/261#author=Shoosh08 || FPP || external || Shoosh08 || Firefox (arkenfox user.js) || fonts || 2023-11-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/yokoffing/Betterfox/discussions/261#author=dcog989 || FPP || external || dcog989 || Firefox (arkenfox user.js) || fonts || 2023-11-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/yokoffing/Betterfox/discussions/261#author=slvrbuu || FPP || external || slvrbuu || Firefox (arkenfox user.js) || fonts || 2023-11-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1796 || RFP || external || RenePunch || Firefox (arkenfox user.js) || media-webrtc || 2024-01-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1844#author=Innocentius0 || RFP || external || Innocentius0 || Firefox (arkenfox user.js) || fonts || 2024-05-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.endeavouros.com/t/enable-html5-canvas-in-firefox-for-the-forum/67993 || RFP || external || swh || Firefox (arkenfox user.js) || canvas || 2025-02-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#author=arkenfoxThorin-II || RFP || internal || arkenfox (Thorin-II) || Firefox (arkenfox user.js) || canvas || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#author=arkenfoxThorin-II~2 || RFP || internal || arkenfox (Thorin-II) || Firefox (arkenfox user.js) || perf-timer || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#author=arkenfoxThorin-II~3 || RFP || internal || arkenfox (Thorin-II) || Firefox (arkenfox user.js) || other || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#author=arkenfoxThorin-II~4 || RFP || internal || arkenfox (Thorin-II) || Firefox (arkenfox user.js) || timezone || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#author=arkenfoxThorin-II~5 || RFP || internal || arkenfox (Thorin-II) || Firefox (arkenfox user.js) || color-scheme || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/Floorp/comments/18xaeqt/fix_resist_fingerprinting/ || RFP || external || DarkDetectiveGames || Floorp || timezone || 2024-01-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Floorp-Projects/Floorp/issues/2395 || RFP || external || dxcvvxd || Floorp || perf-timer || 2026-04-19 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/common/-/issues/32 || RFP || external || unknown || LibreWolf || color-scheme || 2020-01-01 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/114 || RFP || external || daaniiieel || LibreWolf || useragent || 2020-04-20 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/149 || RFP || external || keybreak || LibreWolf || webgl || 2021-01-14 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/156 || RFP || external || keybreak || LibreWolf || dpr-blurry || 2021-01-22 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/laffi0/stuck_with_utc/ || RFP || external || Laxryn || LibreWolf || timezone || 2021-02-01 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/windows/-/issues/22 || FPP || external || ntnguyen8054 || LibreWolf || fonts || 2021-03-06 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/m1bbg2/is_there_a_way_to_tell_librewolf_to_display_the/#author=Dpertierra99 || RFP || external || Dpertierra99 || LibreWolf || timezone || 2021-03-09 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/m1bbg2/is_there_a_way_to_tell_librewolf_to_display_the/#author=JackDostoevsky || RFP || external || JackDostoevsky || LibreWolf || timezone || 2021-03-09 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/windows/-/issues/27 || RFP || external || threadpanic || LibreWolf || color-scheme || 2021-03-15 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/FoundryVTT/comments/m5imth/max_texture_size_decreased_heavily_in_firefox/#author=VindicoAtrum || RFP || external || VindicoAtrum || LibreWolf || webgl || 2021-03-15 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/settings/-/issues/41 || RFP || external || priuatus || LibreWolf || keyboard || 2021-03-16 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/mb7qfr/librewolf_user_agent/ || RFP || external || Exzelt8042 || LibreWolf || useragent || 2021-03-23 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://unix.stackexchange.com/questions/644440/how-to-automatically-launch-librewolf-browser-in-full-screen || RFP || external || Denis || LibreWolf || window-size || 2021-04-10 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/538#author=unknownGitLab-migratedauthoranonymised || RFP || external || unknown (GitLab-migrated, author anonymised) || LibreWolf || timezone || 2021-05-23 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/538#author=unknownGitLab-migratedcommenter || RFP || external || unknown (GitLab-migrated commenter) || LibreWolf || timezone || 2021-05-23 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/on9sju/is_there_a_way_to_start_librewolf_maximized_with_css/ || RFP || external || ardouronerous || LibreWolf || window-size || 2021-07-19 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/settings/-/issues/79 || RFP || external || gradyvuckovic || LibreWolf || canvas || 2021-08-17 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/pfvxwg/different_timezones_on_protonmail/ || RFP || external || noxcadit || LibreWolf || timezone || 2021-09-01 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/poa4e8/wrong_time_zones_in_librewolf/ || RFP || external || GoodMew || LibreWolf || timezone || 2021-09-14 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/ppu8f6/is_there_a_way_to_get_accurate_time_zone/ || RFP || external || NoPrivacyPolicies || LibreWolf || timezone || 2021-09-17 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/244 || RFP || external || Filip62 || LibreWolf || captcha-antibot || 2021-09-19 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/migueravila/bento/issues/51 || RFP || external || Im-Kal || LibreWolf || timezone || 2021-10-17 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/qfdmwj/blurry_font_in_docs/ || RFP || external || ghostscepter || LibreWolf || dpr-blurry || 2021-10-25 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/common/-/issues/49 || RFP || external || lunainvictum || LibreWolf || keyboard || 2021-11-10 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/59#author=lonniebiz1 || RFP || external || lonniebiz1 || LibreWolf || timezone || 2021-11-17 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/tutao/tutanota/issues/3710 || RFP || external || FrenchGithubUser || LibreWolf || timezone || 2021-12-01 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/rihxlx/librewolf_window_size/ || RFP || external || deleted || LibreWolf || window-size || 2021-12-17 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/arch/-/issues/59 || RFP || external || Matii || LibreWolf || window-size || 2021-12-24 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://malwaretips.com/threads/librewolf-browser-a-fork-of-firefox-focused-on-privacy-security-and-freedom.102111/page-6 || RFP || external || Oxygen || LibreWolf || window-size || 2022-01-16 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/277 || RFP || external || YuriNikolai || LibreWolf || canvas || 2022-01-21 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/927 || RFP || external || Kingslayer9988 || LibreWolf || timezone || 2022-02-13 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/sv5yxa/jellyfin_gets_wrong_time_zone_from_librewolf_only/ || RFP || external || SVSBG || LibreWolf || timezone || 2022-02-18 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/source/-/issues/22 || RFP || external || kogiokka || LibreWolf || dpr-blurry || 2022-02-20 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1197 || RFP || external || hunderteins || LibreWolf || timezone || 2022-02-25 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/source/-/issues/25 || RFP || external || Neuchter || LibreWolf || perf-timer || 2022-03-08 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/tzzlv0/site_and_ui_font/ || RFP || external || NewspaperClear5861 || LibreWolf || fonts || 2022-04-09 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/settings/-/issues/170 || RFP || external || mozilianulb || LibreWolf || captcha-antibot || 2022-04-12 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/ubuntu/-/issues/7 || FPP || external || helium314 || LibreWolf || fonts || 2022-04-14 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/298 || RFP || external || kojid || LibreWolf || locale || 2022-04-21 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/settings/-/issues/175 || RFP || external || fxbrit || LibreWolf || captcha-antibot || 2022-04-21 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/LibreWolf/comments/ujocnk/openweb_comments_broken/ || RFP || external || ChiefSmash || LibreWolf || canvas || 2022-05-06 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/arch/-/issues/82 || RFP || external || Sandro774 || LibreWolf || dpr-blurry || 2022-05-07 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/v0y5wl/how_can_i_manually_change_the_pdf_viewers/ || RFP || external || goshadeazam || LibreWolf || color-scheme || 2022-05-30 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/753 || RFP || external || unknown (imported by librewolf-bot) || LibreWolf || dpr-blurry || 2022-06-01 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/macos/-/issues/64 || RFP || external || htunnicliff || LibreWolf || dpr-blurry || 2022-06-01 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/source/-/issues/56 || RFP || external || NichCodes || LibreWolf || window-size || 2022-06-02 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/vgs988/can_librewolf_be_configured_to_remember_my_window/ || RFP || external || Philalethes || LibreWolf || window-size || 2022-06-20 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1005 || RFP || external || unknown (imported by librewolf-bot) || LibreWolf || timezone || 2022-07-09 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/315 || FPP || external || rbrooklyn || LibreWolf || fonts || 2022-07-29 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/wner83/googleamazon_websites_not_loading_properly/ || RFP || external || Itchy_One_ || LibreWolf || extensions || 2022-08-13 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/x5piwv/preferscolorscheme_configuration_not_working_on/ || RFP || external || parawaa || LibreWolf || color-scheme || 2022-09-04 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/settings/-/issues/216 || RFP || external || kimariterikishi || LibreWolf || window-size || 2022-09-06 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/321 || RFP || external || ghtesting2020 || LibreWolf || color-scheme || 2022-09-11 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/ProtonMail/comments/xle5qp/time_stamps_showing_in_utc_due_to/ || RFP || external || Seeker4477 || LibreWolf || timezone || 2022-09-22 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/646 || RFP || external || jammehcow || LibreWolf || captcha-antibot || 2022-09-30 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/linux/-/issues/328 || RFP || external || 64fanatic || LibreWolf || captcha-antibot || 2022-09-30 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/source/-/issues/77 || RFP || external || jmbreuer || LibreWolf || dpr-blurry || 2022-10-15 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/yulq2k/resistfingerprinting/ || RFP || external || YourMexicanDR || LibreWolf || window-size || 2022-11-14 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/yylbkk/grant_timezone_access/ || RFP || external || gerry_mandy || LibreWolf || timezone || 2022-11-18 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/z0ztj6/librewolf_opens_as_a_window_instead_of_fullscreen/ || RFP || external || fiftydinar50 || LibreWolf || window-size || 2022-11-21 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/ztxqwl/alt_number_to_tabs_from_youtube_does_not_work_when/ || RFP || external || deleted || LibreWolf || keyboard || 2022-12-24 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/10hk97r/librewolf_or_brave/ || RFP || external || OfficialBlurii || LibreWolf || window-size || 2023-01-21 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/10jdn20/web_rdp_cursor_and_ctrl_or_shift_no_work/ || RFP || external || 2023q || LibreWolf || keyboard || 2023-01-23 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/117c3rf/browser_now_has_unique_fingerprint/ || RFP || external || jtrox02 || LibreWolf || useragent || 2023-02-20 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/11sk53i/_/jcgvtm0 || RFP || external || Matt_Dragoon || LibreWolf || webgl || 2023-03-16 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/11ujko1/how_do_i_stop_librewolf_from_setting_the_sites/ || RFP || external || mukidon || LibreWolf || locale || 2023-03-18 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/11wz497/problems_with_netflix_and/ || RFP || external || CrazedTamar || LibreWolf || media-webrtc || 2023-03-20 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/traggo/server/issues/141#author=langfingaz || RFP || external || langfingaz || LibreWolf || timezone || 2023-04-12 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/source/-/issues/120 || RFP || external || mlaparie || LibreWolf || color-scheme || 2023-04-18 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/12sgub0/librewolf_window_size/ || RFP || external || eastmpman || LibreWolf || window-size || 2023-04-20 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/debian/-/issues/23 || RFP || external || test1LKJF16 || LibreWolf || window-size || 2023-05-03 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/librewolf-community/browser/source/-/issues/126 || RFP || external || jmbreuer || LibreWolf || canvas || 2023-05-31 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/14kcs34/small_technical_issue/ || RFP || external || Pastalala || LibreWolf || color-scheme || 2023-06-27 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://unix.stackexchange.com/questions/750038/librewolf-browser-unable-to-remember-view-settings || RFP || external || user280674 || LibreWolf || other || 2023-06-28 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/155qjlw/how_to_remove_refresh_rate_lock/ || RFP || external || Kris_0605 || LibreWolf || perf-timer || 2023-07-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1571 || RFP || internal || fxbrit || LibreWolf || dpr-blurry || 2023-08-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1652hwu/is_it_possible_to_have_resist_fingerprinting/ || RFP || external || Infinite100p || LibreWolf || timezone || 2023-08-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/135 || BOTH || external || felschr || LibreWolf || dpr-blurry || 2023-09-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/gdh1995/vimium-c/issues/1010 || RFP || external || ekhodx || LibreWolf || keyboard || 2023-09-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/16whsmq/resistfingerprinting_stuttering/ || RFP || external || BratyKarpaty22 || LibreWolf || perf-timer || 2023-09-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/17a5i50/dark_mode_workaround/ || RFP || external || paroxsitic || LibreWolf || color-scheme || 2023-10-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/K3V1991/LibreWolf-Disable-ResistFingerprinting-to-log-in-to-Twitch/issues/1 || RFP || external || K3V1991 || LibreWolf || captcha-antibot || 2023-11-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/18976ji/discord_bug/#author=Catkook || RFP || external || Catkook || LibreWolf || timezone || 2023-12-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/18976ji/discord_bug/#author=letsmodpcs || RFP || external || letsmodpcs || LibreWolf || timezone || 2023-12-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/18ibe0t/resistfingerprinting_slows_down_the_browser/ || RFP || external || tigerros1 || LibreWolf || perf-timer || 2023-12-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/18jkwf8/uploading_images_on_librewolf_while_using_rfp/ || RFP || external || ExcaliburIN_Games || LibreWolf || canvas || 2023-12-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1733 || RFP || external || Flagpole || LibreWolf || canvas || 2024-01-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1965c95/resist_fingerprinting_without_60hz_lock/ || RFP || external || bemfrvL || LibreWolf || perf-timer || 2024-01-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/198nmfv/how_can_i_fix_the_timezone_issue_without_screwing/#author=ExcaliburIN_Games || RFP || external || ExcaliburIN_Games || LibreWolf || timezone || 2024-01-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/198nmfv/how_can_i_fix_the_timezone_issue_without_screwing/#author=mudderfudden || RFP || external || mudderfudden || LibreWolf || timezone || 2024-01-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/19amlmf/google_meet_no_longer_able_to_use_camera_or_mic_in/ || RFP || external || Ceiu || LibreWolf || media-webrtc || 2024-01-19 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1altutd/calendar_issue/ || RFP || external || Desperate_Dot_8197 || LibreWolf || locale || 2024-02-08 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1bc61z0/uploaded_photos_blank_with_stripes/ || RFP || external || Ok-Bass-5368 || LibreWolf || canvas || 2024-03-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1bfyq1f/how_to_managemake_resistfingerprinting_exceptions/ || RFP || external || wowxiz || LibreWolf || canvas || 2024-03-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1832#author=Drainage2601 || RFP || external || Drainage2601 || LibreWolf || timezone || 2024-03-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1832#author=Tom-Ottawa || RFP || external || Tom-Ottawa || LibreWolf || timezone || 2024-03-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://programming.dev/post/12638571 || RFP || external || starman@programming.dev || LibreWolf || color-scheme || 2024-04-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1c9di2q/is_there_anyway_to_keep_the_120_hz_refresh_rate/ || RFP || external || ILikeToCommentStuff || LibreWolf || perf-timer || 2024-04-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1d9d3k4/dark_mode_websites_despite_resist_fingerprinting/ || RFP || external || LowOwl4312 || LibreWolf || color-scheme || 2024-06-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1dfo33b/timezone_in_online_calendar/ || RFP || external || noideawhattowriteZZ || LibreWolf || timezone || 2024-06-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1di9395/is_canvas_blocker_enough_to_compensate_for/ || RFP || external || Lobiankk || LibreWolf || perf-timer || 2024-06-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1913 || RFP || external || MikolajQ || LibreWolf || canvas || 2024-06-27 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1941 || RFP || external || laurel11 || LibreWolf || timezone || 2024-07-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://lemmy.ca/post/25314557 || RFP || external || streetfestival@lemmy.ca || LibreWolf || timezone || 2024-07-19 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://slrpnk.net/post/11653574 || RFP || external || Sunny@slrpnk.net || LibreWolf || canvas || 2024-07-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/novnc/noVNC/issues/1882 || RFP || external || Lonniebiz || LibreWolf || keyboard || 2024-08-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://sh.itjust.works/comment/13089178 || RFP || external || GoogleSellsAds@sh.itjust.works || LibreWolf || color-scheme || 2024-08-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/1979 || RFP || external || p1zzab0y || LibreWolf || timezone || 2024-08-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1enu7zu/how_can_i_enable_120hz_rendering_with/ || RFP || external || ethanol_addicted || LibreWolf || perf-timer || 2024-08-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/drunohazarb/4chan-captcha-solver/issues/27 || RFP || external || cRu572Vltn || LibreWolf || canvas || 2024-08-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/290 || RFP || external || Giger22 || LibreWolf || canvas || 2024-08-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/1eycshw/_/ljny0m6 || RFP || external || tetratheta || LibreWolf || window-size || 2024-08-24 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1f0f6qe/persite_fingerprinting_exceptions/ || RFP || external || TannieMielie || LibreWolf || webgl || 2024-08-24 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://lemmy.sdf.org/comment/14001931 || RFP || external || ExtremeDullard@lemmy.sdf.org || LibreWolf || timezone || 2024-08-31 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.proxmox.com/threads/firefox-ctrl-or-shift-or-alt-not-working-in-guest-vm.88926/#author=PrimozR || RFP || external || PrimozR || LibreWolf || keyboard || 2024-09-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.proxmox.com/threads/firefox-ctrl-or-shift-or-alt-not-working-in-guest-vm.88926/#author=silverstone || RFP || external || silverstone || LibreWolf || keyboard || 2024-09-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.proxmox.com/threads/firefox-ctrl-or-shift-or-alt-not-working-in-guest-vm.88926/#author=unknownpost19 || RFP || external || unknown (post #19) || LibreWolf || keyboard || 2024-09-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1ffetln/surfing_from_a_different_timezone/ || RFP || external || mtymty || LibreWolf || timezone || 2024-09-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Write/TangerineUI-Userscript/issues/5 || RFP || external || codenyte || LibreWolf || color-scheme || 2024-10-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1g6abes/enable_fingerprinting_but_not_mess_with_timezone/#author=shalintj || RFP || external || shalintj || LibreWolf || timezone || 2024-10-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/stormys.diaper.tf/post/3l6v4n6iakw2h || RFP || external || stormys.diaper.tf || LibreWolf || canvas || 2024-10-19 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2109#author=Ghostdeletedaccount || RFP || external || Ghost (deleted account) || LibreWolf || timezone || 2024-10-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2109#author=princeb71 || RFP || external || princeb71 || LibreWolf || timezone || 2024-10-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2109#author=tuyennguyen || RFP || external || tuyennguyen || LibreWolf || timezone || 2024-10-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1ga668k/librewolf_messes_up_with_timestamps/ || RFP || external || Worms38 || LibreWolf || timezone || 2024-10-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/browsers/comments/1h33rve/why_is_this_happening_i_use_librewolf/ || RFP || external || a_dvaitha || LibreWolf || canvas || 2024-11-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://lemmy.world/post/42004652 || RFP || external || MunkyNutts || LibreWolf || timezone || 2025-01 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/LuteOrg/lute-v3/issues/564 || RFP || external || Skivling || LibreWolf || timezone || 2025-01-08 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2191 || RFP || external || citizen456 || LibreWolf || window-size || 2025-01-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2224 || RFP || external || ranged1 || LibreWolf || canvas || 2025-02-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/kirenida.bsky.social/post/3lj4bbpiyjk2x || RFP || external || kirenida.bsky.social || LibreWolf || perf-timer || 2025-02-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://fosstodon.org/@foo/114083080802006074 || RFP || external || foo@fosstodon.org || LibreWolf || color-scheme || 2025-02-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1j09gz4/youtube_videos_image_briefly_freezes_periodically/ || RFP || external || Kumokumoku || LibreWolf || media-webrtc || 2025-02-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/softailfox.bsky.social/post/3ljdwtutez22l || RFP || external || softailfox.bsky.social || LibreWolf || canvas || 2025-03-01 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1j0mast/new_librewolf_users_a_couple_tips_to_help_with_your/ || RFP || external || Aexertus || LibreWolf || color-scheme || 2025-03-01 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/413 || RFP || external || SFGrenade || LibreWolf || canvas || 2025-03-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/smalladventures.net/post/3ljiqaxu23k26 || RFP || external || smalladventures.net || LibreWolf || canvas || 2025-03-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2271#author=CsyeCokTheSolly || RFP || external || CsyeCokTheSolly || LibreWolf || canvas || 2025-03-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2271#author=LiPeK || RFP || external || LiPeK || LibreWolf || canvas || 2025-03-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2271#author=arizona_rifraf || RFP || external || arizona_rifraf || LibreWolf || canvas || 2025-03-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1j2gxmv/different_time_on_whatsapp_web/ || RFP || external || Embody248 || LibreWolf || timezone || 2025-03-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/duke.hyena.zone/post/3ljl7c3r3jk26 || RFP || external || duke.hyena.zone || LibreWolf || canvas || 2025-03-04 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2302 || RFP || external || Danos || LibreWolf || canvas || 2025-03-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1j4xoef/spoofed_timezone_might_be_too_much/ || RFP || external || timkrief || LibreWolf || timezone || 2025-03-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/1j4wzfm/_/mgfox0a || RFP || external || ThatFeel_IKnowIt || LibreWolf || window-size || 2025-03-07 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/1j519zl/_/mgl2usj || RFP || external || zTubeDogz || LibreWolf || timezone || 2025-03-07 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/syberfab.bsky.social/post/3ljv73o7u5s2h || RFP || external || syberfab.bsky.social || LibreWolf || canvas || 2025-03-08 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2333 || RFP || external || coldmoon || LibreWolf || canvas || 2025-03-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/philc/vimium/issues/4647 || RFP || external || LyndonGingerich || LibreWolf || keyboard || 2025-03-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2338 || RFP || external || fabr_ice || LibreWolf || timezone || 2025-03-13 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2340 || RFP || external || ak42 || LibreWolf || canvas || 2025-03-13 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/1jalrhb/_/mhn6gsu || RFP || external || GrumpyHexagon || LibreWolf || timezone || 2025-03-13 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1j9zwze/figma_canvas_offset_on_librewolf/ || RFP || external || IgorFerreiraMoraes || LibreWolf || window-size || 2025-03-13 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=43362583 || RFP || external || lxn || LibreWolf || timezone || 2025-03-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=43367719 || RFP || external || don-code || LibreWolf || canvas || 2025-03-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1jar789/some_images_not_working_webgl_being_disabled/ || RFP || external || Much_Artist_5097 || LibreWolf || canvas || 2025-03-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=43372553 || RFP || external || voytec || LibreWolf || canvas || 2025-03-15 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/150661#author=Handrail9 || FPP || external || Handrail9 || LibreWolf || window-size || 2025-03-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://mastodon.social/@Methylcobalamin/114189759057750593 || RFP || external || Methylcobalamin || LibreWolf || canvas || 2025-03-19 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1jf0nud/can_you_use_resist_fingerprinting_with_dark_mode/ || RFP || external || krutchieeater466 || LibreWolf || color-scheme || 2025-03-19 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2381 || RFP || external || domo-sapiens || LibreWolf || webgl || 2025-03-24 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1jj6ekt/resist_fingerprinting_default_settings_impact_on/ || RFP || external || RoderickHossack || LibreWolf || canvas || 2025-03-25 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/justneo.xyz/post/3llcgunmgws2u || RFP || external || justneo.xyz || LibreWolf || color-scheme || 2025-03-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2391 || RFP || external || joselp || LibreWolf || timezone || 2025-03-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1josl17/manually_add_canvas_permission/ || RFP || external || Critical-Cockroach47 || LibreWolf || canvas || 2025-04-01 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/callie.on-her.computer/post/3llzkvijwkk2u || RFP || external || callie.on-her.computer || LibreWolf || webgl || 2025-04-04 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2436 || RFP || external || stfbolda || LibreWolf || canvas || 2025-04-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/NeedCoolerShoes/needcoolershoes/issues/9 || RFP || external || G0blinG || LibreWolf || canvas || 2025-05-01 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2454 || RFP || external || Woozy || LibreWolf || canvas || 2025-05-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1kemp53/what_does_resistfingerprinting_do_besides_mess/ || RFP || external || DrPumpkinz || LibreWolf || timezone || 2025-05-04 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/megacultured.bsky.social/post/3lolp3qamzk26 || RFP || external || megacultured.bsky.social || LibreWolf || canvas || 2025-05-07 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2479 || RFP || external || mbehrle || LibreWolf || timezone || 2025-05-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1koy3fs/librewolf_onshape_black_screen_solution/ || RFP || external || Bowen_Baguette || LibreWolf || webgl || 2025-05-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/powerofsin.bsky.social/post/3lqa2xpqk3k2a || RFP || external || powerofsin.bsky.social || LibreWolf || canvas || 2025-05-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/LibreWolf/comments/1kyhf2f/how_to_increase_webgl2_max_texture_size/ || RFP || external || dmcblue || LibreWolf || webgl || 2025-05-29 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1lijllp/spoofed_timezone_exception/ || RFP || external || IaNterlI || LibreWolf || timezone || 2025-06-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2567 || RFP || external || diegosilva || LibreWolf || canvas || 2025-06-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1lpqnnh/solved_keyboard_shortcut_not_working_youtube_speed/ || RFP || external || kriirk_ || LibreWolf || keyboard || 2025-07-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2577 || RFP || external || skal || LibreWolf || canvas || 2025-07-10 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2598 || FPP || external || lucasm || LibreWolf || dpr-blurry || 2025-07-24 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2610 || RFP || external || purvis33 || LibreWolf || color-scheme || 2025-07-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1mo2b38/resist_fingerprinting_breaks_google_meet/ || RFP || external || himynameismiika || LibreWolf || media-webrtc || 2025-08-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2632 || RFP || external || vagab0nd_w0lf || LibreWolf || canvas || 2025-08-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2648 || RFP || external || memecikoliveoil || LibreWolf || canvas || 2025-08-25 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1n3wodr/pdf_images_missing_with_rfp_enabled/ || RFP || external || sskki-exe || LibreWolf || canvas || 2025-08-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/justinaquinogi7b.bsky.social/post/3lxthcuzo522a || RFP || external || justinaquinogi7b.bsky.social || LibreWolf || canvas || 2025-09-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/iyunia.bsky.social/post/3lxxa2vu4l22b || RFP || external || iyunia.bsky.social || LibreWolf || canvas || 2025-09-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1ncpf4y/when_enable_resistfingerprinting_is_selected_pdfs/ || RFP || external || nomad-rc || LibreWolf || canvas || 2025-09-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2667 || RFP || external || f309j092f3j09243g908240g9824g || LibreWolf || extensions || 2025-09-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/neverm0re666.bsky.social/post/3m3d5d622oc2d || RFP || external || neverm0re666.bsky.social || LibreWolf || canvas || 2025-10-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/webcompat/web-bugs/issues/186634#author=matey-0 || RFP || external || matey-0 || LibreWolf || other || 2025-11-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://burgeonlab.com/blog/firefox-fingerprinting-timezone-fix/ || RFP || external || Naty S (BurgeonLab) || LibreWolf || timezone || 2025-11-13 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2720 || RFP || external || Erwan62 || LibreWolf || timezone || 2025-11-20 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2732 || RFP || external || kertlynx || LibreWolf || canvas || 2025-11-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1pgx9gs/issues_with_timezones/#author=Many_Tip_5319 || RFP || external || Many_Tip_5319 || LibreWolf || timezone || 2025-12-07 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1pgx9gs/issues_with_timezones/#author=thqloz || RFP || external || thqloz || LibreWolf || timezone || 2025-12-07 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/htfcuddles.mmfcomic.com/post/3ma6b64iy6s2l || RFP || external || htfcuddles.mmfcomic.com || LibreWolf || canvas || 2025-12-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/superdeluxe.bsky.social/post/3ma5ixhnh7s2w || RFP || external || superdeluxe.bsky.social || LibreWolf || canvas || 2025-12-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/eightarmsedits.bsky.social/post/3maadc7j76k2n || RFP || external || eightarmsedits.bsky.social || LibreWolf || timezone || 2025-12-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2758 || RFP || external || alxndrsn || LibreWolf || webgl || 2025-12-20 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2759#author=tclementdev || RFP || external || tclementdev || LibreWolf || window-size || 2025-12-20 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/toxaquepex.bsky.social/post/3majkdpqxik2f || RFP || external || toxaquepex.bsky.social || LibreWolf || canvas || 2025-12-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://mastodon.derg.nz/@anthropy/115759418099717896 || RFP || external || anthropy@mastodon.derg.nz || LibreWolf || color-scheme || 2025-12-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2766 || RFP || external || BPad || LibreWolf || webgl || 2025-12-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2770 || BOTH || external || ordentio || LibreWolf || fonts || 2025-12-25 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/chardoncs.dev/post/3maudses5622z || RFP || external || chardoncs.dev || LibreWolf || color-scheme || 2025-12-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/zenobius.bsky.social/post/3mb5mfukwes2i || RFP || external || zenobius.bsky.social || LibreWolf || canvas || 2025-12-29 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2778 || RFP || external || SpacemanSpiff || LibreWolf || keyboard || 2026-01-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2779 || RFP || external || tclementdev || LibreWolf || canvas || 2026-01-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/tomchadwin.en.osm.town.ap.brid.gy/post/3mboiahze46i2 || RFP || external || tomchadwin@en.osm.town || LibreWolf || canvas || 2026-01-05 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2781 || RFP || external || iampowerslave || LibreWolf || canvas || 2026-01-05 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1q4z29p/how_to_allow_a_website_to_acces_my_timezone/#author=Zveiner || RFP || external || Zveiner || LibreWolf || timezone || 2026-01-05 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1q4z29p/how_to_allow_a_website_to_acces_my_timezone/#author=_meow11 || RFP || external || _meow11 || LibreWolf || timezone || 2026-01-05 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2785 || RFP || external || Zep_Dep_Rep || LibreWolf || timezone || 2026-01-08 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2786 || RFP || external || Taureon || LibreWolf || canvas || 2026-01-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2819 || RFP || external || SpacemanSpiff || LibreWolf || window-size || 2026-01-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2820 || RFP || external || CDG-c0de || LibreWolf || canvas || 2026-01-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/brynndylow.bsky.social/post/3mdeprrjmdc2i || RFP || external || brynndylow.bsky.social || LibreWolf || canvas || 2026-01-27 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/1qqla5n/privacy_and_privatewindows_separation_settings_block/ || RFP || external || Microeinstein || LibreWolf || perf-timer || 2026-01-29 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2849 || RFP || external || ell1e || LibreWolf || color-scheme || 2026-02-01 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1qtayzj/how_to_fix_claude_ai_freezing_in_librewolf/ || RFP || external || momofantastic || LibreWolf || perf-timer || 2026-02-01 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/accius/openhamclock/issues/48 || RFP || external || ndkohlman || LibreWolf || timezone || 2026-02-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/syncthing/syncthing/issues/10577 || RFP || external || CrazyCatGuy2 || LibreWolf || timezone || 2026-02-15 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/plsechat/pulse-chat/issues/31 || RFP || external || TheDarkPreacher || LibreWolf || timezone || 2026-02-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://mementomori.social/@harald/116136245918453801 || RFP || external || harald@mementomori.social || LibreWolf || canvas || 2026-02-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/localfolf.bsky.social/post/3mfwgu2k36227 || RFP || external || localfolf.bsky.social || LibreWolf || canvas || 2026-02-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2900 || RFP || external || shortwolf || LibreWolf || canvas || 2026-03-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2901 || RFP || external || Max_Supreme || LibreWolf || canvas || 2026-03-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Thyraz/energy-custom-graph/issues/9 || RFP || external || haraldhh || LibreWolf || timezone || 2026-03-04 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2922 || RFP || external || ilovelinux || LibreWolf || color-scheme || 2026-03-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Infinite-Chess/infinitechess.org/issues/1026 || RFP || external || Errorbot1122 || LibreWolf || webgl || 2026-03-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://lemmy.world/comment/22651018 || RFP || external || brillotti@lemmy.world || LibreWolf || canvas || 2026-03-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1rue0xg/this_is_how_to_enable_automatic_fullscreen/ || RFP || external || Thelaststandn || LibreWolf || window-size || 2026-03-15 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1rvnhrt/google_maps_road_number_and_fb_images_are_glitched/#author=PeterHews2022 || RFP || external || PeterHews2022 || LibreWolf || canvas || 2026-03-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1rvnhrt/google_maps_road_number_and_fb_images_are_glitched/#author=lazac69 || RFP || external || lazac69 || LibreWolf || canvas || 2026-03-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2937 || RFP || external || A12345Z67890 || LibreWolf || window-size || 2026-03-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2941 || RFP || external || 91gm2okp || LibreWolf || window-size || 2026-03-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2945 || RFP || external || klausman || LibreWolf || canvas || 2026-03-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1s61hdn/why_does_resistfingerprinting_screw_up_font_support/ || RFP || external || FreshCause2566 || LibreWolf || fonts || 2026-03-28 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2959 || RFP || external || xwx || LibreWolf || other || 2026-04-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/leaf40403.bsky.social/post/3mip336nnac2v || RFP || external || leaf40403.bsky.social || LibreWolf || canvas || 2026-04-04 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/geljado.bsky.social/post/3mixq2y24gs2u || RFP || external || geljado.bsky.social || LibreWolf || canvas || 2026-04-08 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2966#author=leiho-kristal-herdoilduak || BOTH || external || leiho-kristal-herdoilduak || LibreWolf || perf-timer || 2026-04-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/2977 || FPP || external || friendlyanon || LibreWolf || webgl || 2026-04-16 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1so9rky/ai_chatbots_freezing_on_librewolf_fixed/ || RFP || external || Soso12159 || LibreWolf || perf-timer || 2026-04-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1ss8vqg/resistfingerprinting_makes_certain_charts_and/ || RFP || external || Internal-Resist9015 || LibreWolf || canvas || 2026-04-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/derek.glidden.life/post/3mkck6pjqys2r || RFP || external || derek.glidden.life || LibreWolf || canvas || 2026-04-25 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3033 || RFP || external || niehausbert || LibreWolf || media-webrtc || 2026-05-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/e3kskoy7wqk/Firefox-for-windows-7/issues/156 || RFP || external || metapea || LibreWolf || color-scheme || 2026-05-13 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1tklayr/fingerprint_issue/ || RFP || external || ErrorOliver2 || LibreWolf || color-scheme || 2026-05-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3061 || RFP || external || saphta || LibreWolf || timezone || 2026-05-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3072 || RFP || external || ThatCrazy || LibreWolf || timezone || 2026-06-08 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3083 || RFP || external || JoeOsborn || LibreWolf || canvas || 2026-06-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3086 || RFP || external || AfterglowAmpharos || LibreWolf || canvas || 2026-06-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3088 || RFP || external || Chungaa || LibreWolf || window-size || 2026-06-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/openfrontio/OpenFrontIO/issues/4357 || RFP || external || Taureon || LibreWolf || webgl || 2026-06-20 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/ambregris.bsky.social/post/3moxg3iqkl22z || RFP || external || ambregris.bsky.social || LibreWolf || canvas || 2026-06-23 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1udyk2h/cant_disable_timezone_changes/ || RFP || external || IllustratorSafe4704 || LibreWolf || timezone || 2026-06-24 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3107#author=jamiemurphy || RFP || external || jamiemurphy || LibreWolf || other || 2026-06-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://lobste.rs/c/bijgmq || RFP || external || hwj || LibreWolf || webgl || 2026-06-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/loonerlinuxnerd.bsky.social/post/3mpc6xy6rhk2q || RFP || external || loonerlinuxnerd.bsky.social || LibreWolf || canvas || 2026-06-27 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/dzwiedziu.mastodon.social.ap.brid.gy/post/3mpj6qrgrpt72 || RFP || external || dzwiedziu@mastodon.social || LibreWolf || canvas || 2026-06-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3114 || RFP || external || Pander || LibreWolf || canvas || 2026-06-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://codeberg.org/librewolf/issues/issues/3134 || RFP || external || westphalianheretic || LibreWolf || timezone || 2026-07-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/micolithe.us/post/3mqwzplk7ak2r || RFP || external || micolithe.us || LibreWolf || canvas || 2026-07-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/LibreWolf/comments/1v07bnd/cloudflare_error_600010_in_librewolf/#author=waitabittopostagain || RFP || external || waitabittopostagain || LibreWolf || captcha-antibot || 2026-07-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/actualbudget/actual/pull/8706 || RFP || external || StephenBrown2 || LibreWolf || perf-timer || 2026-08-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://librewolf.net/docs/faq/#author=LibreWolfprojectdocs || RFP || internal || LibreWolf (project docs) || LibreWolf || canvas || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://librewolf.net/docs/faq/#author=LibreWolfprojectdocs~2 || RFP || internal || LibreWolf (project docs) || LibreWolf || timezone || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://librewolf.net/docs/faq/#author=LibreWolfprojectdocs~3 || RFP || internal || LibreWolf (project docs) || LibreWolf || color-scheme || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://librewolf.net/docs/faq/#author=LibreWolfprojectdocs~4 || RFP || internal || LibreWolf (project docs) || LibreWolf || window-size || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://librewolf.net/docs/faq/#author=LibreWolfprojectdocs~5 || RFP || internal || LibreWolf (project docs) || LibreWolf || keyboard || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://librewolf.net/docs/faq/#author=LibreWolfprojectdocs~6 || RFP || internal || LibreWolf (project docs) || LibreWolf || webgl || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://librewolf.net/docs/faq/#author=LibreWolfprojectdocs~7 || RFP || internal || LibreWolf (project docs) || LibreWolf || other || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Divested-Mobile/Mull-Fenix/issues/40 || RFP || external || thomas725 || Mull / IronFox (Android) || canvas || 2022-02-27 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/firefox/comments/129iiyr/android_how_to_specify_timezone_utc_with/ || RFP || external || dreieckli || Mull / IronFox (Android) || timezone || 2023-04-02 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/darkreader/darkreader/issues/12268 || RFP || external || tctlrd || Mull / IronFox (Android) || color-scheme || 2024-02-07 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/privacy/comments/1bzfbiq/mull_and_fennec/ || RFP || external || Kantilo || Mull / IronFox (Android) || perf-timer || 2024-04-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/1c95c0q/_/l0jdz8y || RFP || external || Any-Virus5206 || Mull / IronFox (Android) || perf-timer || 2024-04-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/comments/1c95c0q/_/l0jdz8y#darkmode || RFP || external || Any-Virus5206 || Mull / IronFox (Android) || color-scheme || 2024-04-21 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Divested-Mobile/Mull-Fenix/issues/212 || RFP || external || sodinoel || Mull / IronFox (Android) || other || 2024-04-29 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Divested-Mobile/Mull-Fenix/issues/218 || RFP || external || rainfall-1917 || Mull / IronFox (Android) || useragent || 2024-05-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Divested-Mobile/Mull-Fenix/issues/268 || RFP || external || uugaabuugaa || Mull / IronFox (Android) || color-scheme || 2024-11-25 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Divested-Mobile/Mull-Fenix/issues/274 || RFP || external || i-am-mentally-unstable || Mull / IronFox (Android) || canvas || 2024-12-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/ironfox-oss/gitlab-issues/-/issues/215 || RFP || internal || celenity || Mull / IronFox (Android) || other || 2025-01-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/ironfox-oss/gitlab-issues/-/issues/271 || FPP || external || ahd879fh || Mull / IronFox (Android) || fonts || 2025-02-05 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.com/ironfox-oss/gitlab-issues/-/issues/273 || RFP || internal || marcus.herrmann || Mull / IronFox (Android) || other || 2025-02-10 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://ironfoxoss.org/docs/faq/#author=IronFoxprojectdocs || BOTH || internal || IronFox (project docs) || Mull / IronFox (Android) || other || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://ironfoxoss.org/docs/faq/#author=IronFoxprojectdocs~2 || BOTH || internal || IronFox (project docs) || Mull / IronFox (Android) || color-scheme || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://ironfoxoss.org/docs/faq/#author=IronFoxprojectdocs~3 || BOTH || internal || IronFox (project docs) || Mull / IronFox (Android) || fonts || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://ironfoxoss.org/docs/faq/#author=IronFoxprojectdocs~4 || BOTH || internal || IronFox (project docs) || Mull / IronFox (Android) || timezone || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://ironfoxoss.org/docs/faq/#author=IronFoxprojectdocs~5 || BOTH || internal || IronFox (project docs) || Mull / IronFox (Android) || webgl || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://ironfoxoss.org/docs/faq/#author=IronFoxprojectdocs~6 || BOTH || internal || IronFox (project docs) || Mull / IronFox (Android) || locale || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/arkenfox/user.js/issues/1482 || UNCLEAR || external || ghost || Mullvad Browser || captcha-antibot || 2022-06-19 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=35432085 || RFP || external || sundarurfriend || Mullvad Browser || timezone || 2023-04-03 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/16 || RFP || external || CostcoFanboy || Mullvad Browser || perf-timer || 2023-04-04 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=35441645 || RFP || external || notpushkin || Mullvad Browser || canvas || 2023-04-04 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/44 || RFP || external || RTechSn || Mullvad Browser || window-size || 2023-04-07 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/75 || RFP || external || ruihildt || Mullvad Browser || dpr-blurry || 2023-04-18 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/81 || RFP || external || ghost || Mullvad Browser || canvas || 2023-04-24 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/96 || RFP || external || ruihildt || Mullvad Browser || captcha-antibot || 2023-06-13 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/111 || RFP || external || loukad || Mullvad Browser || window-size || 2023-07-02 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/118 || RFP || external || tiararodney || Mullvad Browser || window-size || 2023-07-29 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/124 || RFP || external || asdffdsazqqq || Mullvad Browser || window-size || 2023-08-07 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/152 || RFP || external || alejandro5042 || Mullvad Browser || window-size || 2023-10-01 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/164 || RFP || external || AutonomousCat || Mullvad Browser || captcha-antibot || 2023-10-13 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/164#issuecomment-1761950000 || RFP || external || ave9858 || Mullvad Browser || captcha-antibot || 2023-10-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/202 || RFP || external || akovia || Mullvad Browser || extensions || 2023-12-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/230 || RFP || external || Zepfanman || Mullvad Browser || canvas || 2024-03-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/nilbuild/developer-roadmap/issues/5405 || RFP || external || ruvilonix || Mullvad Browser || canvas || 2024-03-24 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/270 || RFP || external || eiqnepm || Mullvad Browser || window-size || 2024-06-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/355 || RFP || external || proudmuslim-dev || Mullvad Browser || window-size || 2024-11-11 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/358 || RFP || external || Isaac-Piscopo || Mullvad Browser || canvas || 2024-11-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/433 || RFP || external || stano22 || Mullvad Browser || window-size || 2025-03-25 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/512 || RFP || external || Oregano1963 || Mullvad Browser || window-size || 2025-11-15 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/cryptpad/cryptpad/issues/2136 || RFP || external || ghost || Mullvad Browser || other || 2026-01-08 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/533 || RFP || external || antonrosv || Mullvad Browser || window-size || 2026-02-04 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/mullvad/mullvad-browser/issues/538 || RFP || external || Thorin-II || Mullvad Browser || window-size || 2026-02-15 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/mullvadvpn/comments/1rbybmy/starting_mullvad_browser_maximized_howto/ || RFP || external || MadeUpName94 || Mullvad Browser || window-size || 2026-02-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/feedback-on-tor-browser-window-size-issue/21624 || RFP || external || Jack1 || Mullvad Browser || window-size || 2026-05-20 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://mullvad.net/en/help/tag/mullvad-browser#author=Mullvadprojectdocs || RFP || internal || Mullvad (project docs) || Mullvad Browser || window-size || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://mullvad.net/en/help/tag/mullvad-browser#author=Mullvadprojectdocs~2 || RFP || internal || Mullvad (project docs) || Mullvad Browser || dpr-blurry || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://mullvad.net/en/help/tag/mullvad-browser#author=Mullvadprojectdocs~3 || RFP || internal || Mullvad (project docs) || Mullvad Browser || timezone || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://mullvad.net/en/help/tag/mullvad-browser#author=Mullvadprojectdocs~4 || RFP || internal || Mullvad (project docs) || Mullvad Browser || extensions || unknown || collecting agent, unverified ||  || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://tor.stackexchange.com/questions/1822/how-can-i-remove-the-overly-frequent-popup-thats-constantly-warning-me-about-ht || RFP || external || user658182 || Tor Browser || canvas || 2014-03-27 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://tor.stackexchange.com/questions/16051/why-tor-browser-doesnt-recognize-many-emojis || RFP || external || user19736 || Tor Browser || fonts || 2017-11-03 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://reddit.com/r/firefox/comments/7r64e7/could_there_be_any_settings_or_any_command_to/ || RFP || external || ForrestTrump || Tor Browser || canvas || 2018-01-18 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/27290 || RFP || external || gk || Tor Browser || webgl || 2018-08-23 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=19326776 || RFP || external || the_pwner224 || Tor Browser || perf-timer || 2019-03-07 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://forums.whonix.org/t/is-anyone-having-white-bars-in-the-tbb-tor-browser-letterboxing/8345 || RFP || external || 487eyza9hus || Tor Browser || window-size || 2019-10-24 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://x.com/darkdotfail/status/1188970479392116736 || RFP || external || darkdotfail || Tor Browser || window-size || 2019-10-29 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://tor.stackexchange.com/questions/20691/how-can-i-disable-the-grey-border || RFP || external || Retluoc3002 || Tor Browser || window-size || 2019-12-05 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://tor.stackexchange.com/questions/20712/page-doesnt-fill-window-in-tor-browser || RFP || external || ThePiercingPrince || Tor Browser || window-size || 2019-12-18 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://tor.stackexchange.com/questions/21298/cannot-remove-grey-bar-at-bottom-of-tor-browser || RFP || external || Nemgathos || Tor Browser || window-size || 2020-06-07 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://tor.stackexchange.com/questions/21610/view-tor-full-page || RFP || external || c4rm1n3 || Tor Browser || window-size || 2020-10-03 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://old.reddit.com/r/TOR/comments/jxb7j0/#gcw73ls || RFP || external || XeQariX || Tor Browser || canvas || 2020-11-20 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/ocornut/imgui/issues/3644 || RFP || external || DonKult || Tor Browser || perf-timer || 2020-12-07 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/photopea/photopea/issues/2744 || RFP || external || Nightfirecat || Tor Browser || keyboard || 2021-01-12 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/40374 || RFP || external || ilf || Tor Browser || captcha-antibot || 2021-03-12 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/40504 || RFP || external || pseudonymisaTor || Tor Browser || canvas || 2021-07-05 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/40558 || RFP || internal || sysrqb || Tor Browser || canvas || 2021-07-20 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/felixpalmer/peaks-of-austria/issues/1 || RFP || external || kevinoid || Tor Browser || webgl || 2021-10-08 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/letterboxing-on-tor-browser-for-desktop/967 || RFP || external || sketchyshubham || Tor Browser || window-size || 2021-12-01 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/41042 || RFP || external || bentham || Tor Browser || canvas || 2022-07-03 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/41356 || RFP || external || donuts || Tor Browser || window-size || 2022-10-11 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/reversing-default-window-size-and-letterboxing-behavior/9718 || RFP || external || kavavv || Tor Browser || window-size || 2023-10-13 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/TOR/comments/17n2y91/twitterx_profile_avatar_and_header_images_not/ || RFP || external || throwawaythis1hi || Tor Browser || canvas || 2023-11-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://xenforo.com/community/threads/xenforo-2-3-broken-image-uploads-in-firefox-with-privacy-resistfingerprinting-true.224623/#author=OpusX || RFP || external || Opus X || Tor Browser || canvas || 2024 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/TOR/comments/1bn2774/on_uploading_pictures_and_videos_on_twitter/ || RFP || external || Valuable-Elephant507 || Tor Browser || canvas || 2024-03-25 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/42556 || BOTH || external || thorin || Tor Browser || canvas || 2024-05-03 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/tor-browser-incorrect-display-of-datetimes-with-a-timezone/13412 || RFP || external || A. Sanderson (sanderson) || Tor Browser || timezone || 2024-07-02 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/tbb-13-5-how-to-change-letterboxing-color-back-to-old-black-borders-like-in-13-0-16-letterboxing-color-taking-over-webpage-viewport-on-new-tab/13452 || RFP || external || mar || Tor Browser || window-size || 2024-07-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://overgrow.com/t/issues-uploading-with-tor-browser/162132 || RFP || external || allotment || Tor Browser || canvas || 2024-08-30 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/torbrowser/comments/1frvwqv/freebsd_bug_281500_wwwtorbrowser_letterboxing_tiny/ || RFP || external || grahamperrin || Tor Browser || window-size || 2024-09-29 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/no-possibility-to-switch-to-dark-theme-for-websites/15086 || RFP || external || anon68402605 || Tor Browser || color-scheme || 2024-10-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/problem-in-the-images-that-i-download-or-try-to-upload-somewhere/15075 || RFP || external || SRV || Tor Browser || canvas || 2024-10-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/problem-in-the-images-that-i-download-or-try-to-upload-somewhere/15075#vort || RFP || external || Vort || Tor Browser || canvas || 2024-10-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/Divested-Mobile/Mull-Fenix/issues/277 || RFP || external || maria-namia || Tor Browser || canvas || 2024-12-17 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://bsky.app/profile/afa170.bsky.social/post/3lfcujtxiuc2t || RFP || external || afa170.bsky.social || Tor Browser || canvas || 2025-01-09 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/TOR/comments/1ibnn5c/tor_fullscreen_mode/ || RFP || external || Wrecker_IL || Tor Browser || window-size || 2025-01-27 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://news.ycombinator.com/item?id=43023611 || RFP || external || k_sze || Tor Browser || canvas || 2025-02-12 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/why-website-display-stripes/18281 || RFP || external || anon22764326 || Tor Browser || canvas || 2025-04-08 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43672 || RFP || external || cypherpunks || Tor Browser || window-size || 2025-04-22 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://forum.torproject.org/t/letterboxing-wastes-1-3-of-screen-area-on-cinnamon-linux-in-tor-browser/19071 || RFP || external || Swift || Tor Browser || window-size || 2025-05-25 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/waterfox/comments/jobt8e/gmailtimezone_setting_related_to_aboutconfigprefsjs_in_classic/ || RFP || external || Avrution || Waterfox || timezone || 2020-11-05 || collecting agent, unverified || pre-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/zen-browser/desktop/issues/925 || RFP || external || KPCOFGS || Zen Browser || window-size || 2024-08-26 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://www.reddit.com/r/zen_browser/comments/1is87b8/what_is_this_and_how_do_i_fix_it/ || RFP || external || abbbbbcccccddddd || Zen Browser || canvas || 2025-02-18 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/zen-browser/desktop/issues/6974 || RFP || external || unkn0wncode || Zen Browser || window-size || 2025-03-29 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/zen-browser/desktop/issues/7307 || RFP || external || doctorsangria || Zen Browser || window-size || 2025-04-04 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/zen-browser/desktop/issues/7380 || RFP || external || hankertrix || Zen Browser || window-size || 2025-04-06 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 5 || style=&amp;quot;text-align:right;&amp;quot; | 3 || style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|-&lt;br /&gt;
| https://github.com/zen-browser/desktop/issues/9458 || BOTH || external || kennylee60 || Zen Browser || fonts || 2025-07-14 || collecting agent, unverified || post-FPP || style=&amp;quot;text-align:right;&amp;quot; | 4 || style=&amp;quot;text-align:right;&amp;quot; | 2 || style=&amp;quot;text-align:right;&amp;quot; | 2&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1257702</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1257702"/>
		<updated>2026-06-24T13:52:26Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Mitigating Circumstances */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited (either in Firefox, or another browser)&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that allows arbitrary attacker controlled HTML, that a user can interact with, with an attacker-controlled URL in the actual address bar retaining normal badging and iconography&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Techniques that cause a JavaScript alert or similar browser modal to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
=== Mitigating Circumstances ===&lt;br /&gt;
&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one or more levels of severity.  &lt;br /&gt;
&lt;br /&gt;
- Any bug that requires DevTools to have been opened by the user is capped at a sec-moderate&lt;br /&gt;
- As mentioned above, Memory Safety issues caused by OOM conditions, unless precise triggering of the condition can be shown, are capped at sec-moderate&lt;br /&gt;
- Similarly unreliable race conditions that crash the browser are also capped at sec-moderate; if the attacker can retry it will not be reduced&lt;br /&gt;
- Requiring complex or unusual set of actions the user would have to take beyond normal browsing behaviors&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-clickjacking || client security issues due to techniques that cause a user to unintentionally click or tap on a browser control, either by obscuring the true target of the click or by causing the target to appear by surprise in place of the item the user intended to click or tap&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || client issues that cause disclosure of sensitive user data or personal information (see also csectype-side-channel and csectype-sop)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || client Denial of Service issues (use wsec-dos for web server denial of service as these tend to be more severe)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client crashes caused by dereferencing a poisoned (deleted) nsIFrame object (presumed to be limited to a Denial of Service)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-mitigation-bypass || client security issues that allow malicious content to evade protections provided by web security features like CSP and &amp;lt;iframe sandbox&amp;gt;, or user-abuse protections like the popup blocker&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client crashes due to a guaranteed null dereference (do not use for near-null crashes with a content-controlled offset)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || client crashes or hangs that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || privilege escalation either from a lower OS account to root, or from a process to a different, non-parent process&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issues due to a race condition&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || client security issues where a low-privilege process can cause memory corruption or arbitrary code execution in a higher-privilege processs (for example, through malformed IPC messages or Shared Memory)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-side-channel || Disclosure of sensitive information or state through side-effects (typically, timing)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-site-isolation || client security issues in limiting content processes to data and settings for a single site. distinct from web content csectype-sop and non-site-to-site csectype-priv-escalation&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy including Universal-XSS (see also csectype-side-channel for less severe &amp;quot;leaks&amp;quot;)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issues due to UI Redress attacks or manipulation of the browser UI to fool users into taking the wrong action (excluding csectype-clickjacking issues)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || client security issues—or potential issues—due to undefined compiler behavior&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Issues not considered security bugs ==&lt;br /&gt;
&lt;br /&gt;
* Unexploitable bugs that crash only a content process&lt;br /&gt;
* Command injection in Devtools &#039;Copy as XXX&#039; commands, where the command is not native to the OS in question&lt;br /&gt;
* Attacks that assume physical access to the computer.  While certain features of the browser (such as primary password) can mitigate this attack vector, these should not be considered security boundaries. Bypasses of them are considered for improvement on a case-by-case basis and typically are not considered security bugs.  &lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1257691</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1257691"/>
		<updated>2026-06-23T18:02:28Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited (either in Firefox, or another browser)&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that allows arbitrary attacker controlled HTML, that a user can interact with, with an attacker-controlled URL in the actual address bar retaining normal badging and iconography&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Techniques that cause a JavaScript alert or similar browser modal to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
=== Mitigating Circumstances ===&lt;br /&gt;
&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one or more levels of severity.  &lt;br /&gt;
&lt;br /&gt;
 - Any bug that requires a user to have an accessibility client installed or using assistive technology is capped at a sec-moderate&lt;br /&gt;
 - Any bug that requires DevTools to have been opened by the user is capped at a sec-moderate&lt;br /&gt;
 - As mentioned above, Memory Safety issues caused by OOM conditions, unless precise triggering of the condition can be shown, are capped at sec-moderate&lt;br /&gt;
 - Similarly unreliable race conditions that crash the browser are also capped at sec-moderate; if the attacker can retry it will not be reduced&lt;br /&gt;
 - Requiring complex or unusual set of actions the user would have to take beyond normal browsing behaviors&lt;br /&gt;
 - Unusual software configuration not provided by our Preferences page&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-clickjacking || client security issues due to techniques that cause a user to unintentionally click or tap on a browser control, either by obscuring the true target of the click or by causing the target to appear by surprise in place of the item the user intended to click or tap&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || client issues that cause disclosure of sensitive user data or personal information (see also csectype-side-channel and csectype-sop)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || client Denial of Service issues (use wsec-dos for web server denial of service as these tend to be more severe)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client crashes caused by dereferencing a poisoned (deleted) nsIFrame object (presumed to be limited to a Denial of Service)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-mitigation-bypass || client security issues that allow malicious content to evade protections provided by web security features like CSP and &amp;lt;iframe sandbox&amp;gt;, or user-abuse protections like the popup blocker&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client crashes due to a guaranteed null dereference (do not use for near-null crashes with a content-controlled offset)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || client crashes or hangs that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || privilege escalation either from a lower OS account to root, or from a process to a different, non-parent process&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issues due to a race condition&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || client security issues where a low-privilege process can cause memory corruption or arbitrary code execution in a higher-privilege processs (for example, through malformed IPC messages or Shared Memory)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-side-channel || Disclosure of sensitive information or state through side-effects (typically, timing)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-site-isolation || client security issues in limiting content processes to data and settings for a single site. distinct from web content csectype-sop and non-site-to-site csectype-priv-escalation&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy including Universal-XSS (see also csectype-side-channel for less severe &amp;quot;leaks&amp;quot;)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issues due to UI Redress attacks or manipulation of the browser UI to fool users into taking the wrong action (excluding csectype-clickjacking issues)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || client security issues—or potential issues—due to undefined compiler behavior&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Issues not considered security bugs ==&lt;br /&gt;
&lt;br /&gt;
* Unexploitable bugs that crash only a content process&lt;br /&gt;
* Command injection in Devtools &#039;Copy as XXX&#039; commands, where the command is not native to the OS in question&lt;br /&gt;
* Attacks that assume physical access to the computer.  While certain features of the browser (such as primary password) can mitigate this attack vector, these should not be considered security boundaries. Bypasses of them are considered for improvement on a case-by-case basis and typically are not considered security bugs.  &lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1257630</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1257630"/>
		<updated>2026-06-18T18:17:23Z</updated>

		<summary type="html">&lt;p&gt;Tritter: clarify sandbox-escape&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited (either in Firefox, or another browser)&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that allows arbitrary attacker controlled HTML, that a user can interact with, with an attacker-controlled URL in the actual address bar retaining normal badging and iconography&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Techniques that cause a JavaScript alert or similar browser modal to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-clickjacking || client security issues due to techniques that cause a user to unintentionally click or tap on a browser control, either by obscuring the true target of the click or by causing the target to appear by surprise in place of the item the user intended to click or tap&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || client issues that cause disclosure of sensitive user data or personal information (see also csectype-side-channel and csectype-sop)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || client Denial of Service issues (use wsec-dos for web server denial of service as these tend to be more severe)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client crashes caused by dereferencing a poisoned (deleted) nsIFrame object (presumed to be limited to a Denial of Service)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-mitigation-bypass || client security issues that allow malicious content to evade protections provided by web security features like CSP and &amp;lt;iframe sandbox&amp;gt;, or user-abuse protections like the popup blocker&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client crashes due to a guaranteed null dereference (do not use for near-null crashes with a content-controlled offset)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || client crashes or hangs that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || privilege escalation either from a lower OS account to root, or from a process to a different, non-parent process&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issues due to a race condition&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || client security issues where a low-privilege process can cause memory corruption or arbitrary code execution in a higher-privilege processs (for example, through malformed IPC messages or Shared Memory)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-side-channel || Disclosure of sensitive information or state through side-effects (typically, timing)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-site-isolation || client security issues in limiting content processes to data and settings for a single site. distinct from web content csectype-sop and non-site-to-site csectype-priv-escalation&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy including Universal-XSS (see also csectype-side-channel for less severe &amp;quot;leaks&amp;quot;)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issues due to UI Redress attacks or manipulation of the browser UI to fool users into taking the wrong action (excluding csectype-clickjacking issues)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || client security issues—or potential issues—due to undefined compiler behavior&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Issues not considered security bugs ==&lt;br /&gt;
&lt;br /&gt;
* Unexploitable bugs that crash only a content process&lt;br /&gt;
* Command injection in Devtools &#039;Copy as XXX&#039; commands, where the command is not native to the OS in question&lt;br /&gt;
* Attacks that assume physical access to the computer.  While certain features of the browser (such as primary password) can mitigate this attack vector, these should not be considered security boundaries. Bypasses of them are considered for improvement on a case-by-case basis and typically are not considered security bugs.  &lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1257577</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1257577"/>
		<updated>2026-06-12T14:18:32Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited (either in Firefox, or another browser)&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that allows arbitrary attacker controlled HTML, that a user can interact with, with an attacker-controlled URL in the actual address bar retaining normal badging and iconography&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Techniques that cause a JavaScript alert or similar browser modal to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-clickjacking || client security issues due to techniques that cause a user to unintentionally click or tap on a browser control, either by obscuring the true target of the click or by causing the target to appear by surprise in place of the item the user intended to click or tap&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || client issues that cause disclosure of sensitive user data or personal information (see also csectype-side-channel and csectype-sop)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || client Denial of Service issues (use wsec-dos for web server denial of service as these tend to be more severe)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client crashes caused by dereferencing a poisoned (deleted) nsIFrame object (presumed to be limited to a Denial of Service)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-mitigation-bypass || client security issues that allow malicious content to evade protections provided by web security features like CSP and &amp;lt;iframe sandbox&amp;gt;, or user-abuse protections like the popup blocker&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client crashes due to a guaranteed null dereference (do not use for near-null crashes with a content-controlled offset)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || client crashes or hangs that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issues due to a race condition&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || client security issues where a low-privilege process can cause memory corruption or arbitrary code execution in a higher-privilege processs (for example, through malformed IPC messages or Shared Memory)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-side-channel || Disclosure of sensitive information or state through side-effects (typically, timing)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-site-isolation || client security issues in limiting content processes to data and settings for a single site. distinct from web content csectype-sop and non-site-to-site csectype-priv-escalation&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy including Universal-XSS (see also csectype-side-channel for less severe &amp;quot;leaks&amp;quot;)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issues due to UI Redress attacks or manipulation of the browser UI to fool users into taking the wrong action (excluding csectype-clickjacking issues)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || client security issues—or potential issues—due to undefined compiler behavior&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Issues not considered security bugs ==&lt;br /&gt;
&lt;br /&gt;
* Unexploitable bugs that crash only a content process&lt;br /&gt;
* Command injection in Devtools &#039;Copy as XXX&#039; commands, where the command is not native to the OS in question&lt;br /&gt;
* Attacks that assume physical access to the computer.  While certain features of the browser (such as primary password) can mitigate this attack vector, these should not be considered security boundaries. Bypasses of them are considered for improvement on a case-by-case basis and typically are not considered security bugs.  &lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257347</id>
		<title>Fingerprinting</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257347"/>
		<updated>2026-05-12T18:25:54Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page tracks the deployment of Firefox&#039;s Fingerprinting Protection (FPP) feature.&lt;br /&gt;
&lt;br /&gt;
Other documents that may be relevant depending on the audience:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page more appropriate for end-users of Firefox https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page for end users who might have (accidently or not) enabled Resist Fingerprinting https://support.mozilla.org/en-US/kb/resist-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; Firefox&#039;s Fingerprinting Protection Architecture in Gory Detail https://docs.google.com/document/d/1FywogzvkWupoUoz4PcCp9nNd6aKOwBN-c2zRu2Xof9Y/edit?tab=t.0&lt;br /&gt;
&amp;lt;li&amp;gt; Source Docs on the implementation: https://firefox-source-docs.mozilla.org/toolkit/components/resistfingerprinting/resistfingerprinting/implementation.html&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&#039;&#039;As of Firefox 151 Release, last updated 5/12/26, the following protections are enabled:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection !! Desktop FPP !! Android FPP !! Desktop Baseline !! Android Baseline&lt;br /&gt;
|-&lt;br /&gt;
| CanvasRandomization || Yes || Yes || Yes || Nightly-only&lt;br /&gt;
|-&lt;br /&gt;
| EfficientCanvasRandomization || Yes || Yes || Yes || Nightly-only&lt;br /&gt;
|-&lt;br /&gt;
| FontVisibilityLangPack || Yes || Yes || ||&lt;br /&gt;
|-&lt;br /&gt;
| JSMathFdlibm || Yes || Yes || ||&lt;br /&gt;
|-&lt;br /&gt;
| MaxTouchPointsCollapse || Yes || Yes || Yes || Nightly-only&lt;br /&gt;
|-&lt;br /&gt;
| NavigatorHWConcurrencyTiered || Yes || Yes || ||&lt;br /&gt;
|-&lt;br /&gt;
| ScreenAvailToResolution || Yes || Yes || Yes || Nightly-only&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Desktop ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;8&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Release as of 151&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Release&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Beta&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2016747}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;8&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Release as of 151&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Release&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Beta&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1991701}} (Linux touch disabled by companion fix {{bug|1957658}}, re-enabled in 146/147); {{bug|2021715}} (Linux Wayland count adjusted, 150)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;8&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145; Enabled in Baseline Release as of 151&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Release&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Beta&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2025570}} (Google Maps highway labels broken, fixed via RemoteSettings in 150/151)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;8&amp;quot; | CanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 120; Enabled in Baseline Release as of 151&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Release&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Beta&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 115&lt;br /&gt;
| {{bug|1825250}} (Nightly-only in 118–119 due to {{bug|1849903}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1852541}} (Google Meet can&#039;t join, fixed 120); {{bug|1876149}} (onshape.com getImageData); {{bug|1882761}} (Google Maps highway symbols); {{bug|1887161}} (canvas getImageData slow in PBM on maps/Airbnb, fixed via SipHash in 134 then superseded by EfficientCanvasRandomization); {{bug|1905884}} (visual bugs on canvas-heavy sites); {{bug|1957426}} (meta); {{bug|1957427}} (wpt.fyi image comparison, fixed via overrides); {{bug|2010274}} (SoundCloud audio waveform broken in PBM/ETP Strict); {{bug|2025570}} (Google Maps Baseline, shared with EfficientCanvasRandomization)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | FontVisibilityLangPack&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 118&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1827475}} (meta); {{bug|1850672}} (localized font names not in standard list, fixed 118.0.2/119); {{bug|1854950}} (broken rendering on Linux with no native distro fonts, fixed 119/120)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | JSMathFdlibm&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | NavigatorHWConcurrencyTiered&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}} (renamed and tiered in 144 via {{bug|1984333}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1984132}}; {{bug|1982336}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Android ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 151&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 151&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145; Enabled in Baseline Nightly-only as of 151&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | CanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 120; Enabled in Baseline Nightly-only as of 151&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 151&lt;br /&gt;
| {{bug|2032123}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 115&lt;br /&gt;
| {{bug|1825250}} (Nightly-only in 118–119 due to {{bug|1849903}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1852541}} (Google Meet can&#039;t join, fixed 120); {{bug|1876149}} (onshape.com getImageData); {{bug|1882761}} (Google Maps highway symbols); {{bug|1887161}} (canvas getImageData slow in PBM, fixed via SipHash in 134 then superseded by EfficientCanvasRandomization); {{bug|1905884}} (visual bugs on canvas-heavy sites); {{bug|1957426}} (meta); {{bug|1957427}} (wpt.fyi image comparison, fixed via overrides)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | FontVisibilityLangPack&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134 (removed 124–133 via {{bug|1826412}}, re-enabled via {{bug|1928705}})&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1928705}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1928705}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}} (removed in 124 via {{bug|1826412}}, re-added in 134 via {{bug|1928705}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1946625}} (Brahmic scripts broken on older Samsung Android); {{bug|1956251}} (cxcricket.co Bangla Sangam MN font missing from Android font list)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | JSMathFdlibm&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | NavigatorHWConcurrencyTiered&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}} (renamed and tiered in 144 via {{bug|1984333}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1984132}}; {{bug|1982336}}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257013</id>
		<title>Fingerprinting</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257013"/>
		<updated>2026-04-15T18:31:14Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page tracks the deployment of Firefox&#039;s Fingerprinting Protection (FPP) feature.  &lt;br /&gt;
&lt;br /&gt;
Other documents that may be relevant depending on the audience:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page more appropriate for end-users of Firefox https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page for end users who might have (accidently or not) enabled Resist Fingerprinting https://support.mozilla.org/en-US/kb/resist-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; Firefox&#039;s Fingerprinting Protection Architecture in Gory Detail https://docs.google.com/document/d/1FywogzvkWupoUoz4PcCp9nNd6aKOwBN-c2zRu2Xof9Y/edit?tab=t.0&lt;br /&gt;
&amp;lt;li&amp;gt; Source Docs on the implementation: https://firefox-source-docs.mozilla.org/toolkit/components/resistfingerprinting/resistfingerprinting/implementation.html&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&#039;&#039;As of Firefox 150 Release, last updated 4/15/26, the following protections are enabled:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection !! Desktop FPP !! Android FPP !! Desktop Baseline !! Android Baseline&lt;br /&gt;
|-&lt;br /&gt;
| CanvasRandomization || Yes || Yes || Nightly-only ||&lt;br /&gt;
|-&lt;br /&gt;
| EfficientCanvasRandomization || Yes || Yes || Nightly-only ||&lt;br /&gt;
|-&lt;br /&gt;
| FontVisibilityLangPack || Yes || Yes || ||&lt;br /&gt;
|-&lt;br /&gt;
| JSMathFdlibm || Yes || Yes || ||&lt;br /&gt;
|-&lt;br /&gt;
| MaxTouchPointsCollapse || Yes || Yes || Nightly-only ||&lt;br /&gt;
|-&lt;br /&gt;
| NavigatorHWConcurrencyTiered || Yes || Yes || ||&lt;br /&gt;
|-&lt;br /&gt;
| ScreenAvailToResolution || Yes || Yes || Nightly-only ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Desktop ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2016747}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1991701}} (Linux touch disabled by companion fix {{bug|1957658}}, re-enabled in 146/147); {{bug|2021715}} (Linux Wayland count adjusted, 150)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2025570}} (Google Maps highway labels broken, fixed via RemoteSettings in 150/151)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | CanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 120; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 115&lt;br /&gt;
| {{bug|1825250}} (Nightly-only in 118–119 due to {{bug|1849903}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1852541}} (Google Meet can&#039;t join, fixed 120); {{bug|1876149}} (onshape.com getImageData); {{bug|1882761}} (Google Maps highway symbols); {{bug|1887161}} (canvas getImageData slow in PBM on maps/Airbnb, fixed via SipHash in 134 then superseded by EfficientCanvasRandomization); {{bug|1905884}} (visual bugs on canvas-heavy sites); {{bug|1957426}} (meta); {{bug|1957427}} (wpt.fyi image comparison, fixed via overrides); {{bug|2010274}} (SoundCloud audio waveform broken in PBM/ETP Strict); {{bug|2025570}} (Google Maps Baseline, shared with EfficientCanvasRandomization)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | FontVisibilityLangPack&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 118&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1827475}} (meta); {{bug|1850672}} (localized font names not in standard list, fixed 118.0.2/119); {{bug|1854950}} (broken rendering on Linux with no native distro fonts, fixed 119/120)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | JSMathFdlibm&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | NavigatorHWConcurrencyTiered&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}} (renamed and tiered in 144 via {{bug|1984333}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1984132}}; {{bug|1982336}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Android ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | CanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 120&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 115&lt;br /&gt;
| {{bug|1825250}} (Nightly-only in 118–119 due to {{bug|1849903}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1852541}} (Google Meet can&#039;t join, fixed 120); {{bug|1876149}} (onshape.com getImageData); {{bug|1882761}} (Google Maps highway symbols); {{bug|1887161}} (canvas getImageData slow in PBM, fixed via SipHash in 134 then superseded by EfficientCanvasRandomization); {{bug|1905884}} (visual bugs on canvas-heavy sites); {{bug|1957426}} (meta); {{bug|1957427}} (wpt.fyi image comparison, fixed via overrides)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | FontVisibilityLangPack&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134 (removed 124–133 via {{bug|1826412}}, re-enabled via {{bug|1928705}})&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1928705}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1928705}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}} (removed in 124 via {{bug|1826412}}, re-added in 134 via {{bug|1928705}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1946625}} (Brahmic scripts broken on older Samsung Android); {{bug|1956251}} (cxcricket.co Bangla Sangam MN font missing from Android font list)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | JSMathFdlibm&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | NavigatorHWConcurrencyTiered&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}} (renamed and tiered in 144 via {{bug|1984333}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1984132}}; {{bug|1982336}}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257012</id>
		<title>Fingerprinting</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257012"/>
		<updated>2026-04-15T18:25:54Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page tracks the deployment of Firefox&#039;s Fingerprinting Protection (FPP) feature.  &lt;br /&gt;
&lt;br /&gt;
Other documents that may be relevant depending on the audience:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page more appropriate for end-users of Firefox https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page for end users who might have (accidently or not) enabled Resist Fingerprinting https://support.mozilla.org/en-US/kb/resist-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; Firefox&#039;s Fingerprinting Protection Architecture in Gory Detail https://docs.google.com/document/d/1FywogzvkWupoUoz4PcCp9nNd6aKOwBN-c2zRu2Xof9Y/edit?tab=t.0&lt;br /&gt;
&amp;lt;li&amp;gt; Source Docs on the implementation: https://firefox-source-docs.mozilla.org/toolkit/components/resistfingerprinting/resistfingerprinting/implementation.html&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Desktop ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2016747}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1991701}} (Linux touch disabled by companion fix {{bug|1957658}}, re-enabled in 146/147); {{bug|2021715}} (Linux Wayland count adjusted, 150)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2025570}} (Google Maps highway labels broken, fixed via RemoteSettings in 150/151)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | CanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 120; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 115&lt;br /&gt;
| {{bug|1825250}} (Nightly-only in 118–119 due to {{bug|1849903}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1852541}} (Google Meet can&#039;t join, fixed 120); {{bug|1876149}} (onshape.com getImageData); {{bug|1882761}} (Google Maps highway symbols); {{bug|1887161}} (canvas getImageData slow in PBM on maps/Airbnb, fixed via SipHash in 134 then superseded by EfficientCanvasRandomization); {{bug|1905884}} (visual bugs on canvas-heavy sites); {{bug|1957426}} (meta); {{bug|1957427}} (wpt.fyi image comparison, fixed via overrides); {{bug|2010274}} (SoundCloud audio waveform broken in PBM/ETP Strict); {{bug|2025570}} (Google Maps Baseline, shared with EfficientCanvasRandomization)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | FontVisibilityLangPack&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 118&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1827475}} (meta); {{bug|1850672}} (localized font names not in standard list, fixed 118.0.2/119); {{bug|1854950}} (broken rendering on Linux with no native distro fonts, fixed 119/120)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | JSMathFdlibm&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | NavigatorHWConcurrencyTiered&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}} (renamed and tiered in 144 via {{bug|1984333}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1984132}}; {{bug|1982336}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Android ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | CanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 120&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 115&lt;br /&gt;
| {{bug|1825250}} (Nightly-only in 118–119 due to {{bug|1849903}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1852541}} (Google Meet can&#039;t join, fixed 120); {{bug|1876149}} (onshape.com getImageData); {{bug|1882761}} (Google Maps highway symbols); {{bug|1887161}} (canvas getImageData slow in PBM, fixed via SipHash in 134 then superseded by EfficientCanvasRandomization); {{bug|1905884}} (visual bugs on canvas-heavy sites); {{bug|1957426}} (meta); {{bug|1957427}} (wpt.fyi image comparison, fixed via overrides)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | FontVisibilityLangPack&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134 (removed 124–133 via {{bug|1826412}}, re-enabled via {{bug|1928705}})&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1928705}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1928705}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 118&lt;br /&gt;
| {{bug|1849903}} (removed in 124 via {{bug|1826412}}, re-added in 134 via {{bug|1928705}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1946625}} (Brahmic scripts broken on older Samsung Android); {{bug|1956251}} (cxcricket.co Bangla Sangam MN font missing from Android font list)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | JSMathFdlibm&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 134&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 134&lt;br /&gt;
| {{bug|1887682}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | NavigatorHWConcurrencyTiered&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}} (renamed and tiered in 144 via {{bug|1984333}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1984132}}; {{bug|1982336}}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257011</id>
		<title>Fingerprinting</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257011"/>
		<updated>2026-04-15T18:08:43Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page tracks the deployment of Firefox&#039;s Fingerprinting Protection (FPP) feature.  &lt;br /&gt;
&lt;br /&gt;
Other documents that may be relevant depending on the audience:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page more appropriate for end-users of Firefox https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page for end users who might have (accidently or not) enabled Resist Fingerprinting https://support.mozilla.org/en-US/kb/resist-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; Firefox&#039;s Fingerprinting Protection Architecture in Gory Detail https://docs.google.com/document/d/1FywogzvkWupoUoz4PcCp9nNd6aKOwBN-c2zRu2Xof9Y/edit?tab=t.0&lt;br /&gt;
&amp;lt;li&amp;gt; Source Docs on the implementation: https://firefox-source-docs.mozilla.org/toolkit/components/resistfingerprinting/resistfingerprinting/implementation.html&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Desktop ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2016747}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1991701}} (Linux touch disabled by companion fix {{bug|1957658}}, re-enabled in 146/147); {{bug|2021715}} (Linux Wayland count adjusted, 150)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2025570}} (Google Maps highway labels broken, fixed via RemoteSettings in 150/151)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | CanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 120; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 115&lt;br /&gt;
| {{bug|1825250}} (Nightly-only in 118–119 due to {{bug|1849903}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1887161}} (canvas getImageData slow in PBM on maps/Airbnb, fixed via SipHash in 134 then superseded by EfficientCanvasRandomization); {{bug|2025570}} (Google Maps Baseline, shared with EfficientCanvasRandomization)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Android ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;5&amp;quot; | CanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 120&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 120&lt;br /&gt;
| {{bug|1858181}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 115&lt;br /&gt;
| {{bug|1825250}} (Nightly-only in 118–119 due to {{bug|1849903}})&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1887161}}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257010</id>
		<title>Fingerprinting</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257010"/>
		<updated>2026-04-15T17:58:16Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page tracks the deployment of Firefox&#039;s Fingerprinting Protection (FPP) feature.  &lt;br /&gt;
&lt;br /&gt;
Other documents that may be relevant depending on the audience:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page more appropriate for end-users of Firefox https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page for end users who might have (accidently or not) enabled Resist Fingerprinting https://support.mozilla.org/en-US/kb/resist-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; Firefox&#039;s Fingerprinting Protection Architecture in Gory Detail https://docs.google.com/document/d/1FywogzvkWupoUoz4PcCp9nNd6aKOwBN-c2zRu2Xof9Y/edit?tab=t.0&lt;br /&gt;
&amp;lt;li&amp;gt; Source Docs on the implementation: https://firefox-source-docs.mozilla.org/toolkit/components/resistfingerprinting/resistfingerprinting/implementation.html&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Desktop ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2016747}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|1990514}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|1991701}} (Linux touch disabled by companion fix {{bug|1957658}}, re-enabled in 146/147); {{bug|2021715}} (Linux Wayland count adjusted, 150)&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;6&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Baseline Nightly&lt;br /&gt;
| 150&lt;br /&gt;
| {{bug|2021606}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2025570}} (Google Maps highway labels broken, fixed via RemoteSettings in 150/151)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Android ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | MaxTouchPointsCollapse&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 143&lt;br /&gt;
| {{bug|1978414}}&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | EfficientCanvasRandomization&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 145&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Release&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Beta&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|-&lt;br /&gt;
| FPP (PBM) Nightly&lt;br /&gt;
| 145&lt;br /&gt;
| {{bug|1993304}}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257009</id>
		<title>Fingerprinting</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Fingerprinting&amp;diff=1257009"/>
		<updated>2026-04-15T17:08:25Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page tracks the deployment of Firefox&#039;s Fingerprinting Protection (FPP) feature.  &lt;br /&gt;
&lt;br /&gt;
Other documents that may be relevant depending on the audience:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page more appropriate for end-users of Firefox https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; SUMO page for end users who might have (accidently or not) enabled Resist Fingerprinting https://support.mozilla.org/en-US/kb/resist-fingerprinting&lt;br /&gt;
&amp;lt;li&amp;gt; Firefox&#039;s Fingerprinting Protection Architecture in Gory Detail https://docs.google.com/document/d/1FywogzvkWupoUoz4PcCp9nNd6aKOwBN-c2zRu2Xof9Y/edit?tab=t.0&lt;br /&gt;
&amp;lt;li&amp;gt; Source Docs on the implementation: https://firefox-source-docs.mozilla.org/toolkit/components/resistfingerprinting/resistfingerprinting/implementation.html&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Desktop ==&lt;br /&gt;
&lt;br /&gt;
  {| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
  |-&lt;br /&gt;
  ! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
  |-                                                                                                                                                                                          &lt;br /&gt;
  | rowspan=&amp;quot;6&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
  | colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143; Enabled in Baseline Nightly-only as of 150&#039;&#039;&#039;                                                                                    &lt;br /&gt;
  |-                                                              &lt;br /&gt;
  | Baseline Nightly&lt;br /&gt;
  | 150                                                                                                                                                                                       &lt;br /&gt;
  | {{bug|1990514}}&lt;br /&gt;
  |-                                                                                                                                                                                          &lt;br /&gt;
  | FPP (PBM) Release                                             &lt;br /&gt;
  | 143&lt;br /&gt;
  | {{bug|1978414}}&lt;br /&gt;
  |-&lt;br /&gt;
  | FPP (PBM) Beta&lt;br /&gt;
  | 143                                                                                                                                                                                       &lt;br /&gt;
  | {{bug|1978414}}&lt;br /&gt;
  |-                                                                                                                                                                                          &lt;br /&gt;
  | FPP (PBM) Nightly                                             &lt;br /&gt;
  | 143&lt;br /&gt;
  | {{bug|1978414}}&lt;br /&gt;
  |-&lt;br /&gt;
  | colspan=&amp;quot;3&amp;quot; | Regressions: {{bug|2016747}}&lt;br /&gt;
  |}                                                                                                                                                                                          &lt;br /&gt;
  &lt;br /&gt;
== Android ==                                                                                                                                                                               &lt;br /&gt;
                                                                  &lt;br /&gt;
  {| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
  |-&lt;br /&gt;
  ! Protection Name !! Channel !! Version !! Bugs&lt;br /&gt;
  |-&lt;br /&gt;
  | rowspan=&amp;quot;4&amp;quot; | ScreenAvailToResolution&lt;br /&gt;
  | colspan=&amp;quot;3&amp;quot; | &#039;&#039;&#039;Enabled in FPP (PBM) Release as of 143&#039;&#039;&#039;&lt;br /&gt;
  |-                                                                                                                                                                                          &lt;br /&gt;
  | FPP (PBM) Release&lt;br /&gt;
  | 143                                                                                                                                                                                       &lt;br /&gt;
  | {{bug|1978414}}                                               &lt;br /&gt;
  |-&lt;br /&gt;
  | FPP (PBM) Beta&lt;br /&gt;
  | 143                                                                                                                                                                                       &lt;br /&gt;
  | {{bug|1978414}}&lt;br /&gt;
  |-                                                                                                                                                                                          &lt;br /&gt;
  | FPP (PBM) Nightly                                             &lt;br /&gt;
  | 143&lt;br /&gt;
  | {{bug|1978414}}&lt;br /&gt;
  |}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1256869</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1256869"/>
		<updated>2026-03-31T12:52:57Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Issues not considered security bugs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that allows arbitrary attacker controlled HTML, that a user can interact with, with an attacker-controlled URL in the actual address bar retaining normal badging and iconography&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Techniques that cause a JavaScript alert or similar browser modal to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-clickjacking || client security issues due to techniques that cause a user to unintentionally click or tap on a browser control, either by obscuring the true target of the click or by causing the target to appear by surprise in place of the item the user intended to click or tap&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || client issues that cause disclosure of sensitive user data or personal information (see also csectype-side-channel and csectype-sop)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || client Denial of Service issues (use wsec-dos for web server denial of service as these tend to be more severe)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client crashes caused by dereferencing a poisoned (deleted) nsIFrame object (presumed to be limited to a Denial of Service)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-mitigation-bypass || client security issues that allow malicious content to evade protections provided by web security features like CSP and &amp;lt;iframe sandbox&amp;gt;, or user-abuse protections like the popup blocker&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client crashes due to a guaranteed null dereference (do not use for near-null crashes with a content-controlled offset)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || client crashes or hangs that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issues due to a race condition&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || client security issues where a low-privilege process can cause memory corruption or arbitrary code execution in a higher-privilege processs (for example, through malformed IPC messages or Shared Memory)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-side-channel || Disclosure of sensitive information or state through side-effects (typically, timing)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy including Universal-XSS (see also csectype-side-channel for less severe &amp;quot;leaks&amp;quot;)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issues due to UI Redress attacks or manipulation of the browser UI to fool users into taking the wrong action (excluding csectype-clickjacking issues)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || client security issues—or potential issues—due to undefined compiler behavior&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Issues not considered security bugs ==&lt;br /&gt;
&lt;br /&gt;
* Unexploitable bugs that crash only a content process&lt;br /&gt;
* Command injection in Devtools &#039;Copy as XXX&#039; commands, where the command is not native to the OS in question&lt;br /&gt;
* Attacks that assume physical access to the computer.  While certain features of the browser (such as primary password) can mitigate this attack vector, these should not be considered security boundaries. Bypasses of them are considered for improvement on a case-by-case basis and typically are not considered security bugs.  &lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1254560</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1254560"/>
		<updated>2025-07-10T12:42:12Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that allows arbitrary attacker controlled HTML, that a user can interact with, with an attacker-controlled URL in the actual address bar retaining normal badging and iconography&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Techniques that cause a JavaScript alert or similar browser modal to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-clickjacking || client security issues due to techniques that cause a user to unintentionally click or tap on a browser control, either by obscuring the true target of the click or by causing the target to appear by surprise in place of the item the user intended to click or tap&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || client issues that cause disclosure of sensitive user data or personal information (see also csectype-side-channel and csectype-sop)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || client Denial of Service issues (use wsec-dos for web server denial of service as these tend to be more severe)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client crashes caused by dereferencing a poisoned (deleted) nsIFrame object (presumed to be limited to a Denial of Service)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-mitigation-bypass || client security issues that allow malicious content to evade protections provided by web security features like CSP and &amp;lt;iframe sandbox&amp;gt;, or user-abuse protections like the popup blocker&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client crashes due to a guaranteed null dereference (do not use for near-null crashes with a content-controlled offset)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || client crashes or hangs that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issues due to a race condition&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || client security issues where a low-privilege process can cause memory corruption or arbitrary code execution in a higher-privilege processs (for example, through malformed IPC messages or Shared Memory)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-side-channel || Disclosure of sensitive information or state through side-effects (typically, timing)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy including Universal-XSS (see also csectype-side-channel for less severe &amp;quot;leaks&amp;quot;)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issues due to UI Redress attacks or manipulation of the browser UI to fool users into taking the wrong action (excluding csectype-clickjacking issues)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || client security issues—or potential issues—due to undefined compiler behavior&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Issues not considered security bugs ==&lt;br /&gt;
&lt;br /&gt;
* Unexploitable bugs that crash only a content process&lt;br /&gt;
* Command injection in Devtools &#039;Copy as XXX&#039; commands, where the command is not native to the OS in question&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1254559</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1254559"/>
		<updated>2025-07-10T12:42:00Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that allows arbitrary attacker controlled HTML, that a user can interact with, with an attacker-controlled URL in the actual address bar retaining normal badging and iconography&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Techniques that cause a JavaScript alert or similar browser modal to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-clickjacking || client security issues due to techniques that cause a user to unintentionally click or tap on a browser control, either by obscuring the true target of the click or by causing the target to appear by surprise in place of the item the user intended to click or tap&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || client issues that cause disclosure of sensitive user data or personal information (see also csectype-side-channel and csectype-sop)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || client Denial of Service issues (use wsec-dos for web server denial of service as these tend to be more severe)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client crashes caused by dereferencing a poisoned (deleted) nsIFrame object (presumed to be limited to a Denial of Service)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-mitigation-bypass || client security issues that allow malicious content to evade protections provided by web security features like CSP and &amp;lt;iframe sandbox&amp;gt;, or user-abuse protections like the popup blocker&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client crashes due to a guaranteed null dereference (do not use for near-null crashes with a content-controlled offset)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || client crashes or hangs that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issues due to a race condition&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || client security issues where a low-privilege process can cause memory corruption or arbitrary code execution in a higher-privilege processs (for example, through malformed IPC messages or Shared Memory)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-side-channel || Disclosure of sensitive information or state through side-effects (typically, timing)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy including Universal-XSS (see also csectype-side-channel for less severe &amp;quot;leaks&amp;quot;)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issues due to UI Redress attacks or manipulation of the browser UI to fool users into taking the wrong action (excluding csectype-clickjacking issues)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || client security issues—or potential issues—due to undefined compiler behavior&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Issues not considered security bugs ===&lt;br /&gt;
&lt;br /&gt;
* Unexploitable bugs that crash only a content process&lt;br /&gt;
* Command injection in Devtools &#039;Copy as XXX&#039; commands, where the command is not native to the OS in question&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1254207</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1254207"/>
		<updated>2025-05-27T17:25:33Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Assign CVEs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory.&lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* ASAN Nightly bugs go into the roll-up advisory.&lt;br /&gt;
* Sometimes we know a large library update will fix vulnerabilities, but we don&#039;t know _which_ vulnerabilities it fixes (often upstream does not assign CVEs, and we aren&#039;t allowed to assign CVEs for them) or if there are vulnerabilities at all (but we suspect there are.)  We try to avoid this, but in these cases, it&#039;s acceptable to issue a CVE with details like e.g. &#039;Angle graphics library out of date&#039; - &#039;An out of date graphics library (Angle) [likely] contained vulnerabilities that could potentially be exploited.&#039;&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the roll-up&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
 &lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
 &lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects in the advisory description should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with your reviewer (you should know who that is, if you don&#039;t, ask) ahead of time when they will be able to review, and make sure you have the yml files ready by that time.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;If the release is on a Tuesday, this should be done no later than Friday evening.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Add them to the repository ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
// First time:&lt;br /&gt;
git clone https://github.com/mozilla/foundation-security-advisories&lt;br /&gt;
cd foundation-security-advisories&lt;br /&gt;
git remote rename origin origin-public&lt;br /&gt;
git remote add origin git@github.com:mozilla/foundation-security-advisories-private.git&lt;br /&gt;
&lt;br /&gt;
// Every time:&lt;br /&gt;
git pull origin-public master&lt;br /&gt;
git checkout -b adv-131&lt;br /&gt;
// Add your yaml files&lt;br /&gt;
git commit&lt;br /&gt;
git push origin&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The above instructions for setup will check out the public and private repos and will rename the public one so it&#039;s harder to accidentally push to it.&lt;br /&gt;
&lt;br /&gt;
Each advisory cycle, you will update your local repo with the canonical source of truth (the public master branch), create a branch for yourself, you commit your files, and you submit the branch to the private repo.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla and in the yml file. This needs to be done by a person with CVE Services credentials and Bugzilla security access, and can be automated with the &#039;&#039;&#039;assign_cve_ids&#039;&#039;&#039; script in the [https://github.com/mozilla/foundation-security-advisories foundation-security-advisories] repository.&lt;br /&gt;
&lt;br /&gt;
That script will automatically reserve new CVEs, insert them into the yml file, and set the CVE IDs as aliases on Bugzilla. You can use it by running &amp;lt;tt&amp;gt;pip i &amp;amp;&amp;amp; assign_cve_ids&amp;lt;/tt&amp;gt; in the root of the repository. You can provide the required credentials through the &#039;&#039;&#039;CVE_USER&#039;&#039;&#039;, &#039;&#039;&#039;CVE_ORG&#039;&#039;&#039;, &#039;&#039;&#039;CVE_API_KEY&#039;&#039;&#039;, &#039;&#039;&#039;CVE_ENV&#039;&#039;&#039;, and &#039;&#039;&#039;BUGZILLA_API_KEY&#039;&#039;&#039; environment variables. Before running the script, make sure to set the names of the advisories that should get a CVE ID to &#039;&#039;&#039;MFSA-RESERVE-{YEAR}-{BUG_ID}&#039;&#039;&#039;, where &#039;&#039;&#039;{YEAR}&#039;&#039;&#039; is the year that should be associated with the CVE, and &#039;&#039;&#039;{BUG_ID}&#039;&#039;&#039; is the id of a Bugzilla bug that should get the CVE ID as an alias. If you do not want to have a alias set for the advisory, use a small unique number instead. If you have used the [[#Generate_and_edit_the_YML_File|&#039;&#039;&#039;gen_yml.py&#039;&#039;&#039; script from the previous step]] to generate your yml file, the advisories should already have this format.&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that &#039;&#039;&#039;issues that already have had a CVE assigned&#039;&#039;&#039; - for example because it&#039;s an upstream bug - should instead have their identifier set to that CVE.  If the issue should have a CVE from another org but we don&#039;t have it yet, then it should be set to &#039;&#039;&#039;MFSA-TMP-2025-XXXX&#039;&#039;&#039; where XXXX is an incrementing number.  We strive not to re-ruse these.  It is common (usually once or twice a year) for us to request Google to assign a CVE for an issue in an upstream library.  The Googler to contact for this is James Zern, and Tom Ritter (among others) can put you in touch.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments, as well as publishing the actual CVE contents to CVE Services.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1253934</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1253934"/>
		<updated>2025-04-28T17:23:58Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Update the severity of spoofing bugs&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that allows arbitrary attacker controlled HTML, that a user can interact with, with an attacker-controlled URL in the actual address bar retaining normal badging and iconography&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Techniques that cause a JavaScript alert or similar browser modal to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client security issues prevented using layout&#039;s frame poisoning, which usually lowers the severity.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client security issue arising from a null pointer being treated as a valid pointer&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issue arising from the interaction of multiple threads 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || A content process can cause memory corruption or arbitrary/JS code execution in any other process through malformed or tricky IPC messages or Shared Memory&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sidechannel || client security issue arising from information about a computation being exposed through an external measurement such as time or power&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example).&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issue from fooling the user into taking the wrong action by presenting incorrect UI	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1252032</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1252032"/>
		<updated>2024-10-01T20:47:30Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Add them to the repository */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory.&lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* ASAN Nightly bugs go into the roll-up advisory.&lt;br /&gt;
* Sometimes we know a large library update will fix vulnerabilities, but we don&#039;t know _which_ vulnerabilities it fixes (often upstream does not assign CVEs, and we aren&#039;t allowed to assign CVEs for them) or if there are vulnerabilities at all (but we suspect there are.)  We try to avoid this, but in these cases, it&#039;s acceptable to issue a CVE with details like e.g. &#039;Angle graphics library out of date&#039; - &#039;An out of date graphics library (Angle) [likely] contained vulnerabilities that could potentially be exploited.&#039;&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the roll-up&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
&lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
&lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects in the advisory description should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with your reviewer (you should know who that is, if you don&#039;t, ask) ahead of time when they will be able to review, and make sure you have the yml files ready by that time.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;If the release is on a Tuesday, this should be done no later than Friday evening.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Add them to the repository ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
// First time:&lt;br /&gt;
git clone https://github.com/mozilla/foundation-security-advisories&lt;br /&gt;
cd foundation-security-advisories&lt;br /&gt;
git remote rename origin origin-public&lt;br /&gt;
git remote add origin git@github.com:mozilla/foundation-security-advisories-private.git&lt;br /&gt;
&lt;br /&gt;
// Every time:&lt;br /&gt;
git pull origin-public master&lt;br /&gt;
git checkout -b adv-131&lt;br /&gt;
// Add your yaml files&lt;br /&gt;
git commit&lt;br /&gt;
git push origin&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The above instructions for setup will check out the public and private repos and will rename the public one so it&#039;s harder to accidentally push to it.&lt;br /&gt;
&lt;br /&gt;
Each advisory cycle, you will update your local repo with the canonical source of truth (the public master branch), create a branch for yourself, you commit your files, and you submit the branch to the private repo.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla and in the yml file. This needs to be done by a person with CVE Services credentials and Bugzilla security access, and can be automated with the &#039;&#039;&#039;assign_cve_ids&#039;&#039;&#039; script in the [https://github.com/mozilla/foundation-security-advisories foundation-security-advisories] repository.&lt;br /&gt;
&lt;br /&gt;
That script will automatically reserve new CVEs, insert them into the yml file, and set the CVE IDs as aliases on Bugzilla. You can use it by running &amp;lt;tt&amp;gt;pip i &amp;amp;&amp;amp; assign_cve_ids&amp;lt;/tt&amp;gt; in the root of the repository. You can provide the required credentials through the &#039;&#039;&#039;CVE_USER&#039;&#039;&#039;, &#039;&#039;&#039;CVE_ORG&#039;&#039;&#039;, &#039;&#039;&#039;CVE_API_KEY&#039;&#039;&#039;, &#039;&#039;&#039;CVE_ENV&#039;&#039;&#039;, and &#039;&#039;&#039;BUGZILLA_API_KEY&#039;&#039;&#039; environment variables. Before running the script, make sure to set the names of the advisories that should get a CVE ID to &#039;&#039;&#039;MFSA-RESERVE-{YEAR}-{BUG_ID}&#039;&#039;&#039;, where &#039;&#039;&#039;{YEAR}&#039;&#039;&#039; is the year that should be associated with the CVE, and &#039;&#039;&#039;{BUG_ID}&#039;&#039;&#039; is the id of a Bugzilla bug that should get the CVE ID as an alias. If you do not want to have a alias set for the advisory, use a small unique number instead. If you have used the [[#Generate_and_edit_the_YML_File|&#039;&#039;&#039;gen_yml.py&#039;&#039;&#039; script from the previous step]] to generate your yml file, the advisories should already have this format.&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that &#039;&#039;&#039;issues that already have had a CVE assigned&#039;&#039;&#039; - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.  This is very important.  It is common (usually several times a year) for us to request Google to assign a CVE for an issue in an upstream library.  The Googler to contact for this is Adrian Taylor, and Tom Ritter (among others) can put you in touch.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments, as well as publishing the actual CVE contents to CVE Services.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1252031</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1252031"/>
		<updated>2024-10-01T20:47:15Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Get review */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory.&lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* ASAN Nightly bugs go into the roll-up advisory.&lt;br /&gt;
* Sometimes we know a large library update will fix vulnerabilities, but we don&#039;t know _which_ vulnerabilities it fixes (often upstream does not assign CVEs, and we aren&#039;t allowed to assign CVEs for them) or if there are vulnerabilities at all (but we suspect there are.)  We try to avoid this, but in these cases, it&#039;s acceptable to issue a CVE with details like e.g. &#039;Angle graphics library out of date&#039; - &#039;An out of date graphics library (Angle) [likely] contained vulnerabilities that could potentially be exploited.&#039;&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the roll-up&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
&lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
&lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects in the advisory description should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with your reviewer (you should know who that is, if you don&#039;t, ask) ahead of time when they will be able to review, and make sure you have the yml files ready by that time.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;If the release is on a Tuesday, this should be done no later than Friday evening.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Add them to the repository ===&lt;br /&gt;
&lt;br /&gt;
```&lt;br /&gt;
// First time:&lt;br /&gt;
git clone https://github.com/mozilla/foundation-security-advisories&lt;br /&gt;
cd foundation-security-advisories&lt;br /&gt;
git remote rename origin origin-public&lt;br /&gt;
git remote add origin git@github.com:mozilla/foundation-security-advisories-private.git&lt;br /&gt;
&lt;br /&gt;
// Every time:&lt;br /&gt;
git pull origin-public master&lt;br /&gt;
git checkout -b adv-131&lt;br /&gt;
// Add your yaml files&lt;br /&gt;
git commit&lt;br /&gt;
git push origin&lt;br /&gt;
```&lt;br /&gt;
&lt;br /&gt;
The above instructions for setup will check out the public and private repos and will rename the public one so it&#039;s harder to accidentally push to it.&lt;br /&gt;
&lt;br /&gt;
Each advisory cycle, you will update your local repo with the canonical source of truth (the public master branch), create a branch for yourself, you commit your files, and you submit the branch to the private repo.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla and in the yml file. This needs to be done by a person with CVE Services credentials and Bugzilla security access, and can be automated with the &#039;&#039;&#039;assign_cve_ids&#039;&#039;&#039; script in the [https://github.com/mozilla/foundation-security-advisories foundation-security-advisories] repository.&lt;br /&gt;
&lt;br /&gt;
That script will automatically reserve new CVEs, insert them into the yml file, and set the CVE IDs as aliases on Bugzilla. You can use it by running &amp;lt;tt&amp;gt;pip i &amp;amp;&amp;amp; assign_cve_ids&amp;lt;/tt&amp;gt; in the root of the repository. You can provide the required credentials through the &#039;&#039;&#039;CVE_USER&#039;&#039;&#039;, &#039;&#039;&#039;CVE_ORG&#039;&#039;&#039;, &#039;&#039;&#039;CVE_API_KEY&#039;&#039;&#039;, &#039;&#039;&#039;CVE_ENV&#039;&#039;&#039;, and &#039;&#039;&#039;BUGZILLA_API_KEY&#039;&#039;&#039; environment variables. Before running the script, make sure to set the names of the advisories that should get a CVE ID to &#039;&#039;&#039;MFSA-RESERVE-{YEAR}-{BUG_ID}&#039;&#039;&#039;, where &#039;&#039;&#039;{YEAR}&#039;&#039;&#039; is the year that should be associated with the CVE, and &#039;&#039;&#039;{BUG_ID}&#039;&#039;&#039; is the id of a Bugzilla bug that should get the CVE ID as an alias. If you do not want to have a alias set for the advisory, use a small unique number instead. If you have used the [[#Generate_and_edit_the_YML_File|&#039;&#039;&#039;gen_yml.py&#039;&#039;&#039; script from the previous step]] to generate your yml file, the advisories should already have this format.&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that &#039;&#039;&#039;issues that already have had a CVE assigned&#039;&#039;&#039; - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.  This is very important.  It is common (usually several times a year) for us to request Google to assign a CVE for an issue in an upstream library.  The Googler to contact for this is Adrian Taylor, and Tom Ritter (among others) can put you in touch.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments, as well as publishing the actual CVE contents to CVE Services.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1250913</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1250913"/>
		<updated>2024-05-29T17:50:26Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Severity Ratings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that affects the actual URL bar or prevents it from appearing; excluding fullscreen techniques&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that cause a JavaScript alert to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client security issues prevented using layout&#039;s frame poisoning, which usually lowers the severity.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client security issue arising from a null pointer being treated as a valid pointer&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issue arising from the interaction of multiple threads 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || A content process can cause memory corruption or arbitrary/JS code execution in any other process through malformed or tricky IPC messages or Shared Memory&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sidechannel || client security issue arising from information about a computation being exposed through an external measurement such as time or power&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example).&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issue from fooling the user into taking the wrong action by presenting incorrect UI	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1250877</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1250877"/>
		<updated>2024-05-24T12:37:30Z</updated>

		<summary type="html">&lt;p&gt;Tritter: tweaks&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that affects the actual URL bar or prevents it from appearing; excluding fullscreen techniques&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Private Browsing Mode data leaks discoverable in the Browser UI (excepting user-directed actions like Bookmarks/Permissions)&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile, excepting data cleaned on startup due to process reaping&lt;br /&gt;
* Techniques that cause a JavaScript alert to be shown with a different domain than the one in the address bar (or one of its nested browsing contexts)&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client security issues prevented using layout&#039;s frame poisoning, which usually lowers the severity.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client security issue arising from a null pointer being treated as a valid pointer&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issue arising from the interaction of multiple threads 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || A content process can cause memory corruption or arbitrary/JS code execution in any other process through malformed or tricky IPC messages or Shared Memory&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sidechannel || client security issue arising from information about a computation being exposed through an external measurement such as time or power&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example).&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issue from fooling the user into taking the wrong action by presenting incorrect UI	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1250865</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1250865"/>
		<updated>2024-05-22T14:59:48Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties see [[Security_Severity_Ratings/Web]]. For details about Mozilla&#039;s bug bounty program please visit the [https://www.mozilla.org/en-US/security/bug-bounty/ bounty pages] on our official site.&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues, unless constrained e.g. by OOM conditions&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Domain spoofing that affects the actual URL bar or prevents it from appearing; excluding fullscreen techniques&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of detailed browsing history&lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Memory Safety issues caused by OOM conditions; unless precise triggering of the condition can be shown&lt;br /&gt;
* Techniques that put the browser into fullscreen mode without user interaction or while obscuring the notification&lt;br /&gt;
* Techniques that overlay the address bar with another piece of browser chrome to obscure it&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Desktop&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of more limited browsing history or browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks to disk on Mobile&lt;br /&gt;
* Techniques that cause a JavaScript alert to be shown with a different domain in the address bar&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as triggering a release assertion or those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Sometimes none of the above severity ratings apply to a bug because it is not a vulnerability itself, but nonetheless is security-sensitive for other reasons and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is used for bugs that are not themselves exploitable security issues but may contain information about other security-sensitive issues that needs to be kept confidential. Note: if the private information is not related to security issues the bug should use &amp;quot;employee confidential&amp;quot; or some other group instead of &amp;quot;security-sensitive&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Meta bugs tracking a group of related security issues&lt;br /&gt;
* A non-security bug where an independent security issue was discovered during the investigation. The separate security issue should be addressed in a new bug, but the original issue needs to remain hidden until the security issue is resolved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional security bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
==Additional Security Keywords, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
In addition to characterizing the severity of an issue with the &amp;lt;code&amp;gt;sec-&amp;lt;/code&amp;gt; keywords, we also have sub-type keywords, whiteboard tags (standardized string), and flags we can use to further characterize a security issue.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-framepoisoning || client security issues prevented using layout&#039;s frame poisoning, which usually lowers the severity.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to JIT miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-nullptr || client security issue arising from a null pointer being treated as a valid pointer&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues&lt;br /&gt;
|-&lt;br /&gt;
|csectype-race || client security issue arising from the interaction of multiple threads 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sandbox-escape || A content process can cause memory corruption or arbitrary/JS code execution in any other process through malformed or tricky IPC messages or Shared Memory&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sidechannel || client security issue arising from information about a computation being exposed through an external measurement such as time or power&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example).&lt;br /&gt;
|-&lt;br /&gt;
|csectype-spoof || client security issue from fooling the user into taking the wrong action by presenting incorrect UI	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1246066</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1246066"/>
		<updated>2023-04-07T15:08:06Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Get review */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory. &lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* ASAN Nightly bugs go into the roll-up advisory.&lt;br /&gt;
* Sometimes we know a large library update will fix vulnerabilities, but we don&#039;t know _which_ vulnerabilities it fixes (often upstream does not assign CVEs, and we aren&#039;t allowed to assign CVEs for them) or if there are vulnerabilities at all (but we suspect there are.)  We try to avoid this, but in these cases, it&#039;s acceptable to issue a CVE with details like e.g. &#039;Angle graphics library out of date&#039; - &#039;An out of date graphics library (Angle) [likely] contained vulnerabilities that could potentially be exploited.&#039;&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the roll-up&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
 &lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
 &lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects in the advisory description should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla, and in the yml file.  This can be automated with this script: https://github.com/tomrittervg/secadv/blob/master/cve_assignment_script.txt&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that &#039;&#039;&#039;issues that already have had a CVE assigned&#039;&#039;&#039; - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.  This is very important.  It is common (usually several times a year) for us to request Google to assign a CVE for an issue in an upstream library.  The Googler to contact for this is Adrian Taylor, and Tom Ritter (among others) can put you in touch.&lt;br /&gt;
&lt;br /&gt;
A CVE ID from Mitre is assigned from [https://docs.google.com/spreadsheets/d/14rI7jdL23HHJ5VOpVJhV_zc_bp2InrXlKD_vap9oec0/edit our CVE pool] of numbers as an “alias” in Bugzilla and the CVE Pool sheet is updated to include the bug number and title on the listing for the assigned CVE ID.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
==== Oh no, I don&#039;t have enough CVEs! or Oh no, Google never got back to me! ====&lt;br /&gt;
&lt;br /&gt;
That&#039;s alright.  Assign the issue an id of MFSA-TMP-YEAR-#### where # is a unique incrementing number (like MFSA-TMP-2023-001). Everything will work fine. Later when we have the CVE, go back and assign it.  It&#039;s hard to keep track of TMP numbers, but this is uncommon. A command like &amp;lt;code&amp;gt;git grep &amp;quot;MFSA-TMP&amp;quot; $(git rev-list --all -- announce) -- announce/&amp;lt;/code&amp;gt; will show you any uses, even if they&#039;ve been correct in the file.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mozilla/foundation-security-advisories/commit/3114d01de2f27cdb606d8d07603c2362515104f1 Here&#039;s an example of what it looks like.]&lt;br /&gt;
&lt;br /&gt;
n.b. While that example used MFSA-YEAR-####, that format is actually used for the advisories themselves (so MFSA-2020-0001 was accidentally used to refer both to an individual issue pending a CVE and to all advisories for Firefox 71.) So for now on we use the MFSA-TMP prefix to distinguish. We also previously used the MFSA-YEAR-# format for individual issues from 2005ish - 2016.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with your reviewer (you should know who that is, if you don&#039;t, ask) ahead of time when they will be able to review, and make sure you have the yml files ready by that time.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;If the release is on a Tuesday, this should be done no later than Friday evening.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1246065</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1246065"/>
		<updated>2023-04-07T15:06:39Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Assign CVEs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory. &lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* ASAN Nightly bugs go into the roll-up advisory.&lt;br /&gt;
* Sometimes we know a large library update will fix vulnerabilities, but we don&#039;t know _which_ vulnerabilities it fixes (often upstream does not assign CVEs, and we aren&#039;t allowed to assign CVEs for them) or if there are vulnerabilities at all (but we suspect there are.)  We try to avoid this, but in these cases, it&#039;s acceptable to issue a CVE with details like e.g. &#039;Angle graphics library out of date&#039; - &#039;An out of date graphics library (Angle) [likely] contained vulnerabilities that could potentially be exploited.&#039;&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the roll-up&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
 &lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
 &lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects in the advisory description should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla, and in the yml file.  This can be automated with this script: https://github.com/tomrittervg/secadv/blob/master/cve_assignment_script.txt&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that &#039;&#039;&#039;issues that already have had a CVE assigned&#039;&#039;&#039; - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.  This is very important.  It is common (usually several times a year) for us to request Google to assign a CVE for an issue in an upstream library.  The Googler to contact for this is Adrian Taylor, and Tom Ritter (among others) can put you in touch.&lt;br /&gt;
&lt;br /&gt;
A CVE ID from Mitre is assigned from [https://docs.google.com/spreadsheets/d/14rI7jdL23HHJ5VOpVJhV_zc_bp2InrXlKD_vap9oec0/edit our CVE pool] of numbers as an “alias” in Bugzilla and the CVE Pool sheet is updated to include the bug number and title on the listing for the assigned CVE ID.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
==== Oh no, I don&#039;t have enough CVEs! or Oh no, Google never got back to me! ====&lt;br /&gt;
&lt;br /&gt;
That&#039;s alright.  Assign the issue an id of MFSA-TMP-YEAR-#### where # is a unique incrementing number (like MFSA-TMP-2023-001). Everything will work fine. Later when we have the CVE, go back and assign it.  It&#039;s hard to keep track of TMP numbers, but this is uncommon. A command like &amp;lt;code&amp;gt;git grep &amp;quot;MFSA-TMP&amp;quot; $(git rev-list --all -- announce) -- announce/&amp;lt;/code&amp;gt; will show you any uses, even if they&#039;ve been correct in the file.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mozilla/foundation-security-advisories/commit/3114d01de2f27cdb606d8d07603c2362515104f1 Here&#039;s an example of what it looks like.]&lt;br /&gt;
&lt;br /&gt;
n.b. While that example used MFSA-YEAR-####, that format is actually used for the advisories themselves (so MFSA-2020-0001 was accidentally used to refer both to an individual issue pending a CVE and to all advisories for Firefox 71.) So for now on we use the MFSA-TMP prefix to distinguish. We also previously used the MFSA-YEAR-# format for individual issues from 2005ish - 2016.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with dveditz ahead of time that he can take a look with a turn-around time of 2-3 days, and then send the yml files to him about a week or 8 days before the release date. Make edits.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;This should be done about 4 days before the release.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1246064</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1246064"/>
		<updated>2023-04-07T14:57:58Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Background */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory. &lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* ASAN Nightly bugs go into the roll-up advisory.&lt;br /&gt;
* Sometimes we know a large library update will fix vulnerabilities, but we don&#039;t know _which_ vulnerabilities it fixes (often upstream does not assign CVEs, and we aren&#039;t allowed to assign CVEs for them) or if there are vulnerabilities at all (but we suspect there are.)  We try to avoid this, but in these cases, it&#039;s acceptable to issue a CVE with details like e.g. &#039;Angle graphics library out of date&#039; - &#039;An out of date graphics library (Angle) [likely] contained vulnerabilities that could potentially be exploited.&#039;&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the roll-up&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
 &lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
 &lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects in the advisory description should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla, and in the yml file.  This can be automated with this script: https://github.com/tomrittervg/secadv/blob/master/cve_assignment_script.txt&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that issues that already have had a CVE assigned - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.&lt;br /&gt;
&lt;br /&gt;
A CVE ID from Mitre is assigned from [https://docs.google.com/spreadsheets/d/14rI7jdL23HHJ5VOpVJhV_zc_bp2InrXlKD_vap9oec0/edit our CVE pool] of numbers as an “alias” in Bugzilla and the CVE Pool sheet is updated to include the bug number and title on the listing for the assigned CVE ID.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
==== Oh no, I don&#039;t have enough CVEs! ====&lt;br /&gt;
&lt;br /&gt;
That&#039;s alright.  Assign the issue an id of MFSA-TMP-YEAR-#### where # is a unique incrementing number. Everything will work fine. Later when we have the CVE, go back and assign it.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mozilla/foundation-security-advisories/commit/3114d01de2f27cdb606d8d07603c2362515104f1 Here&#039;s an example of what it looks like.]&lt;br /&gt;
&lt;br /&gt;
n.b. While that example used MFSA-YEAR-####, that format is actually used for the advisories themselves (so MFSA-2020-0001 was accidentally used to refer both to an individual issue pending a CVE and to all advisories for Firefox 71.) So I&#039;m suggesting the MFSA-TMP prefix to distinguish. We also previously the MFSA-YEAR-# format for individual issues from 2005ish - 2016.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with dveditz ahead of time that he can take a look with a turn-around time of 2-3 days, and then send the yml files to him about a week or 8 days before the release date. Make edits.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;This should be done about 4 days before the release.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1245667</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1245667"/>
		<updated>2023-03-01T18:22:41Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Add csectype-sandbox-escape&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties, see this corresponding page. For details about the bug bounty for the Firefox browser, and specific other applications, see [this page]. For details about the bug bounty for Mozilla Servers and Web Properties, see [this page].&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Spoofing of full URL bar or bypass of SSL integrity checks&lt;br /&gt;
* Memory read that results in data being written into an inert container (ie string or image) that is subsequently accessible to content&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Memory corruption leading to a limited or arbitrary memory read or write.&lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of browsing history&lt;br /&gt;
* Overflows resulting in native code execution &lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Status Codes, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the keywords may instead contain one of the following security status codes.&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Often none of the above severity ratings apply to a bug, because it is not a vulnerability but nonetheless is security sensitive and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is a bit of a catch-all bucket used for bugs that are not exploitable security issues but need to be kept confidential to protect sensitive information.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Bugs submitted by a user where the discussion is dependent on that user&#039;s browsing behavior (and cannot be effectively redacted)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to jit miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ssandbox-escape || A content process can cause memory corruption or arbitrary/JS code execution in any other process through malformed or tricky IPC messages or Shared Memory&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example). 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ui-redress || client security issues due to UI Redress attacks, either site-on-site (&amp;quot;clickjacking&amp;quot; and friends) or manipulation of the browser UI to fool users into taking the wrong action. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== secopstype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
secopstype- keywords are assigned to bugs to indicate the type of a client or website vulnerability. If you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:30%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:70%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|secops-cred-leak || Issues relating to credentials leak of Mozilla related accounts&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Mobile/GeckoView&amp;diff=1245388</id>
		<title>Mobile/GeckoView</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Mobile/GeckoView&amp;diff=1245388"/>
		<updated>2023-02-02T20:22:35Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Add some security-relevant information&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;GeckoView&#039;&#039;&#039; wraps Mozilla&#039;s [https://wikipedia.org/wiki/Gecko_(software) Gecko browser engine] in a reusable Android library for applications that wish to use Mozilla’s JavaScript, HTML layout, and rendering engines (generally referred to as SpiderMonkey and Gecko).&lt;br /&gt;
&lt;br /&gt;
Mozilla uses GeckoView to power [https://www.mozilla.org/en-US/firefox/browsers/mobile/android/ Firefox for Android], [https://blog.mozilla.org/blog/2018/09/18/firefox-reality-now-available/ Firefox Reality], [https://www.mozilla.org/firefox/mobile/#focus Firefox Focus], and other Android apps. GeckoView serves a similar purpose to Android&#039;s built-in WebView, but it has its own APIs and is &#039;&#039;not&#039;&#039; a drop in replacement.&lt;br /&gt;
&lt;br /&gt;
== Why GeckoView? ==&lt;br /&gt;
&lt;br /&gt;
While Android offers a built-in WebView, it&#039;s not intended for building browsers, and many advanced Web APIs are disabled. Android&#039;s WebView is also a moving target: it&#039;s impossible know exactly which engine (and what version of that engine) will power a WebView on client devices.&lt;br /&gt;
&lt;br /&gt;
In contrast, GeckoView is:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Full-Featured&#039;&#039;&#039;: GeckoView is designed to expose the entire power of the Web to applications, including being suitable for building web browsers.&lt;br /&gt;
* &#039;&#039;&#039;Self-Contained&#039;&#039;&#039;: Because GeckoView is a standalone library that you bundle with your application, you can be confident that the code you test is the code that will actually run.&lt;br /&gt;
* &#039;&#039;&#039;Standards Compliant&#039;&#039;&#039;: Like Firefox, GeckoView offers excellent support for modern Web standards.&lt;br /&gt;
&lt;br /&gt;
== About GeckoView ==&lt;br /&gt;
&lt;br /&gt;
Mozilla provides a GeckoView package and a [https://maven.mozilla.org/?prefix=maven2/org/mozilla/geckoview/ Maven Repo] along with [https://mozilla.github.io/geckoview/javadoc/mozilla-central/org/mozilla/geckoview/package-summary.html package documentation]. GeckoView has Stable, Beta, and Nightly channels that follow the [https://wiki.mozilla.org/Release_Management/Calendar Firefox browser’s Release Calendar] which typically ships a new major version to the Stable channel every 4 weeks and the maven repository is updated accordingly.&lt;br /&gt;
&lt;br /&gt;
When a new version is released to the Stable channel, any relevant security fixes will be published to the [https://www.mozilla.org/en-US/security/advisories/ Mozilla Security Advisories page]. While GeckoView is not explicitly called out in the advisories, most but not strictly all vulnerabilities will affect GeckoView. Exceptions would be vulnerabilities that occur in user-facing components excluded from GeckoView (such as the address bar) or desktop-platform-specific vulnerabilities. Keeping the GeckoView dependency up-to-date is the most effective way to incorporate security fixes.&lt;br /&gt;
&lt;br /&gt;
== Getting Help ==&lt;br /&gt;
&lt;br /&gt;
Interested in GeckoView? We&#039;re here to help!&lt;br /&gt;
&lt;br /&gt;
If you have questions or need assistance, please reach out to us in the [https://chat.mozilla.org/#/room/#geckoview:mozilla.org #geckoview] Matrix room.&lt;br /&gt;
&lt;br /&gt;
The overall Mozilla security team can be reached at security@mozilla.org.  If you ship GeckoView in your application you are encouraged to let us know at that address.&lt;br /&gt;
&lt;br /&gt;
== Get Started ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Building a browser? Check out [https://mozilla-mobile.github.io/android-components/ Android Components], our collection of ready-to-use support libraries!&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Configure Gradle ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Set the GeckoView version&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Like Firefox, GeckoView has three release channels: Stable, Beta, and Nightly. Browse the [https://maven.mozilla.org/?prefix=maven2/org/mozilla/geckoview/ Maven Repository] to see currently available builds.&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;Groovy&amp;quot;&amp;gt;&lt;br /&gt;
ext {&lt;br /&gt;
    geckoviewChannel = &amp;quot;nightly&amp;quot;&lt;br /&gt;
    geckoviewVersion = &amp;quot;70.0.20190712095934&amp;quot;&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. Add Mozilla&#039;s Maven repository&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;Groovy&amp;quot;&amp;gt;&lt;br /&gt;
repositories {&lt;br /&gt;
    maven {&lt;br /&gt;
        url &amp;quot;https://maven.mozilla.org/maven2/&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3. Configure Java 8 support&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;Groovy&amp;quot;&amp;gt;&lt;br /&gt;
android {&lt;br /&gt;
    // ...&lt;br /&gt;
&lt;br /&gt;
    // Note: compileOptions is only required for minSdkVersion &amp;lt; 24&lt;br /&gt;
    compileOptions {&lt;br /&gt;
        sourceCompatibility JavaVersion.VERSION_1_8&lt;br /&gt;
        targetCompatibility JavaVersion.VERSION_1_8&lt;br /&gt;
    }&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4. Add GeckoView Implementations&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;Groovy&amp;quot;&amp;gt;&lt;br /&gt;
dependencies {&lt;br /&gt;
    // ...&lt;br /&gt;
    implementation &amp;quot;org.mozilla.geckoview:geckoview-${geckoviewChannel}:${geckoviewVersion}&amp;quot;   &lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Add GeckoView to a Layout ===&lt;br /&gt;
&lt;br /&gt;
Inside a layout &amp;lt;code&amp;gt;.xml&amp;lt;/code&amp;gt; file, add the following:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;XML&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;org.mozilla.geckoview.GeckoView&lt;br /&gt;
    android:id=&amp;quot;@+id/geckoview&amp;quot;&lt;br /&gt;
    android:layout_width=&amp;quot;fill_parent&amp;quot;&lt;br /&gt;
    android:layout_height=&amp;quot;fill_parent&amp;quot; /&amp;gt;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Initialize GeckoView in an Activity ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1. Import the GeckoView classes inside an Activity:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;Java&amp;quot;&amp;gt;&lt;br /&gt;
import org.mozilla.geckoview.GeckoRuntime;&lt;br /&gt;
import org.mozilla.geckoview.GeckoSession;&lt;br /&gt;
import org.mozilla.geckoview.GeckoView;&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2. In that activity&#039;s &amp;lt;code&amp;gt;onCreate&amp;lt;/code&amp;gt; function, add the following:&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;Java&amp;quot;&amp;gt;&lt;br /&gt;
GeckoView view = findViewById(R.id.geckoview);&lt;br /&gt;
GeckoSession session = new GeckoSession();&lt;br /&gt;
GeckoRuntime runtime = GeckoRuntime.create(this);&lt;br /&gt;
&lt;br /&gt;
session.open(runtime);&lt;br /&gt;
view.setSession(session);&lt;br /&gt;
session.loadUri(&amp;quot;about:buildconfig&amp;quot;); // Or any other URL...&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== You&#039;re done! ===&lt;br /&gt;
&lt;br /&gt;
Your application should now load and display a webpage inside of GeckoView.&lt;br /&gt;
&lt;br /&gt;
To learn more about GeckoView&#039;s capabilities, review GeckoView&#039;s [https://mozilla.github.io/geckoview/javadoc/mozilla-central/ JavaDoc] or the [https://searchfox.org/mozilla-central/source/mobile/android/geckoview_example reference application].&lt;br /&gt;
&lt;br /&gt;
== Documentation and Examples ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;APIs&#039;&#039;&#039;&lt;br /&gt;
* [https://mozilla.github.io/geckoview/javadoc/mozilla-central/ GeckoView API Documentation] (JavaDoc format)&lt;br /&gt;
* [https://mozilla-mobile.github.io/android-components/reference/ Android Components APIs]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Building / Contributing&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* [https://mozilla.github.io/geckoview/contributor/geckoview-quick-start GeckoView Contributor Quick Start Guide].&lt;br /&gt;
* [[Mobile/Get_Involved]]&lt;br /&gt;
* [https://developer.mozilla.org/en-US/docs/Mozilla/Developer_guide/Introduction Mozilla Developer Guide]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Bugs&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* [https://bugzilla.mozilla.org/enter_bug.cgi?product=GeckoView&amp;amp;component=General File a new GeckoView bug]&lt;br /&gt;
* [https://bugzilla.mozilla.org/buglist.cgi?product=GeckoView&amp;amp;component=General&amp;amp;resolution=---&amp;amp;list_id=14532935 All GeckoView Bugs]&lt;br /&gt;
* [[Mobile/GeckoView/Bugs|GeckoView Bug Dashboard]] 🐛&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Products / Examples&#039;&#039;&#039;&lt;br /&gt;
* [https://blog.mozilla.org/futurereleases/2019/06/27/reinventing-firefox-for-android-a-preview/ Firefox Preview] ([https://github.com/mozilla-mobile/fenix GitHub])&lt;br /&gt;
* [https://blog.mozilla.org/blog/2018/09/18/firefox-reality-now-available/ Firefox Reality] ([https://github.com/mozillareality/firefoxreality GitHub])&lt;br /&gt;
* [https://www.mozilla.org/firefox/mobile/#focus Firefox Focus] ([https://github.com/mozilla-mobile/focus-android/ GitHub])&lt;br /&gt;
* [https://searchfox.org/mozilla-central/source/mobile/android/geckoview_example GeckoView Reference Application]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Minimum System Requirements&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* GeckoView requires Android OS version 4.1 (API Level 16) or later. Fenix and Focus support Android 5.0 (API level 21) and later.&lt;br /&gt;
* 32-bit ARMv7-A, 64-bit ARMv8-A (aka ARM64), 32-bit x86, or x86_64 CPU&lt;br /&gt;
* Minimum device specs are quad-core 1.2 GHz and 2 GB RAM (like the [https://www.gsmarena.com/compare.php3?&amp;amp;idPhone3=8104&amp;amp;idPhone2=8721&amp;amp;idPhone1=9008 Moto G4 Play, E4, or E5]), though Mozilla&#039;s GeckoView test devices are the [https://en.wikipedia.org/wiki/Moto_G5 Moto G5] with an octa-core 1.4 GHz CPU and 2 GB RAM and the [https://en.wikipedia.org/wiki/Pixel_2 Google Pixel 2] with an octa-core 1.9 GHz CPU and 4 GB RAM.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1244826</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1244826"/>
		<updated>2022-12-08T16:25:27Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Criteria */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories. Presently Tom Ritter does Security Advisories, who inherited it from Al Billings.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory. &lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* ASAN Nightly bugs go into the roll-up advisory.&lt;br /&gt;
* Sometimes we know a large library update will fix vulnerabilities, but we don&#039;t know _which_ vulnerabilities it fixes (often upstream does not assign CVEs, and we aren&#039;t allowed to assign CVEs for them) or if there are vulnerabilities at all (but we suspect there are.)  We try to avoid this, but in these cases, it&#039;s acceptable to issue a CVE with details like e.g. &#039;Angle graphics library out of date&#039; - &#039;An out of date graphics library (Angle) [likely] contained vulnerabilities that could potentially be exploited.&#039;&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the roll-up&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
 &lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
 &lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla, and in the yml file.  This can be automated with this script: https://github.com/tomrittervg/secadv/blob/master/cve_assignment_script.txt&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that issues that already have had a CVE assigned - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.&lt;br /&gt;
&lt;br /&gt;
A CVE ID from Mitre is assigned from [https://docs.google.com/spreadsheets/d/14rI7jdL23HHJ5VOpVJhV_zc_bp2InrXlKD_vap9oec0/edit our CVE pool] of numbers as an “alias” in Bugzilla and the CVE Pool sheet is updated to include the bug number and title on the listing for the assigned CVE ID.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
==== Oh no, I don&#039;t have enough CVEs! ====&lt;br /&gt;
&lt;br /&gt;
That&#039;s alright.  Assign the issue an id of MFSA-TMP-YEAR-#### where # is a unique incrementing number. Everything will work fine. Later when we have the CVE, go back and assign it.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mozilla/foundation-security-advisories/commit/3114d01de2f27cdb606d8d07603c2362515104f1 Here&#039;s an example of what it looks like.]&lt;br /&gt;
&lt;br /&gt;
n.b. While that example used MFSA-YEAR-####, that format is actually used for the advisories themselves (so MFSA-2020-0001 was accidentally used to refer both to an individual issue pending a CVE and to all advisories for Firefox 71.) So I&#039;m suggesting the MFSA-TMP prefix to distinguish. We also previously the MFSA-YEAR-# format for individual issues from 2005ish - 2016.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with dveditz ahead of time that he can take a look with a turn-around time of 2-3 days, and then send the yml files to him about a week or 8 days before the release date. Make edits.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;This should be done about 4 days before the release.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1244825</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1244825"/>
		<updated>2022-12-08T16:22:45Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories. Presently Tom Ritter does Security Advisories, who inherited it from Al Billings.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory. &lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* ASAN Nightly bugs go into the roll-up advisory.&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the roll-up&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
 &lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
 &lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla, and in the yml file.  This can be automated with this script: https://github.com/tomrittervg/secadv/blob/master/cve_assignment_script.txt&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that issues that already have had a CVE assigned - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.&lt;br /&gt;
&lt;br /&gt;
A CVE ID from Mitre is assigned from [https://docs.google.com/spreadsheets/d/14rI7jdL23HHJ5VOpVJhV_zc_bp2InrXlKD_vap9oec0/edit our CVE pool] of numbers as an “alias” in Bugzilla and the CVE Pool sheet is updated to include the bug number and title on the listing for the assigned CVE ID.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
==== Oh no, I don&#039;t have enough CVEs! ====&lt;br /&gt;
&lt;br /&gt;
That&#039;s alright.  Assign the issue an id of MFSA-TMP-YEAR-#### where # is a unique incrementing number. Everything will work fine. Later when we have the CVE, go back and assign it.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mozilla/foundation-security-advisories/commit/3114d01de2f27cdb606d8d07603c2362515104f1 Here&#039;s an example of what it looks like.]&lt;br /&gt;
&lt;br /&gt;
n.b. While that example used MFSA-YEAR-####, that format is actually used for the advisories themselves (so MFSA-2020-0001 was accidentally used to refer both to an individual issue pending a CVE and to all advisories for Firefox 71.) So I&#039;m suggesting the MFSA-TMP prefix to distinguish. We also previously the MFSA-YEAR-# format for individual issues from 2005ish - 2016.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with dveditz ahead of time that he can take a look with a turn-around time of 2-3 days, and then send the yml files to him about a week or 8 days before the release date. Make edits.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;This should be done about 4 days before the release.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1243118</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1243118"/>
		<updated>2022-06-24T15:27:07Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Assign CVEs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories. Presently Tom Ritter does Security Advisories, who inherited it from Al Billings.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory. &lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the &amp;quot;roll-up&amp;quot;.&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
 &lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
 &lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons. This can lead to a use-after-free causing a potentially exploitable crash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities.&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* The title should be a full sentence.&lt;br /&gt;
* Function names and objects should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags.&lt;br /&gt;
* Description of the bug should not credit/mention the bug reporter again.&lt;br /&gt;
* Check the ESR version number for decimal errors (e.g., 78.6000001).&lt;br /&gt;
* Do not include IRC nicks in the reporter field.&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;.&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit.&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla, and in the yml file.  This can be automated with this script: https://github.com/tomrittervg/secadv/blob/master/cve_assignment_script.txt&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that issues that already have had a CVE assigned - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.&lt;br /&gt;
&lt;br /&gt;
A CVE ID from Mitre is assigned from [https://docs.google.com/spreadsheets/d/14rI7jdL23HHJ5VOpVJhV_zc_bp2InrXlKD_vap9oec0/edit our CVE pool] of numbers as an “alias” in Bugzilla and the CVE Pool sheet is updated to include the bug number and title on the listing for the assigned CVE ID.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
==== Oh no, I don&#039;t have enough CVEs! ====&lt;br /&gt;
&lt;br /&gt;
That&#039;s alright.  Assign the issue an id of MFSA-TMP-YEAR-#### where # is a unique incrementing number. Everything will work fine. Later when we have the CVE, go back and assign it.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mozilla/foundation-security-advisories/commit/3114d01de2f27cdb606d8d07603c2362515104f1 Here&#039;s an example of what it looks like.]&lt;br /&gt;
&lt;br /&gt;
n.b. While that example used MFSA-YEAR-####, that format is actually used for the advisories themselves (so MFSA-2020-0001 was accidentally used to refer both to an individual issue pending a CVE and to all advisories for Firefox 71.) So I&#039;m suggesting the MFSA-TMP prefix to distinguish. We also previously the MFSA-YEAR-# format for individual issues from 2005ish - 2016.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with dveditz ahead of time that he can take a look with a turn-around time of 2-3 days, and then send the yml files to him about a week or 8 days before the release date. Make edits.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;This should be done about 4 days before the release.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=MozillaBuild&amp;diff=1242011</id>
		<title>MozillaBuild</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=MozillaBuild&amp;diff=1242011"/>
		<updated>2022-04-21T20:29:59Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Overview ===&lt;br /&gt;
MozillaBuild is a meta-installer that provides everything needed to build Mozilla on Windows, sans Visual C++. Its source lives in https://hg.mozilla.org/mozilla-build/. Bugs should be filed in [https://bugzilla.mozilla.org/enter_bug.cgi?product=mozilla.org&amp;amp;component=MozillaBuild mozilla.org :: MozillaBuild].  For information about building Mozilla on Win32, [https://firefox-source-docs.mozilla.org/setup/windows_build.html#building-firefox-on-windows see the Firefox Source Docs page].&lt;br /&gt;
&lt;br /&gt;
=== Current Version ===&lt;br /&gt;
The current version of MozillaBuild is 4.0. It is available on [https://ftp.mozilla.org/pub/mozilla/libraries/win32/MozillaBuildSetup-Latest.exe ftp.mozilla.org].&lt;br /&gt;
&lt;br /&gt;
=== To Upgrade From A Previous Version ===&lt;br /&gt;
&lt;br /&gt;
Upgrading from an earlier MozillaBuild installation is straightforward but each step is important.&lt;br /&gt;
&lt;br /&gt;
# Delete your current MozillaBuild environment by moving your MozillaBuild folder into the trash. If you can&#039;t remove the existing installation, you probably have a terminal open or watchman or ssh-agent running. Terminate that process and try again.&lt;br /&gt;
# Install the new MozillaBuild release. &lt;br /&gt;
# If you had previously enabled Mintty, you will need to do so again by adding &amp;lt;tt&amp;gt;SET USE_MINTTY=1&amp;lt;/tt&amp;gt; to the top of start-shell.bat.&lt;br /&gt;
# Clobber any trees you have by running &amp;lt;tt&amp;gt;./mach clobber&amp;lt;/tt&amp;gt; (&amp;lt;b&amp;gt;build errors may occur otherwise&amp;lt;/b&amp;gt;).&lt;br /&gt;
# Re-run &amp;lt;tt&amp;gt;./mach bootstrap&amp;lt;/tt&amp;gt; to ensure that your tools are up-to-date. Ensure that you agree to run the Mercurial configuration wizard to ensure that its extensions are up-to-date.&lt;br /&gt;
&lt;br /&gt;
=== Windows Terminal ===&lt;br /&gt;
&lt;br /&gt;
It&#039;s possible to use Windows Terminal instead of the Command Prompt when using MozillaBuild.&lt;br /&gt;
To do so, add the following profile to the Windows Terminal settings JSON file:&lt;br /&gt;
&lt;br /&gt;
 {&lt;br /&gt;
     &amp;quot;name&amp;quot;: &amp;quot;MozillaBuild&amp;quot;,&lt;br /&gt;
     &amp;quot;commandline&amp;quot;: &amp;quot;C:/mozilla-build/start-shell.bat -here&amp;quot;,&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
Note that:&lt;br /&gt;
* The &amp;lt;code&amp;gt;-here&amp;lt;/code&amp;gt; flag can only be provided for MozillaBuild 4.0 and newer. Remove it from &amp;lt;code&amp;gt;commandline&amp;lt;/code&amp;gt; if you&#039;re using MozillaBuild 3.4 or earlier.&lt;br /&gt;
* Additionally, [https://bugzilla.mozilla.org/show_bug.cgi?id=1748762 the &amp;lt;code&amp;gt;&amp;quot;startingDirectory&amp;quot;&amp;lt;/code&amp;gt; option and the &amp;lt;code&amp;gt;wt -d&amp;lt;/code&amp;gt; flag don&#039;t work] unless &amp;lt;code&amp;gt;-here&amp;lt;/code&amp;gt; is provided.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Technical Details ===&lt;br /&gt;
The MozillaBuild package contains other software prerequisites necessary for building Mozilla, including [https://www.msys2.org/ an MSYS2 environment], &lt;br /&gt;
[https://www.mercurial-scm.org/ &amp;lt;code&amp;gt;Mercurial&amp;lt;/code&amp;gt;], Python, NSIS, and UPX, as well as optional but useful tools such as wget and emacs.&lt;br /&gt;
Note that the &amp;quot;UNIX-like&amp;quot; environment provided by MozillaBuild is only really useful for building and committing to the Mozilla source. Many command line tools you would expect in a modern Linux distribution are not present, and it&#039;s not possible to install them with a package manager.&lt;br /&gt;
&lt;br /&gt;
MozillaBuild does not modify the Windows registry.&lt;br /&gt;
&lt;br /&gt;
===== Command Prompt Tips and Caveats =====&lt;br /&gt;
* To paste into this window, you must right-click on the window&#039;s title bar, move your cursor to the “Edit” menu, and click “Paste”. You can also set “Quick Edit Mode” in the “Properties” menu and right-click the window to paste your selection.&lt;br /&gt;
* The MSYS2 root directory is located at&amp;lt;code&amp;gt;/c/mozilla-build/msys2/&amp;lt;/code&amp;gt; (assuming the default installation directory).&lt;br /&gt;
** For MozillaBuild 3.4 and older, the MSYS root directory can be found at &amp;lt;code&amp;gt;/c/mozilla-build/msys/&amp;lt;/code&amp;gt; instead.&lt;br /&gt;
* As of MozillaBuild 4.0, [https://cygwin.com/cygwin-ug-net/cygpath.html &amp;lt;code&amp;gt;cygpath&amp;lt;/code&amp;gt;] can be used to convert between path types:&lt;br /&gt;
&lt;br /&gt;
To convert from a Windows path to a Unix-y one, such as using MozillaBuild to edit a file printed by &amp;lt;code&amp;gt;hg&amp;lt;/code&amp;gt; (&amp;lt;b&amp;gt;remember to use single-quotes here!&amp;lt;/b&amp;gt;)&lt;br /&gt;
&lt;br /&gt;
 $ cygpath -u &#039;C:\mozilla-source\mozilla-unified\README.txt&#039;&lt;br /&gt;
 /c/mozilla-source/mozilla-unified/README.txt&lt;br /&gt;
&lt;br /&gt;
To convert from a Unix-y path to a Windows one, such as for copying a path printed by MozillaBuild to open in your Windows-native IDE:&lt;br /&gt;
&lt;br /&gt;
 $ cygpath -w &#039;/c/mozilla-source/mozilla-unified/README.txt&#039;&lt;br /&gt;
 C:\mozilla-source\mozilla-unified\README.txt&lt;br /&gt;
&lt;br /&gt;
=== Release Notes ===&lt;br /&gt;
* [https://groups.google.com/a/mozilla.org/g/dev-platform/c/0GHhML7tY6c MozillaBuild 4.0]&lt;br /&gt;
* [https://groups.google.com/a/mozilla.org/g/dev-platform/c/MzWYQ0NtXos MozillaBuild 3.4]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/oQk9k9-co54/k5FaAMg2BwAJ MozillaBuild 3.3]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/yJY5Ra0vJLQ/SsK9O-eoDgAJ MozillaBuild 3.2]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/Hy-LPWqJxd8/N1-AzRfhBAAJ MozillaBuild 3.1.1]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/C_S6HXcz7g0/6fIcnCF8BQAJ MozillaBuild 3.1]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/goLGqnPfAMI/-79pncxxBwAJ MozillaBuild 3.0]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/j4MUKzoDOlQ/gHH7w495AgAJ MozillaBuild 2.2.0]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/qpO21XQaNV8/-D5mNKqnCAAJ MozillaBuild 2.1.0]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/xJjMtp1_GV0/-zVzSMuDNVcJ MozillaBuild 2.0.0]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/XnFg0p1DJVI/laRQeGJDviwJ MozillaBuild 1.11.0]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/rslz21w1vng/P0jvA5y4vL4J MozillaBuild 1.10.0]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/cUqsdWEWIcw/HDyhJMz3-ysJ MozillaBuild 1.9.0]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/_9U6160_oyA/dWWpklVicwkJ MozillaBuild 1.8.0]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/XRecAHF-H28/aSbrdKJLUNoJ MozillaBuild 1.7]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/J3sBNBU1SvY/THhkqOCAvvYJ MozillaBuild 1.6]&lt;br /&gt;
* [https://groups.google.com/d/msg/mozilla.dev.platform/s7PsRYJyHbI/AsLz9dVgwIUJ MozillaBuild 1.5.1]: added YASM for WebM code in Firefox 4.&lt;br /&gt;
* [http://blog.mozilla.com/ted/2010/07/22/mozillabuild-1-5/ MozillaBuild 1.5]: Mercurial 1.5.4, Python 2.6.5, and support for Visual Studio 2010.&lt;br /&gt;
* [http://blog.mozilla.com/ted/2009/07/24/mozillabuild-1-4/ MozillaBuild 1.4]: Windows x64 compatibility and other.&lt;br /&gt;
* [http://blog.mozilla.com/ted/2008/06/16/mozillabuild-13/ MozillaBuild 1.3]&lt;br /&gt;
* [[MozillaBuild:ReleaseNotes:1.2]]&lt;br /&gt;
&lt;br /&gt;
There are no release notes for 1.1 and below.&lt;br /&gt;
&lt;br /&gt;
=== Historic Versions ===&lt;br /&gt;
Old versions of MozillaBuild can also be found on [https://ftp.mozilla.org/pub/mozilla/libraries/win32/ ftp.mozilla.org].&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Release_Management/Calendar&amp;diff=1238094</id>
		<title>Release Management/Calendar</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Release_Management/Calendar&amp;diff=1238094"/>
		<updated>2021-09-23T16:20:21Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Add fxtrains heroku link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:Firefox Release Calendar}}&lt;br /&gt;
This schedule is based on the current [[RapidRelease]] plan. Future dates may change if the process changes.  Code is not always released to users on the same day as the branch migration.  The release to users may be a few days later, to allow for manual testing and sign-off. Thunderbird tracks the [https://www.mozilla.org/en-US/firefox/organizations/ ESR schedule] column per [[Thunderbird:Home#Releases|Thunderbird release info]].&lt;br /&gt;
&lt;br /&gt;
== Calendars ==&lt;br /&gt;
&lt;br /&gt;
This wiki page may not always have the most current information. Please refer to one of the following calendars for up-to-date scheduling:&lt;br /&gt;
&lt;br /&gt;
* [https://www.google.com/calendar/embed?src=mozilla.com_2d37383433353432352d3939%40resource.calendar.google.com Firefox Merge/Release Dates] ([https://www.google.com/calendar/ical/mozilla.com_2d37383433353432352d3939%40resource.calendar.google.com/public/basic.ics ICS for Thunderbird/Lightning or your calendar app]) (low noise)&lt;br /&gt;
* [https://www.google.com/calendar/embed?src=bW96aWxsYS5jb21fZGJxODRhbnI5aTh0Y25taGFiYXRzdHY1Y29AZ3JvdXAuY2FsZW5kYXIuZ29vZ2xlLmNvbQ Firefox Merge/Release Full Scheduling Calendar] ([https://calendar.google.com/calendar/ical/mozilla.com_dbq84anr9i8tcnmhabatstv5co%40group.calendar.google.com/public/basic.ics ICS]) (highly detailed - 99.99% up to date)&lt;br /&gt;
&lt;br /&gt;
== Future branch dates ==&lt;br /&gt;
&amp;lt;big&amp;gt;[[Release_Management/Release_owners|Release Owners]]&amp;lt;/big&amp;gt;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!Quarter ||Soft Freeze ||Merge Date ||Nightly ||Beta ||Release Date ||Release ||ESR&lt;br /&gt;
|-&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot;|Q4 2021&lt;br /&gt;
!2021-09-30&lt;br /&gt;
!2021-10-04&lt;br /&gt;
|[https://fx-trains.herokuapp.com/release/?version=95 Firefox 95]||[https://fx-trains.herokuapp.com/release/?version=94 Firefox 94]&lt;br /&gt;
!2021-10-05&lt;br /&gt;
|Firefox 93&lt;br /&gt;
|Firefox 78.15; 91.2&lt;br /&gt;
|-&lt;br /&gt;
!2021-10-28&lt;br /&gt;
!2021-11-01&lt;br /&gt;
|[https://fx-trains.herokuapp.com/release/?version=96 Firefox 96]||[https://fx-trains.herokuapp.com/release/?version=95 Firefox 95]&lt;br /&gt;
!2021-11-02&lt;br /&gt;
|Firefox 94&lt;br /&gt;
|Firefox 91.3&lt;br /&gt;
|-&lt;br /&gt;
!2021-12-02&lt;br /&gt;
!2021-12-06&lt;br /&gt;
|[https://fx-trains.herokuapp.com/release/?version=97 Firefox 97]||[https://fx-trains.herokuapp.com/release/?version=96 Firefox 96]&lt;br /&gt;
!2021-12-07&lt;br /&gt;
|Firefox 95&lt;br /&gt;
|Firefox 91.4&lt;br /&gt;
|-&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot;|Q1 2022&lt;br /&gt;
!2022-01-06&lt;br /&gt;
!2022-01-10&lt;br /&gt;
|[https://fx-trains.herokuapp.com/release/?version=98 Firefox 98]||[https://fx-trains.herokuapp.com/release/?version=97 Firefox 97]&lt;br /&gt;
!2022-01-11&lt;br /&gt;
|Firefox 96&lt;br /&gt;
|Firefox 91.5&lt;br /&gt;
|-&lt;br /&gt;
!2022-02-03&lt;br /&gt;
!2022-02-07&lt;br /&gt;
|[https://fx-trains.herokuapp.com/release/?version=99 Firefox 99]||[https://fx-trains.herokuapp.com/release/?version=98 Firefox 98]&lt;br /&gt;
!2022-02-08&lt;br /&gt;
|Firefox 97&lt;br /&gt;
|Firefox 91.6&lt;br /&gt;
|-&lt;br /&gt;
!2022-03-03&lt;br /&gt;
!2022-03-07&lt;br /&gt;
|[https://fx-trains.herokuapp.com/release/?version=100 Firefox 100]||[https://fx-trains.herokuapp.com/release/?version=99 Firefox 99]&lt;br /&gt;
!2022-03-08&lt;br /&gt;
|Firefox 98&lt;br /&gt;
|Firefox 91.7&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;The Nightly soft freeze is typically during the week prior to merge day. During this period high-risk patches should avoid landing until after the Nightly version bump lands on mozilla-central on merge day.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Past branch dates ==&lt;br /&gt;
More details on contents of releases can be found in the [https://www.mozilla.org/firefox/releases/ release notes archive] or [https://en.wikipedia.org/wiki/Firefox_version_history Wikipedia: Firefox version history].&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!Soft Freeze||Merge Date||Central||Beta&lt;br /&gt;
!Release Date||Release||ESR&lt;br /&gt;
|-&lt;br /&gt;
!2021-09-02&lt;br /&gt;
!2021-09-06&lt;br /&gt;
|Firefox 94||Firefox 93&lt;br /&gt;
!2021-09-07&lt;br /&gt;
|Firefox 92&lt;br /&gt;
|Firefox 78.14; 91.1&lt;br /&gt;
|-&lt;br /&gt;
!2021-08-05&lt;br /&gt;
!2021-08-09&lt;br /&gt;
|Firefox 93||Firefox 92&lt;br /&gt;
!2021-08-10&lt;br /&gt;
|Firefox 91&lt;br /&gt;
|Firefox 78.13; 91.0&lt;br /&gt;
|-&lt;br /&gt;
!2021-07-08&lt;br /&gt;
!2021-07-12&lt;br /&gt;
|Firefox 92||Firefox 91&lt;br /&gt;
!2021-07-13&lt;br /&gt;
|Firefox 90&lt;br /&gt;
|Firefox 78.12&lt;br /&gt;
|-&lt;br /&gt;
!2021-05-27&lt;br /&gt;
!2021-05-31&lt;br /&gt;
|Firefox 91||Firefox 90&lt;br /&gt;
!2021-06-01&lt;br /&gt;
|Firefox 89&lt;br /&gt;
|Firefox 78.11&lt;br /&gt;
|-&lt;br /&gt;
!2021-04-15&lt;br /&gt;
!2021-04-19&lt;br /&gt;
|Firefox 90||Firefox 89&lt;br /&gt;
!2021-04-19&lt;br /&gt;
|Firefox 88&lt;br /&gt;
|Firefox 78.10&lt;br /&gt;
|-&lt;br /&gt;
!2021-03-18&lt;br /&gt;
!2021-03-22&lt;br /&gt;
|Firefox 89||Firefox 88&lt;br /&gt;
!2021-03-23&lt;br /&gt;
|Firefox 87&lt;br /&gt;
|Firefox 78.9&lt;br /&gt;
|-&lt;br /&gt;
!2021-02-18&lt;br /&gt;
!2021-02-22&lt;br /&gt;
|Firefox 88||Firefox 87&lt;br /&gt;
!2021-02-23&lt;br /&gt;
|Firefox 86&lt;br /&gt;
|Firefox 78.8&lt;br /&gt;
|-&lt;br /&gt;
!2021-01-21&lt;br /&gt;
!2021-01-25&lt;br /&gt;
|Firefox 87||Firefox 86&lt;br /&gt;
!2021-01-26&lt;br /&gt;
|Firefox 85&lt;br /&gt;
|Firefox 78.7&lt;br /&gt;
|-&lt;br /&gt;
!2020-12-10&lt;br /&gt;
!2020-12-14&lt;br /&gt;
|Firefox 86||Firefox 85&lt;br /&gt;
!2020-12-15&lt;br /&gt;
|Firefox 84&lt;br /&gt;
|Firefox 78.6&lt;br /&gt;
|-&lt;br /&gt;
!2020-11-12&lt;br /&gt;
!2020-11-16&lt;br /&gt;
|Firefox 85||Firefox 84&lt;br /&gt;
!2020-11-17&lt;br /&gt;
|Firefox 83&lt;br /&gt;
|Firefox 78.5&lt;br /&gt;
|-&lt;br /&gt;
!2020-10-15&lt;br /&gt;
!2020-10-19&lt;br /&gt;
|Firefox 84||Firefox 83&lt;br /&gt;
!2020-10-20&lt;br /&gt;
|Firefox 82&lt;br /&gt;
|Firefox 78.4&lt;br /&gt;
|-&lt;br /&gt;
!2020-09-17&lt;br /&gt;
!2020-09-21&lt;br /&gt;
|Firefox 83||Firefox 82&lt;br /&gt;
!2020-09-22&lt;br /&gt;
|Firefox 81&lt;br /&gt;
|Firefox 78.3&lt;br /&gt;
|-&lt;br /&gt;
!2020-08-20&lt;br /&gt;
!2020-08-24&lt;br /&gt;
|Firefox 82||Firefox 81&lt;br /&gt;
!2020-08-25&lt;br /&gt;
|Firefox 80&lt;br /&gt;
|Firefox 68.12; 78.2&lt;br /&gt;
|-&lt;br /&gt;
!2020-07-23&lt;br /&gt;
!2020-07-27&lt;br /&gt;
|Firefox 81||Firefox 80&lt;br /&gt;
!2020-07-28&lt;br /&gt;
|Firefox 79&lt;br /&gt;
|Firefox 68.11; 78.1&lt;br /&gt;
|-&lt;br /&gt;
!2020-06-26&lt;br /&gt;
!2020-06-29&lt;br /&gt;
|Firefox 80||Firefox 79&lt;br /&gt;
!2020-06-30&lt;br /&gt;
|Firefox 78&lt;br /&gt;
|Firefox 68.10; 78.0&lt;br /&gt;
|-&lt;br /&gt;
!2020-05-28&lt;br /&gt;
!2020-06-01&lt;br /&gt;
|Firefox 79||Firefox 78&lt;br /&gt;
!2020-06-02&lt;br /&gt;
|Firefox 77&lt;br /&gt;
|Firefox 68.9&lt;br /&gt;
|-&lt;br /&gt;
!2020-04-30&lt;br /&gt;
!2020-05-04&lt;br /&gt;
|Firefox 78||Firefox 77&lt;br /&gt;
!2020-05-05&lt;br /&gt;
|Firefox 76&lt;br /&gt;
|Firefox 68.8&lt;br /&gt;
|-&lt;br /&gt;
!2020-04-02&lt;br /&gt;
!2020-04-06&lt;br /&gt;
|Firefox 77||Firefox 76&lt;br /&gt;
!2020-04-07&lt;br /&gt;
|Firefox 75&lt;br /&gt;
|Firefox 68.7&lt;br /&gt;
|-&lt;br /&gt;
!2020-03-05&lt;br /&gt;
!2020-03-09&lt;br /&gt;
|Firefox 76||Firefox 75&lt;br /&gt;
!2020-03-10&lt;br /&gt;
|Firefox 74&lt;br /&gt;
|Firefox 68.6&lt;br /&gt;
|-&lt;br /&gt;
!2020-02-06&lt;br /&gt;
!2020-02-10&lt;br /&gt;
|Firefox 75||Firefox 74&lt;br /&gt;
!2020-02-11&lt;br /&gt;
|Firefox 73&lt;br /&gt;
|Firefox 68.5&lt;br /&gt;
|-&lt;br /&gt;
!2020-01-02&lt;br /&gt;
!2020-01-06&lt;br /&gt;
|Firefox 74||Firefox 73&lt;br /&gt;
!2020-01-07&lt;br /&gt;
|Firefox 72&lt;br /&gt;
|Firefox 68.4&lt;br /&gt;
|-&lt;br /&gt;
!2019-11-25&lt;br /&gt;
!2019-12-02&lt;br /&gt;
|Firefox 73||Firefox 72&lt;br /&gt;
!2019-12-03&lt;br /&gt;
|Firefox 71&lt;br /&gt;
|Firefox 68.3&lt;br /&gt;
|-&lt;br /&gt;
!2019-10-14&lt;br /&gt;
!2019-10-21&lt;br /&gt;
|Firefox 72||Firefox 71&lt;br /&gt;
!2019-10-22&lt;br /&gt;
|Firefox 70&lt;br /&gt;
|Firefox 68.2&lt;br /&gt;
|-&lt;br /&gt;
!2019-08-26&lt;br /&gt;
!2019-09-02&lt;br /&gt;
|Firefox 71||Firefox 70&lt;br /&gt;
!2019-09-03&lt;br /&gt;
|Firefox 69&lt;br /&gt;
|Firefox 60.9; 68.1&lt;br /&gt;
|-&lt;br /&gt;
!2019-07-01&lt;br /&gt;
!2019-07-08&lt;br /&gt;
|Firefox 70||Firefox 69&lt;br /&gt;
!2019-07-09&lt;br /&gt;
|Firefox 68&lt;br /&gt;
|Firefox 60.8; 68.0&lt;br /&gt;
|-&lt;br /&gt;
!2019-05-13&lt;br /&gt;
!2019-05-20&lt;br /&gt;
|Firefox 69||Firefox 68&lt;br /&gt;
!2019-05-21&lt;br /&gt;
|Firefox 67&lt;br /&gt;
|Firefox 60.7&lt;br /&gt;
|-&lt;br /&gt;
!2019-03-11&lt;br /&gt;
!2019-03-18&lt;br /&gt;
|[https://docs.google.com/spreadsheets/d/1jtNuLGugHVgZTKR3NXQGngA_EjzSGxpRBzW-DvNK3EI/edit Firefox 68]||[https://docs.google.com/document/d/1feDkXleRXMJJS9lxP_vbyBApIDoEr44KchAZoYHkS54/edit Firefox 67]&lt;br /&gt;
!2019-03-19&lt;br /&gt;
|Firefox 66&lt;br /&gt;
|Firefox 60.6&lt;br /&gt;
|-&lt;br /&gt;
!2019-01-21&lt;br /&gt;
!2019-01-28&lt;br /&gt;
|[https://docs.google.com/document/d/1feDkXleRXMJJS9lxP_vbyBApIDoEr44KchAZoYHkS54/edit Firefox 67]||Firefox 66&lt;br /&gt;
!2019-01-29&lt;br /&gt;
|Firefox 65&lt;br /&gt;
|Firefox 60.5&lt;br /&gt;
|-&lt;br /&gt;
!2018-12-03&lt;br /&gt;
!2018-12-10&lt;br /&gt;
|[https://docs.google.com/document/d/1KnDiM3UmLbCPrc3UVZq6Z5Tdb2jnTfjpdyahSqgSGNE/edit Firefox 66]||Firefox 65&lt;br /&gt;
!2018-12-11&lt;br /&gt;
|Firefox 64&lt;br /&gt;
|Firefox 60.4&lt;br /&gt;
|-&lt;br /&gt;
!2018-10-15&lt;br /&gt;
!2018-10-22&lt;br /&gt;
|[https://docs.google.com/document/d/1vI9KWvSMQ50R9YgdMX7nG7CSuOnTeRGN9sOH_D6_v_c/edit Firefox 65]||Firefox 64&lt;br /&gt;
!2018-10-23&lt;br /&gt;
|Firefox 63&lt;br /&gt;
|Firefox 60.3&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!Merge Date||Central||Beta&lt;br /&gt;
!Release Date||Release||ESR&lt;br /&gt;
|-&lt;br /&gt;
!2018-09-04&lt;br /&gt;
|[https://docs.google.com/document/d/1MQa4J9OSTc1i60sFcVNyoFNLK8TLBXJlL9W12VoEUAc/edit Firefox 64]||Firefox 63&lt;br /&gt;
!2018-09-05&lt;br /&gt;
|Firefox 62&lt;br /&gt;
|Firefox 60.2&lt;br /&gt;
|-&lt;br /&gt;
!2018-06-25&lt;br /&gt;
|[https://docs.google.com/document/d/185O88wIwV-fRwqOKJaCCPVXjxhm70h8J4ApsJt1H9Rk/edit Firefox 63]||Firefox 62&lt;br /&gt;
!2018-06-26&lt;br /&gt;
|Firefox 61&lt;br /&gt;
|Firefox 52.9; 60.1&lt;br /&gt;
|-&lt;br /&gt;
!2018-05-07&lt;br /&gt;
|[https://docs.google.com/document/d/17FvsBOudLr15DgN-E82UamLhnweDHmGzQu4wIEi1QUg/edit Firefox 62]||Firefox 61&lt;br /&gt;
!2018-05-09&lt;br /&gt;
|Firefox 60&lt;br /&gt;
|Firefox 52.8; 60.0&lt;br /&gt;
|-&lt;br /&gt;
!2018-03-12&lt;br /&gt;
|[https://docs.google.com/document/d/1cLYXPrlEES90PSKQHFLf3j0tiOUfUth2ye9Kfg9xLYY/edit Firefox 61]||Firefox 60&lt;br /&gt;
!2018-03-13&lt;br /&gt;
|Firefox 59&lt;br /&gt;
|Firefox 52.7&lt;br /&gt;
|-&lt;br /&gt;
!2018-01-22&lt;br /&gt;
|[https://docs.google.com/document/d/14D5Au23znkkqeLZu22cI7kSM0EowkC0cq0ppiZR2lg4/edit Firefox 60]||Firefox 59&lt;br /&gt;
!2018-01-23&lt;br /&gt;
|Firefox 58&lt;br /&gt;
|Firefox 52.6&lt;br /&gt;
|-&lt;br /&gt;
!2017-11-13&lt;br /&gt;
|[https://docs.google.com/document/d/1ZOs9Ingbz0e-mWDu8yXGiMM-SnpBXThkLdXnplG4e2w/edit Firefox 59]||Firefox 58&lt;br /&gt;
!2017-11-14&lt;br /&gt;
|Firefox 57&lt;br /&gt;
|Firefox 52.5&lt;br /&gt;
|-&lt;br /&gt;
!2017-09-21&lt;br /&gt;
|[https://docs.google.com/document/d/1jPyeW14MyHyQX7kXBU8KN9jsxO2VQjP3GN_VpLiG9YM/edit Firefox 58]||Firefox 57&lt;br /&gt;
!2017-09-28&lt;br /&gt;
|Firefox 56&lt;br /&gt;
|Firefox 52.4&lt;br /&gt;
|-&lt;br /&gt;
!2017-08-02&lt;br /&gt;
|[https://docs.google.com/document/d/1jeypuqBqEyIh-4qxXT0UnE2aVjetN7uVD8W7L7TbWKg/edit Firefox 57]||Firefox 56&lt;br /&gt;
!2017-08-08&lt;br /&gt;
|Firefox 55&lt;br /&gt;
|Firefox 52.3&lt;br /&gt;
|-&lt;br /&gt;
!2017-06-12&lt;br /&gt;
|Firefox 56||Firefox 55&lt;br /&gt;
!2017-06-13&lt;br /&gt;
|Firefox 54&lt;br /&gt;
|Firefox 52.2&lt;br /&gt;
|-&lt;br /&gt;
!2017-04-18&lt;br /&gt;
|Firefox 55||Firefox 54&lt;br /&gt;
!2017-04-19&lt;br /&gt;
|Firefox 53&lt;br /&gt;
|Firefox 45.9; 52.1&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!Merge Date||Central||Aurora||Beta&lt;br /&gt;
!Release Date||Release||ESR&lt;br /&gt;
|-&lt;br /&gt;
!2017-03-06&lt;br /&gt;
|Firefox 55||Firefox 54||Firefox 53&lt;br /&gt;
!2017-03-07&lt;br /&gt;
|Firefox 52&lt;br /&gt;
|Firefox 45.8; 52.0&lt;br /&gt;
|-&lt;br /&gt;
!2017-01-23&lt;br /&gt;
|Firefox 54||Firefox 53||Firefox 52&lt;br /&gt;
!2017-01-24&lt;br /&gt;
|Firefox 51&lt;br /&gt;
|Firefox 45.7&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
!2016-12-13&lt;br /&gt;
|Firefox 50.1.0&lt;br /&gt;
|Firefox 45.6&lt;br /&gt;
|-&lt;br /&gt;
!2016-11-14&lt;br /&gt;
|Firefox 53||Firefox 52||Firefox 51&lt;br /&gt;
!2016-11-15&lt;br /&gt;
|Firefox 50&lt;br /&gt;
|Firefox 45.5&lt;br /&gt;
|-&lt;br /&gt;
!2016-09-19&lt;br /&gt;
|Firefox 52||Firefox 51||Firefox 50&lt;br /&gt;
!2016-09-20&lt;br /&gt;
|Firefox 49&lt;br /&gt;
|Firefox 45.4&lt;br /&gt;
|-&lt;br /&gt;
!2016-08-01&lt;br /&gt;
|Firefox 51||Firefox 50||Firefox 49&lt;br /&gt;
!2016-08-02&lt;br /&gt;
|Firefox 48&lt;br /&gt;
|Firefox 45.3&lt;br /&gt;
|-&lt;br /&gt;
!2016-06-06&lt;br /&gt;
|Firefox 50||Firefox 49||Firefox 48&lt;br /&gt;
!2016-06-07&lt;br /&gt;
|Firefox 47&lt;br /&gt;
|Firefox 45.2&lt;br /&gt;
|-&lt;br /&gt;
!2016-04-25&lt;br /&gt;
|Firefox 49||Firefox 48||Firefox 47&lt;br /&gt;
!2016-04-26&lt;br /&gt;
|Firefox 46&lt;br /&gt;
|Firefox 38.8; 45.1&lt;br /&gt;
|-&lt;br /&gt;
!2016-03-07&lt;br /&gt;
|Firefox 48||Firefox 47||Firefox 46&lt;br /&gt;
!2016-03-08&lt;br /&gt;
|Firefox 45&lt;br /&gt;
|Firefox 38.7; 45.0&lt;br /&gt;
|-&lt;br /&gt;
!2016-01-25&lt;br /&gt;
|Firefox 47||Firefox 46||Firefox 45&lt;br /&gt;
!2016-01-26&lt;br /&gt;
|Firefox 44&lt;br /&gt;
|Firefox 38.6&lt;br /&gt;
|-&lt;br /&gt;
!2015-12-14&lt;br /&gt;
|Firefox 46||Firefox 45||Firefox 44&lt;br /&gt;
!2015-12-15&lt;br /&gt;
|Firefox 43&lt;br /&gt;
|Firefox 38.5&lt;br /&gt;
|-&lt;br /&gt;
!2015-10-29&lt;br /&gt;
|Firefox 45||Firefox 44||Firefox 43&lt;br /&gt;
!2015-11-03&lt;br /&gt;
|Firefox 42&lt;br /&gt;
|Firefox 38.4&lt;br /&gt;
|-&lt;br /&gt;
!2015-09-21&lt;br /&gt;
|Firefox 44||Firefox 43||Firefox 42&lt;br /&gt;
!2015-09-22&lt;br /&gt;
|Firefox 41&lt;br /&gt;
|Firefox 38.3&lt;br /&gt;
|-&lt;br /&gt;
!2015-08-10&lt;br /&gt;
|Firefox 43||Firefox 42||Firefox 41&lt;br /&gt;
!2015-08-11&lt;br /&gt;
|Firefox 40&lt;br /&gt;
|Firefox 38.2&lt;br /&gt;
|-&lt;br /&gt;
!2015-06-29&lt;br /&gt;
|Firefox 42||Firefox 41||Firefox 40&lt;br /&gt;
!2015-06-30&lt;br /&gt;
|Firefox 39&lt;br /&gt;
|Firefox 31.8; 38.1&lt;br /&gt;
|-&lt;br /&gt;
!&lt;br /&gt;
| || || &lt;br /&gt;
!2015-06-02&lt;br /&gt;
|Firefox 38.0.5&lt;br /&gt;
|-&lt;br /&gt;
!2015-05-11*&lt;br /&gt;
|Firefox 41||Firefox 40||Firefox 39&lt;br /&gt;
!2015-05-12*&lt;br /&gt;
|Firefox 38&lt;br /&gt;
|Firefox 31.7; 38.0&lt;br /&gt;
|-&lt;br /&gt;
!2015-03-30*&lt;br /&gt;
|Firefox 40||Firefox 39||Firefox 38&lt;br /&gt;
!2015-03-31*&lt;br /&gt;
|Firefox 37&lt;br /&gt;
|Firefox 31.6&lt;br /&gt;
|-&lt;br /&gt;
!2015-02-23&lt;br /&gt;
|Firefox 39||Firefox 38||Firefox 37&lt;br /&gt;
!2015-02-24&lt;br /&gt;
|Firefox 36&lt;br /&gt;
|Firefox 31.5&lt;br /&gt;
|-&lt;br /&gt;
!2015-01-12*&lt;br /&gt;
|Firefox 38||Firefox 37||Firefox 36&lt;br /&gt;
!2015-01-13*&lt;br /&gt;
|Firefox 35&lt;br /&gt;
|Firefox 31.4&lt;br /&gt;
|-&lt;br /&gt;
!2014-11-28*&lt;br /&gt;
|Firefox 37||Firefox 36||Firefox 35&lt;br /&gt;
!2014-12-01*&lt;br /&gt;
|Firefox 34&lt;br /&gt;
|Firefox 31.3&lt;br /&gt;
|-&lt;br /&gt;
!2014-10-13 &lt;br /&gt;
|Firefox 36||Firefox 35||Firefox 34&lt;br /&gt;
!2014-10-14&lt;br /&gt;
|Firefox 33&lt;br /&gt;
|Firefox 31.2&lt;br /&gt;
|-&lt;br /&gt;
!2014-09-02*&lt;br /&gt;
|Firefox 35||Firefox 34||Firefox 33&lt;br /&gt;
!2014-09-02&lt;br /&gt;
|Firefox 32&lt;br /&gt;
|Firefox 24.8; 31.1&lt;br /&gt;
|-&lt;br /&gt;
!2014-07-21&lt;br /&gt;
|Firefox 34||Firefox 33||Firefox 32&lt;br /&gt;
!2014-07-22&lt;br /&gt;
|Firefox 31&lt;br /&gt;
|Firefox 24.7; 31.0&lt;br /&gt;
|-&lt;br /&gt;
!2014-06-09&lt;br /&gt;
|Firefox 33||Firefox 32||Firefox 31&lt;br /&gt;
!2014-06-10&lt;br /&gt;
|Firefox 30&lt;br /&gt;
|Firefox 24.6&lt;br /&gt;
|-&lt;br /&gt;
!2014-04-28&lt;br /&gt;
|Firefox 32||Firefox 31||Firefox 30&lt;br /&gt;
!2014-04-29&lt;br /&gt;
|Firefox 29&lt;br /&gt;
|Firefox 24.5&lt;br /&gt;
|-&lt;br /&gt;
!2014-03-17&lt;br /&gt;
|Firefox 31||Firefox 30||Firefox 29&lt;br /&gt;
!2014-03-18&lt;br /&gt;
|Firefox 28&lt;br /&gt;
|Firefox 24.4&lt;br /&gt;
|-&lt;br /&gt;
!2014-02-03*&lt;br /&gt;
|Firefox 30||Firefox 29||Firefox 28&lt;br /&gt;
!2014-02-04*&lt;br /&gt;
|Firefox 27&lt;br /&gt;
|Firefox 24.3&lt;br /&gt;
|-&lt;br /&gt;
!2013-12-09&lt;br /&gt;
|Firefox 29||Firefox 28||Firefox 27&lt;br /&gt;
!2013-12-10&lt;br /&gt;
|Firefox 26&lt;br /&gt;
|Firefox 24.2&lt;br /&gt;
|-&lt;br /&gt;
!2013-10-28&lt;br /&gt;
|Firefox 28||Firefox 27||Firefox 26&lt;br /&gt;
!2013-10-29&lt;br /&gt;
|Firefox 25&lt;br /&gt;
|Firefox 17.0.10; 24.1&lt;br /&gt;
|-&lt;br /&gt;
!2013-09-16&lt;br /&gt;
|Firefox 27||Firefox 26||Firefox 25&lt;br /&gt;
!2013-09-17&lt;br /&gt;
|Firefox 24&lt;br /&gt;
|Firefox 17.0.9; 24.0&lt;br /&gt;
|-&lt;br /&gt;
!2013-08-05&lt;br /&gt;
|Firefox 26||Firefox 25||Firefox 24&lt;br /&gt;
!2013-08-06&lt;br /&gt;
|Firefox 23&lt;br /&gt;
|Firefox 17.0.8&lt;br /&gt;
|-&lt;br /&gt;
!2013-06-24&lt;br /&gt;
|Firefox 25||Firefox 24||Firefox 23&lt;br /&gt;
!2013-06-25&lt;br /&gt;
|Firefox 22&lt;br /&gt;
|Firefox 17.0.7&lt;br /&gt;
|-&lt;br /&gt;
!2013-05-13&lt;br /&gt;
|Firefox 24||Firefox 23||Firefox 22&lt;br /&gt;
!2013-05-14&lt;br /&gt;
|Firefox 21&lt;br /&gt;
|Firefox 17.0.6&lt;br /&gt;
|-&lt;br /&gt;
!2013-04-01&lt;br /&gt;
|Firefox 23||Firefox 22||Firefox 21&lt;br /&gt;
!2013-04-02&lt;br /&gt;
|Firefox 20&lt;br /&gt;
|Firefox 17.0.5&lt;br /&gt;
|-&lt;br /&gt;
!2013-02-19*&lt;br /&gt;
|Firefox 22||Firefox 21||Firefox 20&lt;br /&gt;
!2013-02-19&lt;br /&gt;
|Firefox 19&lt;br /&gt;
|Firefox 17.0.3&lt;br /&gt;
|-&lt;br /&gt;
!2013-01-07&amp;lt;nowiki&amp;gt;*&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
|Firefox 21||Firefox 20||Firefox 19&lt;br /&gt;
!2013-01-08&amp;lt;nowiki&amp;gt;*&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
|Firefox 18&lt;br /&gt;
|Firefox 10.0.12; 17.0.2&lt;br /&gt;
|-&lt;br /&gt;
!2012-11-19&lt;br /&gt;
|Firefox 20||Firefox 19||Firefox 18&lt;br /&gt;
!2012-11-20&lt;br /&gt;
|Firefox 17&lt;br /&gt;
|Firefox 10.0.11; 17.0&lt;br /&gt;
|-&lt;br /&gt;
!2012-10-08&lt;br /&gt;
|Firefox 19&lt;br /&gt;
|Firefox 18&lt;br /&gt;
|Firefox 17&lt;br /&gt;
!2012-10-09&lt;br /&gt;
|Firefox 16&lt;br /&gt;
|Firefox 10.0.8&lt;br /&gt;
|-&lt;br /&gt;
!2012-08-27&lt;br /&gt;
|Firefox 18&lt;br /&gt;
|Firefox 17&lt;br /&gt;
|Firefox 16&lt;br /&gt;
!2012-08-28&lt;br /&gt;
|Firefox 15&lt;br /&gt;
|Firefox 10.0.7&lt;br /&gt;
|-&lt;br /&gt;
!2012-07-16&lt;br /&gt;
|Firefox 17&lt;br /&gt;
|Firefox 16&lt;br /&gt;
|Firefox 15&lt;br /&gt;
!2012-07-17&lt;br /&gt;
|Firefox 14&lt;br /&gt;
|Firefox 10.0.6&lt;br /&gt;
|-&lt;br /&gt;
!2012-06-05&lt;br /&gt;
|Firefox 16&lt;br /&gt;
|Firefox 15&lt;br /&gt;
|Firefox 14&lt;br /&gt;
!2012-06-05&lt;br /&gt;
|Firefox 13&lt;br /&gt;
|Firefox 10.0.5&lt;br /&gt;
|-&lt;br /&gt;
!2012-04-24&lt;br /&gt;
|Firefox 15&lt;br /&gt;
|Firefox 14&lt;br /&gt;
|Firefox 13&lt;br /&gt;
!2012-04-24&lt;br /&gt;
|Firefox 12&lt;br /&gt;
|Firefox 10.0.4&lt;br /&gt;
|-&lt;br /&gt;
!2012-03-13&lt;br /&gt;
|Firefox 14&lt;br /&gt;
|Firefox 13&lt;br /&gt;
|Firefox 12&lt;br /&gt;
!2012-03-13&lt;br /&gt;
|Firefox 11&lt;br /&gt;
|Firefox 10.0.3&lt;br /&gt;
|-&lt;br /&gt;
!2012-01-31&lt;br /&gt;
|Firefox 13&lt;br /&gt;
|Firefox 12&lt;br /&gt;
|Firefox 11&lt;br /&gt;
!2012-01-31&lt;br /&gt;
|Firefox 10&lt;br /&gt;
|Firefox 10.0&lt;br /&gt;
|-&lt;br /&gt;
!2011-12-20&lt;br /&gt;
|Firefox 12&lt;br /&gt;
|Firefox 11&lt;br /&gt;
|Firefox 10&lt;br /&gt;
!2011-12-20&lt;br /&gt;
|Firefox 9&lt;br /&gt;
|-&lt;br /&gt;
!2011-11-08&lt;br /&gt;
|Firefox 11&lt;br /&gt;
|Firefox 10&lt;br /&gt;
|Firefox 9&lt;br /&gt;
!2011-11-08&lt;br /&gt;
|Firefox 8&lt;br /&gt;
|-&lt;br /&gt;
!2011-09-27&lt;br /&gt;
|Firefox 10&lt;br /&gt;
|Firefox 9&lt;br /&gt;
|Firefox 8&lt;br /&gt;
!2011-09-27&lt;br /&gt;
|Firefox 7&lt;br /&gt;
|-&lt;br /&gt;
!2011-08-16&lt;br /&gt;
|Firefox 9&lt;br /&gt;
|Firefox 8&lt;br /&gt;
|Firefox 7&lt;br /&gt;
!2011-08-16&lt;br /&gt;
|Firefox 6&lt;br /&gt;
|-&lt;br /&gt;
!2011-07-05&lt;br /&gt;
|Firefox 8||Firefox 7||Firefox 6&lt;br /&gt;
!&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
!&lt;br /&gt;
| || || &lt;br /&gt;
!2011-06-21&lt;br /&gt;
|Firefox 5&lt;br /&gt;
|-&lt;br /&gt;
!2011-05-24&lt;br /&gt;
|Firefox 7||Firefox 6|| &lt;br /&gt;
|-&lt;br /&gt;
!2011-05-17&lt;br /&gt;
| || ||Firefox 5&lt;br /&gt;
|-&lt;br /&gt;
!2011-04-12&lt;br /&gt;
|Firefox 6||Firefox 5 &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;*&amp;lt;/nowiki&amp;gt;Some release dates and merge dates are rescheduled to avoid conflicts with holidays.&lt;br /&gt;
&lt;br /&gt;
Notes:&lt;br /&gt;
* Four week schedule starting late 2019.&lt;br /&gt;
* Irregular schedule targeting six to eight week intervals, adjusting for holidays, starting 2016.&lt;br /&gt;
* Six week schedule from 2011 to 2015 (with some dates delayed to avoid conflicts with holidays).&lt;br /&gt;
* Firefox 5 was on a slightly different schedule. It spent five weeks each on Aurora and Beta while later releases spent six weeks on each branch.&lt;br /&gt;
&lt;br /&gt;
[[category:Release_Management|R]]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1231013</id>
		<title>Security/Firefox/Security Bug Life Cycle/Security Advisories</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Security_Advisories&amp;diff=1231013"/>
		<updated>2020-09-22T15:36:06Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Assign CVEs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Background ==&lt;br /&gt;
&lt;br /&gt;
This page documents the process to create security advisories for Firefox.  If you&#039;re looking for what the advisories actually are; you want to go to https://www.mozilla.org/en-US/security/advisories/&lt;br /&gt;
&lt;br /&gt;
The goal is that with this document, and the scripts, anyone with the appropriate access can produce advisories. Presently Tom Ritter does Security Advisories, who inherited it from Al Billings.&lt;br /&gt;
&lt;br /&gt;
== Process ==&lt;br /&gt;
&lt;br /&gt;
=== Determine what bugs will get advisories ===&lt;br /&gt;
&lt;br /&gt;
==== Criteria ====&lt;br /&gt;
&lt;br /&gt;
* All client bugs that ship in Firefox reported in Bugzilla with a sec-critical, sec-high, sec-moderate, or sec-low rating are normally included in an advisory. &lt;br /&gt;
* Exceptions are occasionally made for sec-low rated issues, especially internal reports, deemed too minor for advisory inclusion.&lt;br /&gt;
* Internally found memory corruption issues, usually found by developers or members of the fuzzing team, are included in a “roll-up” advisory that is a list of internally found and fixed issues affecting the previous release that were reported by employees or longtime community members. This roll up does not get a detailed advisory but is simply a list of internally found issues.&lt;br /&gt;
* Externally reported security bugs with security ratings always receive an advisory outside of the above parameters if they affected a shipped Firefox release.&lt;br /&gt;
* Internally-found vulnerabilities that are not simple memory corruption usually get a separate advisory and don&#039;t go in the &amp;quot;roll-up&amp;quot;.&lt;br /&gt;
* Vulnerabilities that only existed in Nightly or Beta versions do not need an advisory.&lt;br /&gt;
&lt;br /&gt;
==== Tag them ====&lt;br /&gt;
&lt;br /&gt;
# Query for bugs using the status-firefoxXX (with the release number) flag that are marked as “verified” or “fixed” that also do not have the status-firefoxXY flag for the previous release set to “fixed”, “verified”, “unaffected”, or “disabled” in bugzilla. Additionally, we query on whether the bugs have a “sec-” keyword or are in any security group in Bugzilla. [https://github.com/tomrittervg/secadv/blob/master/gen_queries.py I use a script that generates the bugzilla query for a given version.]  For example &amp;lt;tt&amp;gt;./gen_queries.py 71&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;./gen_queries.py 71 -v&amp;lt;/tt&amp;gt;&lt;br /&gt;
# For each bug, decide on an advisory, marking it with a whiteboard tag. A missing whiteboard tag helps us notice when new fixes land late in the release cycle, and in the future the whiteboard tag is useful for tracking when a vulnerability received an advisory.&lt;br /&gt;
## The whiteboard of the bug is tagged with [adv-mainXX+], [adv-mainXX-], [adv-ESRXX.X+], or [adv-ESRXX.X-] to mark whether an advisory is being created (a ‘+’) or explicitly not being created (a ‘-’) for a given Firefox or Firefox ESR release.&lt;br /&gt;
## [adv-mainXX+r] (and [adv-esrXX+r]) is used to mark bugs that will go into the roll-up advisory.&lt;br /&gt;
&lt;br /&gt;
=== Write the advisories ===&lt;br /&gt;
&lt;br /&gt;
On each bug granted an advisory (excepting the roll-up bugs) - an attachment is added to the bug with a description of &#039;advisory.txt&#039;. The file should contain:&lt;br /&gt;
&lt;br /&gt;
 Title&lt;br /&gt;
 Reporter&lt;br /&gt;
 &lt;br /&gt;
 Description&lt;br /&gt;
&lt;br /&gt;
for example:&lt;br /&gt;
&lt;br /&gt;
 Memory corruption when processing WebRTC messages&lt;br /&gt;
 John Doe&lt;br /&gt;
 &lt;br /&gt;
 When receiving a foobar message, an attacker could specify in incorrect number of gordons, leading to memory corruption.&lt;br /&gt;
&lt;br /&gt;
Advisories are written in the past tense. Typically they&#039;re somewhat vague, but they don&#039;t have to be. Anyone is allowed to write an advisory for a bug if they feel they can do so; however, only one non-obsolete advisory.txt should be attached when the yml creation is performed.&lt;br /&gt;
&lt;br /&gt;
=== Generate and edit the YML File ===&lt;br /&gt;
&lt;br /&gt;
Using [https://github.com/tomrittervg/secadv/blob/master/gen_yml.py this script], generate a first-pass at the .yml file.&lt;br /&gt;
&lt;br /&gt;
Go through and review it. For the first pass, I recommend edits be made directly on the advisory.txt attachments. However, certain edits will not be possible to do there. Specifically: adding (or removing) the description field from the top of the document and editing the list of reporters in the rollup advisory.&lt;br /&gt;
&lt;br /&gt;
=== Review it yourself ===&lt;br /&gt;
&lt;br /&gt;
* We use the past tense when writing about vulnerabilities&lt;br /&gt;
* The titles of bugs do *not* use Title Case, they use Sentence Case.&lt;br /&gt;
* Function names and objects should be enclosed with &amp;amp;lt;code&amp;amp;gt; tags&lt;br /&gt;
* JavaScript not javascript&lt;br /&gt;
* use-after-free not &#039;use after free&#039;&lt;br /&gt;
* Check if there are no community members on the rollup, and if so, remove that bit&lt;br /&gt;
&lt;br /&gt;
=== Assign CVEs ===&lt;br /&gt;
&lt;br /&gt;
Typically done a day or two before the release, assign CVEs to the bugs in bugzilla, and in the yml file.  TODOXXX - this should be automated. (I&#039;m thinking - assign them using a google apps script that interfaces with the spreadsheet, regenerate the yml and diff across any manual edits.)&lt;br /&gt;
&lt;br /&gt;
A noteworthy item is that issues that already have had a CVE assigned - for example because it&#039;s an upstream bug - should get a &#039;&#039;&#039;feed: false&#039;&#039;&#039; in the advisory, after reporter.&lt;br /&gt;
&lt;br /&gt;
A CVE ID from Mitre is assigned from [https://docs.google.com/spreadsheets/d/14rI7jdL23HHJ5VOpVJhV_zc_bp2InrXlKD_vap9oec0/edit our CVE pool] of numbers as an “alias” in Bugzilla and the CVE Pool sheet is updated to include the bug number and title on the listing for the assigned CVE ID.&lt;br /&gt;
&lt;br /&gt;
The CVE ID is unique per bug except for the internal roll-up advisories, which use one CVE ID for a list of bugs. (The CVE assignment process can be complicated because Mitre imposes many rules on CVE assignment and requires communication back in specified data formats when CVEs are assigned. Failure to follow this process can result in Mitre refusing to hand out additional CVE IDs for use.)&lt;br /&gt;
&lt;br /&gt;
==== Oh no, I don&#039;t have enough CVEs! ====&lt;br /&gt;
&lt;br /&gt;
That&#039;s alright.  Assign the issue an id of MFSA-TMP-YEAR-#### where # is a unique incrementing number. Everything will work fine. Later when we have the CVE, go back and assign it.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/mozilla/foundation-security-advisories/commit/3114d01de2f27cdb606d8d07603c2362515104f1 Here&#039;s an example of what it looks like.]&lt;br /&gt;
&lt;br /&gt;
n.b. While that example used MFSA-YEAR-####, that format is actually used for the advisories themselves (so MFSA-2020-0001 was accidentally used to refer both to an individual issue pending a CVE and to all advisories for Firefox 71.) So I&#039;m suggesting the MFSA-TMP prefix to distinguish. We also previously the MFSA-YEAR-# format for individual issues from 2005ish - 2016.&lt;br /&gt;
&lt;br /&gt;
=== Get review ===&lt;br /&gt;
&lt;br /&gt;
Confirm with dveditz ahead of time that he can take a look with a turn-around time of 2-3 days, and then send the yml files to him about a week or 8 days before the release date. Make edits.&lt;br /&gt;
&lt;br /&gt;
Following that round, send the .yml files to the security-group list and solicit more feedback.  &#039;&#039;&#039;This should be done about 4 days before the release.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Release ===&lt;br /&gt;
&lt;br /&gt;
Before releasing ensure that no last-days uplift happened that would be ommitted. The yml files are checked into git and staged in the private https://github.com/mozilla/foundation-security-advisories-private/ repo. Release management will pull from this repo and commit it to the public https://github.com/mozilla/foundation-security-advisories/ repo which will make them live on the site in moments.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1230404</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1230404"/>
		<updated>2020-08-27T18:15:18Z</updated>

		<summary type="html">&lt;p&gt;Tritter: PBM leaks are moderate&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties, see this corresponding page. For details about the bug bounty for the Firefox browser, and specific other applications, see [this page]. For details about the bug bounty for Mozilla Servers and Web Properties, see [this page].&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we believe a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Spoofing of full URL bar or bypass of SSL integrity checks&lt;br /&gt;
* Memory read that results in data being written into an inert container (ie string or image) that is subsequently accessible to content&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Memory corruption leading to a limited or arbitrary memory read or write.&lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of browsing history&lt;br /&gt;
* Overflows resulting in native code execution &lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Private Browsing Mode data leaks&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of browsing history through efficient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Status Codes, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the keywords may instead contain one of the following security status codes.&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Often none of the above severity ratings apply to a bug, because it is not a vulnerability but nonetheless is security sensitive and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is a bit of a catch-all bucket used for bugs that are not exploitable security issues but need to be kept confidential to protect sensitive information.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Bugs submitted by a user where the discussion is dependent on that user&#039;s browsing behavior (and cannot be effectively redacted)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to jit miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example). 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ui-redress || client security issues due to UI Redress attacks, either site-on-site (&amp;quot;clickjacking&amp;quot; and friends) or manipulation of the browser UI to fool users into taking the wrong action. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== secopstype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
secopstype- keywords are assigned to bugs to indicate the type of a client or website vulnerability. If you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:30%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:70%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|secops-cred-leak || Issues relating to credentials leak of Mozilla related accounts&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Hall_of_Fame&amp;diff=1228400</id>
		<title>Security/Firefox/Security Bug Life Cycle/Hall of Fame</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Firefox/Security_Bug_Life_Cycle/Hall_of_Fame&amp;diff=1228400"/>
		<updated>2020-06-23T15:43:19Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Created page with &amp;quot;===== Updating the Client Bug Bounty Hall of Fame =====  The &amp;lt;u&amp;gt;Client&amp;lt;/u&amp;gt; Bug Bounty Hall of Fame is located at https://www.mozilla.org/en-US/security/bug-bounty/hall-of-fame...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===== Updating the Client Bug Bounty Hall of Fame =====&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;u&amp;gt;Client&amp;lt;/u&amp;gt; Bug Bounty Hall of Fame is located at https://www.mozilla.org/en-US/security/bug-bounty/hall-of-fame/  This wiki page is about how to update it.&lt;br /&gt;
&lt;br /&gt;
The HOF lives in https://github.com/mozilla/foundation-security-advisories and the script to update it is there as well.  Grab that repo.&lt;br /&gt;
&lt;br /&gt;
Using a bugzilla API key, run &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;./update_hof.py -a &amp;lt;apikey&amp;gt; -y &amp;lt;year&amp;gt; -q &amp;lt;quarter&amp;gt; -f bug-bounty-hof/client.yml&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It will remind you that you need to assign hof+ flags to bugs that should receive it. Kill the script, copy that link, go assign the flags, and then come back and re-run it.&lt;br /&gt;
&lt;br /&gt;
This will take a long time, because it needs to look at every security bug. When it&#039;s done, it will:&lt;br /&gt;
&lt;br /&gt;
# Prepend the new credit entries to the client.yml file&lt;br /&gt;
# Edit the update_hof.py script to contain any new credit mappings that should be present&lt;br /&gt;
# Produce a debuglog.&amp;amp;lt;timestamp&amp;gt;.log file.&lt;br /&gt;
&lt;br /&gt;
Next we&#039;re going to double check things.  You should:&lt;br /&gt;
* git diff the client.yml file looking for any unusual entries (e.g. &#039;Anonymous&#039; or shared credit entries)&lt;br /&gt;
* &amp;lt;tt&amp;gt;grep -v range debuglog.&amp;amp;lt;timestamp&amp;gt;.log&amp;lt;/tt&amp;gt; to look at the bugs that resulted in credit entries. This allows you to map credit entries from the yml file to bugs for checking.&lt;br /&gt;
* Review these bugs. &lt;br /&gt;
** If you gave a hof+ flag to a bug, do you see it here? (It should have a &#039;bounty-&#039; indicator.) &lt;br /&gt;
** Do any of these bugs have a special credit field from the bug? A shared credit?&lt;br /&gt;
** Are any of them marked &amp;quot;do not publish&amp;quot;? Double check they shouldn&#039;t be published.&lt;br /&gt;
&lt;br /&gt;
After that, commit it to a branch, push it (you can push the branch to the public repo), and submit a pull request for Dan or Tom to review.&lt;br /&gt;
&lt;br /&gt;
(If you want, you can run &amp;lt;tt&amp;gt;./update_hof.py --sort-credit-entries&amp;lt;/tt&amp;gt; in a second commit and copy-paste replace the existing variables in the script to sort them nicely.)&lt;br /&gt;
&lt;br /&gt;
===== Special Note =====&lt;br /&gt;
&lt;br /&gt;
For really weird implementation purposes, in order to run this script, you need access to [https://bugzilla.mozilla.org/show_bug.cgi?id=1622495 Bug 1622495]. If you can&#039;t view that bug, you&#039;re not going to be able to run the script.&lt;br /&gt;
&lt;br /&gt;
===== Historical Note =====&lt;br /&gt;
&lt;br /&gt;
In early 2020 Tom re-generated the entire Client Hall of Fame from 2010 to 2019. It involved a lot of manual work, and porting names across that disappeared. There is a &amp;lt;tt&amp;gt;doitall&amp;lt;/tt&amp;gt; option buried in the script. You should not use it. It will not produce a Hall of Fame that is identical to the one present - a lot of manual touch-ups had to be made. Going forward we should update it a quarter at a time.&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=BMO/Bot_Registry&amp;diff=1225470</id>
		<title>BMO/Bot Registry</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=BMO/Bot_Registry&amp;diff=1225470"/>
		<updated>2020-03-26T02:40:24Z</updated>

		<summary type="html">&lt;p&gt;Tritter: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Some times you want a BMO account that is not a real person.&lt;br /&gt;
That&#039;s okay -- in fact it is a good security measure!&lt;br /&gt;
&lt;br /&gt;
However this comes with some problems -- if we (the bmo admins) can&#039;t tell who owns a bot,&lt;br /&gt;
and we have to make a decision that might break we have no way of informing the owner except&lt;br /&gt;
to break it and wait to hear back. This list below is by no means mandatory, but if you fill it out,&lt;br /&gt;
we can help avoid future breakages!&lt;br /&gt;
&lt;br /&gt;
If you include a link to the repo, things can be even smoother.&lt;br /&gt;
&lt;br /&gt;
If your bot misbehaves, we can tell you about it rather than just blocking it. &lt;br /&gt;
&lt;br /&gt;
== Bot Requirements ==&lt;br /&gt;
&lt;br /&gt;
All bot and automation users:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;must&#039;&#039;&#039; have a `bots.tld` bugmail by 2020-06-30&lt;br /&gt;
* &#039;&#039;&#039;must&#039;&#039;&#039; use the REST api by 2020-06-30&lt;br /&gt;
* if they have elevated privileges must use a API key by 2020-06-30&lt;br /&gt;
* &#039;&#039;&#039;should&#039;&#039;&#039; be listed in this registry &#039;&#039;unless&#039;&#039; there is a business reason not to list them publicly&lt;br /&gt;
* when they modify bugs, they &#039;&#039;&#039;should&#039;&#039;&#039; leave a comment that the bug has been modified by a bot unless it does not make sense to&lt;br /&gt;
&lt;br /&gt;
== Bot List ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Bot Bugmail !! Owner Bugmail !! API (xmlrpc, jsonrpc, bzapi, or rest) !! Token or API Key!! Repo&lt;br /&gt;
|-&lt;br /&gt;
| pulsebot@bots.tld || mh+mozilla@glandium.org || rest || api-key || https://github.com/glandium/pulsebot/&lt;br /&gt;
|-&lt;br /&gt;
| treeherderbugbot@gmail.com || [https://lists.mozilla.org/listinfo/tools-treeherder tools-treeherder] || xmlrpc || Username/password || [https://github.com/github/github-services/blob/master/lib/services/bugzilla.rb GitHub&#039;s Bugzilla integration]&lt;br /&gt;
|-&lt;br /&gt;
| intermittent-bug-filer@mozilla.bugs || [https://lists.mozilla.org/listinfo/tools-treeherder tools-treeherder] || rest || api-key || https://github.com/mozilla/treeherder&lt;br /&gt;
|-&lt;br /&gt;
| orangefactor@bots.tld   || auto-tools@moco || rest || api-key || https://hg.mozilla.org/automation/orangefactor/&lt;br /&gt;
|-&lt;br /&gt;
| webops-kanban@mozilla.bugs || atoll || Unknown || Token || &lt;br /&gt;
|-&lt;br /&gt;
| mozilla+bugcloser@davedash.com || Unknown || Unknown || Token (github) || Unknown&lt;br /&gt;
|-&lt;br /&gt;
| release-mgmt-analysis@mozilla.com || mcastelluccio@mozilla.com || rest || api-key || https://github.com/mozilla/bugbug/&lt;br /&gt;
|-&lt;br /&gt;
| release-mgmt-account-bot@mozilla.tld || cdenizet@mozilla.com || rest || api-key || https://github.com/mozilla/relman-auto-nag/&lt;br /&gt;
|-&lt;br /&gt;
| slaveapi@mozilla.releng.tld || release@mozilla.com || Unknown || Unknown || https://github.com/mozilla/build-slaveapi&lt;br /&gt;
|-&lt;br /&gt;
| flow2bugs@netops.bugs || unknown || Unknown || Unknown || Unknown&lt;br /&gt;
|- &lt;br /&gt;
| webcompat-bugs@mozilla.bugs || miket@mozilla.com || rest || api-key || TBD&lt;br /&gt;
|-&lt;br /&gt;
| pulgasaur@mozilla.bugs || peterbe@mozilla.com || rest || api-key || https://github.com/mozilla/github-bugzilla-pr-linker&lt;br /&gt;
|-&lt;br /&gt;
| moc-queue-bot@mozilla.bugs || moc@mozilla.com || rest || api-key || git-internal/puppet/modules/moc_bug_queuemon&lt;br /&gt;
|-&lt;br /&gt;
| omphalos@mozilla.bugs || mgoodwin@mozilla.com || rest || api-key || https://github.com/mozilla/OneCRL-Tools&lt;br /&gt;
|-&lt;br /&gt;
| bug-husbandry-bot@mozilla.bugs || ehumphries@moco || rest || api-key || [[Bugmasters/Projects/Bug_Handling/Bug_Husbandry]]&lt;br /&gt;
|-&lt;br /&gt;
| reviewbot@mozilla.com || babadie@mozilla.com || rest || api-key; phabricator-token || https://github.com/mozilla/code-review&lt;br /&gt;
|-&lt;br /&gt;
| upliftbot@mozilla.com || babadie@mozilla.com || rest || api-key; phabricator-token || https://github.com/mozilla/release-services/tree/master/src/uplift/bot&lt;br /&gt;
|-&lt;br /&gt;
| wptsync@mozilla.bugs || jgraham@mozilla.com || rest || api-key || https://github.com/mozilla/wpt-sync&lt;br /&gt;
|-&lt;br /&gt;
| release+phabricator@mozilla.com || sfraser@mozilla.com || rest || api-key || Unknown / Phabricator use&lt;br /&gt;
|-&lt;br /&gt;
| foxsec-pytest@mozilla.com || abahnken@mozilla.com || rest || api-key || https://github.com/mozilla-services/pytest-services&lt;br /&gt;
|-&lt;br /&gt;
| experimenter@mozilla.com || jbuckley@mozilla.com || rest || api-key || https://github.com/mozilla/experimenter&lt;br /&gt;
|-&lt;br /&gt;
| bugmail@firebot.glob.uno || glob@mozilla.com || rest || anon || https://github.com/globau/firebot&lt;br /&gt;
|-&lt;br /&gt;
| bteam-dashboard@bmo.tld || glob@mozilla.com || rest || api-key || https://github.com/globau/bteam-dashboard&lt;br /&gt;
|-&lt;br /&gt;
| conduit-dashboard@bmo.tld || glob@mozilla.com || rest || api-key || https://github.com/globau/bteam-dashboard/tree/conduit&lt;br /&gt;
|- &lt;br /&gt;
| jitbugs@mozilla.bugs || mgaudet@mozilla.com || n/a || n/a || Watchable Account for JavaScript JIT Bug Reviews&lt;br /&gt;
|-&lt;br /&gt;
| relops-bug-generator@mozilla.com || jwatkins@mozilla.com || n/a || n/a || Automated Bug Generation for RelOps&lt;br /&gt;
|-&lt;br /&gt;
| mozilla-apprentice@mcc.id.au || cam@mcc.id.au || rest || api-key || https://github.com/heycam/wg-tracker&lt;br /&gt;
|-&lt;br /&gt;
| security-baseline@bots.tld || sbennetts@mozilla.com || rest || api-key || https://github.com/mozilla-services/foxsec&lt;br /&gt;
|-&lt;br /&gt;
| hlundberg@bots.tld || sstruble@moco || rest || api-key || n/a&lt;br /&gt;
|-&lt;br /&gt;
| n/a || tom@mozilla.com || rest || api-key || private Google Sheets scripts&lt;br /&gt;
|-&lt;br /&gt;
| n/a || ktaeleman@mozilla.com || rest || anon || https://github.com/FirefoxGraphics/triage&lt;br /&gt;
|-&lt;br /&gt;
| n/a || helfi92@gmail.com || rest || api-key || https://github.com/mozilla-frontend-infra/bugzilla-graphql-gateway&lt;br /&gt;
|-&lt;br /&gt;
| secops-fraud@mozilla.com || abahnken@mozilla.com || rest || api-key || https://github.com/mozilla-services/foxsec-pipeline/tree/master/contrib/bugzilla-alert-manager&lt;br /&gt;
|-&lt;br /&gt;
| updatebot@bots.tld || tom@mozilla.com || rest || api-key || https://github.com/mozilla-services/updatebot&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security/Fingerprinting&amp;diff=1225048</id>
		<title>Security/Fingerprinting</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security/Fingerprinting&amp;diff=1225048"/>
		<updated>2020-03-13T04:00:12Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Terse List */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Cross-Origin Fingerprinting Unlinkability ==&lt;br /&gt;
The anti-fingerprinting project is part of the Tor Uplift project. &amp;lt;br&amp;gt;&lt;br /&gt;
Its goal is to build up the same level of fingerprinting resistance as the Tor Browser in Firefox. &amp;lt;br&amp;gt;&lt;br /&gt;
Refer to the design and implementation document of the Tor Browser: &amp;lt;br&amp;gt;&lt;br /&gt;
https://www.torproject.org/projects/torbrowser/design/#fingerprinting-linkability&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&lt;br /&gt;
This page contains technical details about the things we do in Resist fingerprinting mode. It is up to date as of March 7, 2018&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Terse List ===&lt;br /&gt;
&lt;br /&gt;
* Complicated (see below)&lt;br /&gt;
** Canvas image extraction is blocked&lt;br /&gt;
** Absolute Screen Coordinates are obscured&lt;br /&gt;
** Window Dimensions are rounded to a multiple of 200x100, and a warning is shown when maximizing&lt;br /&gt;
** We only allow specific system fonts to be used, and we ship them to the user using kinto&lt;br /&gt;
&lt;br /&gt;
* Non-Trivial (see below)&lt;br /&gt;
** The performance API is mostly disabled&lt;br /&gt;
** Time Precision is reduced to 100ms, with up to 100ms of jitter&lt;br /&gt;
** mozAddonManager may be blocked {{Bug|1384330}}&lt;br /&gt;
** Media Devices are spoofed {{Bug|1372073}}&lt;br /&gt;
** WebGL is limited {{Bug|1217290}}&lt;br /&gt;
** The Keyboard Layout is spoofed &lt;br /&gt;
** The Locale is spoofed to en-US&lt;br /&gt;
** The Date Input Field and Date Picker Panel are spoofed to en-US {{Bug|1492587}}&lt;br /&gt;
** If you customize the preferred language list (Accept-Language), you will be warned {{Bug|1039069}}&lt;br /&gt;
** System Media Queries will never match {{Bug|1479240}}&lt;br /&gt;
** The Pointer Event is spoofed {{Bug|1363508}} and also pointerEvent.pointerid {{Bug|1492766}}&lt;br /&gt;
&lt;br /&gt;
* Trivial&lt;br /&gt;
** The browser version is reported to be the most recent ESR version (but the OS is not spoofed)&lt;br /&gt;
** Timezone is spoofed to &#039;UTC&#039;&lt;br /&gt;
** The gamepad API is disabled&lt;br /&gt;
** All device sensors are disabled&lt;br /&gt;
** The WebSpeech API is disabled&lt;br /&gt;
** WEBGL_debug_renderer_info extension is disabled {{Bug|1337157}}&lt;br /&gt;
** navigator.hardwareConcurrency is spoofed to 2&lt;br /&gt;
** Site-specific zoom is disabled {{Bug|1369357}}&lt;br /&gt;
** MediaError.message is restricted to a whitelist {{Bug|1354633}}&lt;br /&gt;
** The Network Information API reports an &#039;Unknown&#039; connection type, and the ontypechange event is suppressed {{Bug|1372072}}&lt;br /&gt;
** The Media Statistics API will report calculated numbers not reflecting reality {{Bug|1369309}}&lt;br /&gt;
** Web Extensions are able to toggle privacy.resistFingerprinting&lt;br /&gt;
** Geolocation is disabled {{Bug|1372069}} - but this will be reverted {{Bug|1441295}}&lt;br /&gt;
** screen.orientation.type is spoofed as &#039;landscape-primary&#039; and screen.orientation.angle is spoofed to &#039;0&#039; {{Bug|1281949}} but also {{Bug|1433815}}&lt;br /&gt;
** navigator.plugins and navigator.mimeTypes are reported as empty {{Bug|1281963}} and {{Bug|1324044}}&lt;br /&gt;
** prefers-reduced-motion always returns false {{Bug|1478158}}&lt;br /&gt;
** AudioContext OutputLatency is spoofed {{Bug|1564422}}&lt;br /&gt;
** prefers-color-scheme always says light mode.&lt;br /&gt;
&lt;br /&gt;
=== Details ===&lt;br /&gt;
&lt;br /&gt;
==== Canvas Fingerprinting Detection ====&lt;br /&gt;
&lt;br /&gt;
==== Absolute Screen Coordinates ====&lt;br /&gt;
&lt;br /&gt;
{{Bug|1382499}}&lt;br /&gt;
&lt;br /&gt;
==== Window Dimensions ====&lt;br /&gt;
&lt;br /&gt;
{{Bug|1330882}}&lt;br /&gt;
&lt;br /&gt;
==== Fonts ====&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
==== Performance API ====&lt;br /&gt;
&lt;br /&gt;
Most performance APIs are disabled, but not all of them.  TODO more details.&lt;br /&gt;
&lt;br /&gt;
==== Time Precision Reduction ====&lt;br /&gt;
&lt;br /&gt;
TODO more details&lt;br /&gt;
&lt;br /&gt;
* animation API - {{Bug|1382545}}&lt;br /&gt;
&lt;br /&gt;
==== mozAddonManager ====&lt;br /&gt;
&lt;br /&gt;
window.navigator.mozAddonManager is only exposed to addons.mozilla.org. In Resist Fingerprinting mode, we keep it exposed; however if the additional preference &#039;privacy.resistFingerprinting.block_mozAddonManager&#039; is true, then it is not exposed to AMO&lt;br /&gt;
&lt;br /&gt;
==== Media Devices ====&lt;br /&gt;
&lt;br /&gt;
When RFP is enabled, enumerateDevices reports that the user has one camera (named &#039;Internal Camera&#039;) and one microphone (named &#039;Internal Microphone&#039;). The devicechange event is also suppressed.&lt;br /&gt;
&lt;br /&gt;
==== WebGL ====&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
==== Keyboard Layout ====&lt;br /&gt;
&lt;br /&gt;
{{Bug|1222285}}, {{Bug|1438795}}, {{Bug|1409974}}, {{Bug|1433592}}&lt;br /&gt;
&lt;br /&gt;
==== Locale ====&lt;br /&gt;
&lt;br /&gt;
{{Bug|867501}}, {{Bug|1330892}}, {{Bug|1369330}}, {{Bug|1409973}}&lt;br /&gt;
&lt;br /&gt;
==== Accept-Languages ====&lt;br /&gt;
&lt;br /&gt;
== Project Schedule ==&lt;br /&gt;
* Complete the implementation of MVP in &#039;&#039;&#039;Firefox 57 (2017-09-20)&#039;&#039;&#039;&lt;br /&gt;
** This is being tracked by three milestones M1, M2, and M3&lt;br /&gt;
* Feature stabilization and refinement in &#039;&#039;&#039;Firefox 58 (2017-11-13)&#039;&#039;&#039;&lt;br /&gt;
** Perform integration test to identify regressions and Web compatibility issues&lt;br /&gt;
** Perform tests to verify the effectiveness of fingerprinting protection&lt;br /&gt;
** Fix regressions and any other issues&lt;br /&gt;
** Figure out the product strategy of Firefox to roll out this functionality&lt;br /&gt;
* Ship the feature in &#039;&#039;&#039;Firefox 59 (2018-01-15)&lt;br /&gt;
** Tor Browser will be using Firefox ESR 59&lt;br /&gt;
&lt;br /&gt;
== Bug Tracking ==&lt;br /&gt;
All fingerprinting bugs are being tracked under the meta bug: &amp;lt;br&amp;gt;&lt;br /&gt;
{{Bug|1329996}} - [META] Support anti-fingerprinting protection&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Priority Definition&#039;&#039;&#039;&lt;br /&gt;
* P1: MVP (Minimum Viable Product)&lt;br /&gt;
* P2: Nice to Have&lt;br /&gt;
* P3: Backlog&lt;br /&gt;
* Any bug which is marked as [fp:m1-3] in the Whiteboard is also MVP, regardless of its Priority&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Whiteboard Definition&#039;&#039;&#039;&lt;br /&gt;
* [fingerprinting]: Indicate this is a fingerprinting bug&lt;br /&gt;
* [fp:m1]: Target milestone is M1 (2017-06-12 Firefox 55)&lt;br /&gt;
* [fp:m2]: Target milestone is M2 (2017-08-02 Firefox 56)&lt;br /&gt;
* [fp:m3]: Target milestone is M3 (2017-09-20 Firefox 57)&lt;br /&gt;
* [fp-backlog]: Backlog bugs&lt;br /&gt;
&lt;br /&gt;
== Dashboard ==&lt;br /&gt;
=== MVP: M1 Bugs List (2017-06-12 Firefox 55) ===&lt;br /&gt;
&amp;lt;bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;NEW&amp;quot;, &amp;quot;ASSIGNED&amp;quot;, &amp;quot;REOPENED&amp;quot;, &amp;quot;RESOLVED&amp;quot;, &amp;quot;VERIFIED&amp;quot;], &lt;br /&gt;
        &amp;quot;whiteboard&amp;quot;:[&amp;quot;fp:m1&amp;quot;],&lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, status, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;status, assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/bugzilla&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== MVP: M2 Bugs List (2017-08-07 Firefox 56) ===&lt;br /&gt;
&amp;lt;bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;NEW&amp;quot;, &amp;quot;ASSIGNED&amp;quot;, &amp;quot;REOPENED&amp;quot;, &amp;quot;RESOLVED&amp;quot;, &amp;quot;VERIFIED&amp;quot;], &lt;br /&gt;
        &amp;quot;whiteboard&amp;quot;:[&amp;quot;fp:m2&amp;quot;],&lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, status, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;status, assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/bugzilla&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== MVP: M3 Bugs List (2017-09-25 Firefox 57) ===&lt;br /&gt;
&amp;lt;bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;NEW&amp;quot;, &amp;quot;ASSIGNED&amp;quot;, &amp;quot;REOPENED&amp;quot;, &amp;quot;RESOLVED&amp;quot;, &amp;quot;VERIFIED&amp;quot;], &lt;br /&gt;
        &amp;quot;whiteboard&amp;quot;:[&amp;quot;fp:m3&amp;quot;],&lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, status, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;status, assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/bugzilla&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== MVP: Bugs To Be Triaged ===&lt;br /&gt;
The following bugs are MVP bugs which are not specified priority yet.&lt;br /&gt;
&amp;lt;bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;blocks&amp;quot;:&amp;quot;1329996&amp;quot;,&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;NEW&amp;quot;, &amp;quot;ASSIGNED&amp;quot;, &amp;quot;REOPENED&amp;quot;, &amp;quot;RESOLVED&amp;quot;, &amp;quot;VERIFIED&amp;quot;],&lt;br /&gt;
        &amp;quot;priority&amp;quot;:[&amp;quot;--&amp;quot;],&lt;br /&gt;
        &amp;quot;whiteboard&amp;quot;:[&amp;quot;fp:m&amp;quot;],&lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, status, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;status, assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/bugzilla&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Fingerprinting P2 Bugs List ===&lt;br /&gt;
&amp;lt;disabled-bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;blocks&amp;quot;:&amp;quot;1329996&amp;quot;,&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;NEW&amp;quot;, &amp;quot;ASSIGNED&amp;quot;, &amp;quot;REOPENED&amp;quot;, &amp;quot;RESOLVED&amp;quot;, &amp;quot;VERIFIED&amp;quot;], &lt;br /&gt;
        &amp;quot;priority&amp;quot;:[&amp;quot;P2&amp;quot;], &lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, status, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;status, assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/disabled-bugzilla&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Fingerprinting P3-P5 Bugs List ===&lt;br /&gt;
&amp;lt;disabled-bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;blocks&amp;quot;:&amp;quot;1329996&amp;quot;,&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;NEW&amp;quot;, &amp;quot;ASSIGNED&amp;quot;, &amp;quot;REOPENED&amp;quot;, &amp;quot;RESOLVED&amp;quot;, &amp;quot;VERIFIED&amp;quot;], &lt;br /&gt;
        &amp;quot;priority&amp;quot;:[&amp;quot;P3&amp;quot;, &amp;quot;P4&amp;quot;, &amp;quot;P5&amp;quot;, &amp;quot;--&amp;quot;], &lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, status, priority, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;status, assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/disabled-bugzilla&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Fingerprinting Breakage ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;NEW&amp;quot;, &amp;quot;ASSIGNED&amp;quot;, &amp;quot;REOPENED&amp;quot;, &amp;quot;RESOLVED&amp;quot;, &amp;quot;VERIFIED&amp;quot;],&lt;br /&gt;
        &amp;quot;whiteboard&amp;quot;:[&amp;quot;fingerprinting-breakage&amp;quot;],&lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, status, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;status, assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/bugzilla&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All Open Tagged Fingerprinting Bugs ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;disabled-bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;NEW&amp;quot;, &amp;quot;ASSIGNED&amp;quot;, &amp;quot;REOPENED&amp;quot;],&lt;br /&gt;
        &amp;quot;whiteboard&amp;quot;:[&amp;quot;fingerprinting&amp;quot;],&lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, status, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;status, assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/disabled-bugzilla&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Fingerprinting Resolved Bugs ===&lt;br /&gt;
&amp;lt;disabled-bugzilla&amp;gt;&lt;br /&gt;
    {&lt;br /&gt;
        &amp;quot;blocks&amp;quot;:&amp;quot;1329996&amp;quot;,&lt;br /&gt;
        &amp;quot;status&amp;quot;:[&amp;quot;RESOLVED&amp;quot;, &amp;quot;VERIFIED&amp;quot;], &lt;br /&gt;
        &amp;quot;include_fields&amp;quot;: &amp;quot;id, summary, priority, product, component, assigned_to, depends_on, whiteboard&amp;quot;,&lt;br /&gt;
        &amp;quot;order&amp;quot;: &amp;quot;assigned_to&amp;quot;&lt;br /&gt;
    }&lt;br /&gt;
&amp;lt;/disabled-bugzilla&amp;gt;&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings&amp;diff=1224464</id>
		<title>Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings&amp;diff=1224464"/>
		<updated>2020-03-02T18:41:00Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Point to sub-pages.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Security Severity Ratings page has been split between the [https://wiki.mozilla.org/Security_Severity_Ratings/Web Web Severity Ratings] for Mozilla Websites, Services, and Servers and the [https://wiki.mozilla.org/Security_Severity_Ratings/Client Client Severity Ratings] for Mozilla Applications including Firefox, Fenix, and related.&lt;br /&gt;
&lt;br /&gt;
* [https://wiki.mozilla.org/Security_Severity_Ratings/Web Web Severity Ratings]&lt;br /&gt;
* [https://wiki.mozilla.org/Security_Severity_Ratings/Client Client Severity Ratings]&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224463</id>
		<title>User:Tritter/Working/Web Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224463"/>
		<updated>2020-03-02T18:36:52Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Replaced content with &amp;quot;Published to https://wiki.mozilla.org/Security_Severity_Ratings/Web&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Published to https://wiki.mozilla.org/Security_Severity_Ratings/Web&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224462</id>
		<title>User:Tritter/Working/Client Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224462"/>
		<updated>2020-03-02T18:36:45Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Replaced content with &amp;quot;Published to https://wiki.mozilla.org/Security_Severity_Ratings/Client&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Published to https://wiki.mozilla.org/Security_Severity_Ratings/Client&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Web&amp;diff=1224461</id>
		<title>Security Severity Ratings/Web</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Web&amp;diff=1224461"/>
		<updated>2020-03-02T18:36:23Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Created page with &amp;quot;__TOC__  ==Severity Ratings ==  In all cases, the severity of server and web application bugs is dependent on the [https://www.mozilla.org/en-US/security/bug-bounty/web-eligib...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
In all cases, the severity of server and web application bugs is dependent on the [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/ critically of the service] and the value of the data that could be compromised. Thus while the table below provides &amp;lt;i&amp;gt;very&amp;lt;/i&amp;gt; broad guidelines, they cannot be directly used to determine the severity of a bug absent the consideration of the affected service. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to users of our services. Often-times there is no difference technically between a sec-critical and a sec-high, the difference is purely related to to the classification of the site and the risk to users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Remote Code Execution on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical] or [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#core-sites Core] site.&lt;br /&gt;
* Authentication Flaws (which lead to account compromise)&lt;br /&gt;
* Session Management Flaws (which lead to account compromise) &lt;br /&gt;
* Stored Cross-site Scripting (XSS)&lt;br /&gt;
* Reflected XSS on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical Site]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: Typically, sec-high issues are exploitable web vulnerabilities that can lead to the targeted compromise of a small number of users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Reflected XSS on a non Critical or Core site&lt;br /&gt;
* CSRF&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose the user or organization to immediate risk. The vulnerability combined with another moderate vulnerability could result in an attack of high or critical severity (aka stepping stone). The lack of standard defense in depth techniques and security controls.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* XSS blocked by CSP&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Missing Additional Security Controls (x-frame options, SECURE/HTTPOnly flags, etc)&lt;br /&gt;
* Error Handling Issues &lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Minor security vulnerabilities such as leaks or spoofs of non-sensitive information. Missing best practice security controls &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Lack of proper input validation (not resulting in XSS or injection)&lt;br /&gt;
* Content spoofing (non-html) &lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
=== wsectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
wsectype- keywords are assigned to bugs to indicate the type of a vulnerability. These should be assigned to every vulnerability. If you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:30%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:70%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|wsec-applogic || Issues relating to the application logic&lt;br /&gt;
|-&lt;br /&gt;
|wsec-appmisconfig || Application misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authentication || Website or server authentication security issues (lockouts, password policy, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authorization || Web/server authorization security issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-automation-attack || Application is vulnerable to automation attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-bruteforce || Application is vulnerable to bruteforce attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-client || Web client side related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-cookie || Cookie related errors (HTTPOnly / Secure Flag, incorrect domain / path)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crossdomain || Issue such as x-frame-options, crossdomain.xml, cross site sharing settings&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crypto || Crypto related items such as password hashing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-csrf || Cross-Site Request Forgery (CSRF) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|wsec-deplib || Known vulnerability in a dependant library&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dir-index || Directory index incorrectly accessible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-disclosure || Disclosure of sensitive data, personal information, etc from a web service&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dos || Used to denote web server Denial of Service bugs. For similar bugs in client software please use csectype-dos instead.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-email || Email related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-errorhandling || Any error handling issue&lt;br /&gt;
|-&lt;br /&gt;
|wsec-fileinclusion || Local or remote file inclusion possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-headers || Missing or misconfigured security headers&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http || Application is incorrectly accessible over http&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http-header-inject || Application vulnerable to header injection attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-impersonation || Impersonation / Spoofing attacks (UI Redress, etc) 	&lt;br /&gt;
|-&lt;br /&gt;
|wsec-injection || Injection attacks other than SQLi or XSS &lt;br /&gt;
|-&lt;br /&gt;
|wsec-input || Failure to perform input validation. Most often you will probably use the xss tag instead&lt;br /&gt;
|-&lt;br /&gt;
|wsec-logging || Logging issues such as requests for CEF log points.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-nullbyte || Application is vulnerable to null byte injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-objref || Insecure direct object references used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-oscmd || Application is vulnerable to Operating System command injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-other || Web/server security issues that don&#039;t fit into other categories&lt;br /&gt;
|-&lt;br /&gt;
|wsec-overflow || Application is vulnerable to overflow attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-redirect || Open redirect vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-selfxss || Self cross site scripting&lt;br /&gt;
|-&lt;br /&gt;
|wsec-serialization || Insecure deserialization&lt;br /&gt;
|-&lt;br /&gt;
|wsec-servermisconfig || Server misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-session || Issues related to sesson management (Session fixation, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-sqli || SQL Injection &lt;br /&gt;
|-&lt;br /&gt;
|wsec-ssrf || Server Side Request Forgery (SSRF) bugs in server products. CWE-918&lt;br /&gt;
|-&lt;br /&gt;
|wsec-takeover || Domain vulnerable to takeover&lt;br /&gt;
|-&lt;br /&gt;
|wsec-tls || TLS related issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-traversal || Directory traversal possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-weakpasswd || Weak passwords can be used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xml || XML related vulnerability including XML External Entity (XXE) processing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xss || Cross-Site Scripting (XSS) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
! Flags&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:15%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:25%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:60%&amp;quot; | Settings&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1224460</id>
		<title>Security Severity Ratings/Client</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Security_Severity_Ratings/Client&amp;diff=1224460"/>
		<updated>2020-03-02T18:36:13Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Created page with &amp;quot;__TOC__  The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties,...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties, see this corresponding page. For details about the bug bounty for the Firefox browser, and specific other applications, see [this page]. For details about the bug bounty for Mozilla Servers and Web Properties, see [this page].&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we beleive a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Spoofing of full URL bar or bypass of SSL integrity checks&lt;br /&gt;
* Memory read that results in data being written into an inert container (ie string or image) that is subsequently accessible to content&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Memory corruption leading to a limited or arbitrary memory read or write.&lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of browsing history&lt;br /&gt;
* Overflows resulting in native code execution &lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of browsing history through effecient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Status Codes, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the keywords may instead contain one of the following security status codes.&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Often none of the above severity ratings apply to a bug, because it is not a vulnerability but nonetheless is security sensitive and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is a bit of a catch-all bucket used for bugs that are not exploitable security issues but need to be kept confidential to protect sensitive information.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Bugs submitted by a user where the discussion is dependent on that user&#039;s browsing behavior (and cannot be effectively redacted)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to jit miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example). 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ui-redress || client security issues due to UI Redress attacks, either site-on-site (&amp;quot;clickjacking&amp;quot; and friends) or manipulation of the browser UI to fool users into taking the wrong action. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224043</id>
		<title>User:Tritter/Working/Client Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224043"/>
		<updated>2020-02-20T18:41:27Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Severity Ratings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties, see this corresponding page. For details about the bug bounty for the Firefox browser, and specific other applications, see [this page]. For details about the bug bounty for Mozilla Servers and Web Properties, see [this page].&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we beleive a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Spoofing of full URL bar or bypass of SSL integrity checks&lt;br /&gt;
* Memory read that results in data being written into an inert container (ie string or image) that is subsequently accessible to content&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Memory corruption leading to a limited or arbitrary memory read or write.&lt;br /&gt;
* Sandbox escapes&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of browsing history&lt;br /&gt;
* Overflows resulting in native code execution &lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of browsing history through effecient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Status Codes, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the keywords may instead contain one of the following security status codes.&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Often none of the above severity ratings apply to a bug, because it is not a vulnerability but nonetheless is security sensitive and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is a bit of a catch-all bucket used for bugs that are not exploitable security issues but need to be kept confidential to protect sensitive information.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Bugs submitted by a user where the discussion is dependent on that user&#039;s browsing behavior (and cannot be effectively redacted)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to jit miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example). 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ui-redress || client security issues due to UI Redress attacks, either site-on-site (&amp;quot;clickjacking&amp;quot; and friends) or manipulation of the browser UI to fool users into taking the wrong action. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224026</id>
		<title>User:Tritter/Working/Client Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224026"/>
		<updated>2020-02-20T15:19:37Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Severity Ratings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties, see this corresponding page. For details about the bug bounty for the Firefox browser, and specific other applications, see [this page]. For details about the bug bounty for Mozilla Servers and Web Properties, see [this page].&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we beleive a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Spoofing of full URL bar or bypass of SSL integrity checks&lt;br /&gt;
* Memory read that results in data being written into an inert container (ie string or image) that is subsequently accessible to content&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Memory corruption leading to a limited or arbitrary memory read or write.&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of browsing history&lt;br /&gt;
* Overflows resulting in native code execution &lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of browsing history through effecient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
* Most Denial of Service vulnerabilities, such as those requiring a browser restart&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Status Codes, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the keywords may instead contain one of the following security status codes.&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Often none of the above severity ratings apply to a bug, because it is not a vulnerability but nonetheless is security sensitive and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is a bit of a catch-all bucket used for bugs that are not exploitable security issues but need to be kept confidential to protect sensitive information.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Bugs submitted by a user where the discussion is dependent on that user&#039;s browsing behavior (and cannot be effectively redacted)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to jit miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example). 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ui-redress || client security issues due to UI Redress attacks, either site-on-site (&amp;quot;clickjacking&amp;quot; and friends) or manipulation of the browser UI to fool users into taking the wrong action. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224025</id>
		<title>User:Tritter/Working/Web Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224025"/>
		<updated>2020-02-20T15:18:35Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Severity Ratings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
In all cases, the severity of server and web application bugs is dependent on the [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/ critically of the service] and the value of the data that could be compromised. Thus while the table below provides &amp;lt;i&amp;gt;very&amp;lt;/i&amp;gt; broad guidelines, they cannot be directly used to determine the severity of a bug absent the consideration of the affected service. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to users of our services. Often-times there is no difference technically between a sec-critical and a sec-high, the difference is purely related to to the classification of the site and the risk to users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Remote Code Execution on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical] or [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#core-sites Core] site.&lt;br /&gt;
* Authentication Flaws (which lead to account compromise)&lt;br /&gt;
* Session Management Flaws (which lead to account compromise) &lt;br /&gt;
* Stored Cross-site Scripting (XSS)&lt;br /&gt;
* Reflected XSS on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical Site]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: Typically, sec-high issues are exploitable web vulnerabilities that can lead to the targeted compromise of a small number of users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Reflected XSS on a non Critical or Core site&lt;br /&gt;
* CSRF&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose the user or organization to immediate risk. The vulnerability combined with another moderate vulnerability could result in an attack of high or critical severity (aka stepping stone). The lack of standard defense in depth techniques and security controls.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* XSS blocked by CSP&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Missing Additional Security Controls (x-frame options, SECURE/HTTPOnly flags, etc)&lt;br /&gt;
* Error Handling Issues &lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Minor security vulnerabilities such as leaks or spoofs of non-sensitive information. Missing best practice security controls &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Lack of proper input validation (not resulting in XSS or injection)&lt;br /&gt;
* Content spoofing (non-html) &lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
=== wsectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
wsectype- keywords are assigned to bugs to indicate the type of a vulnerability. These should be assigned to every vulnerability. If you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:30%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:70%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|wsec-applogic || Issues relating to the application logic&lt;br /&gt;
|-&lt;br /&gt;
|wsec-appmisconfig || Application misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authentication || Website or server authentication security issues (lockouts, password policy, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authorization || Web/server authorization security issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-automation-attack || Application is vulnerable to automation attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-bruteforce || Application is vulnerable to bruteforce attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-client || Web client side related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-cookie || Cookie related errors (HTTPOnly / Secure Flag, incorrect domain / path)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crossdomain || Issue such as x-frame-options, crossdomain.xml, cross site sharing settings&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crypto || Crypto related items such as password hashing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-csrf || Cross-Site Request Forgery (CSRF) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|wsec-deplib || Known vulnerability in a dependant library&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dir-index || Directory index incorrectly accessible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-disclosure || Disclosure of sensitive data, personal information, etc from a web service&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dos || Used to denote web server Denial of Service bugs. For similar bugs in client software please use csectype-dos instead.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-email || Email related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-errorhandling || Any error handling issue&lt;br /&gt;
|-&lt;br /&gt;
|wsec-fileinclusion || Local or remote file inclusion possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-headers || Missing or misconfigured security headers&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http || Application is incorrectly accessible over http&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http-header-inject || Application vulnerable to header injection attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-impersonation || Impersonation / Spoofing attacks (UI Redress, etc) 	&lt;br /&gt;
|-&lt;br /&gt;
|wsec-injection || Injection attacks other than SQLi or XSS &lt;br /&gt;
|-&lt;br /&gt;
|wsec-input || Failure to perform input validation. Most often you will probably use the xss tag instead&lt;br /&gt;
|-&lt;br /&gt;
|wsec-logging || Logging issues such as requests for CEF log points.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-nullbyte || Application is vulnerable to null byte injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-objref || Insecure direct object references used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-oscmd || Application is vulnerable to Operating System command injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-other || Web/server security issues that don&#039;t fit into other categories&lt;br /&gt;
|-&lt;br /&gt;
|wsec-overflow || Application is vulnerable to overflow attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-redirect || Open redirect vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-selfxss || Self cross site scripting&lt;br /&gt;
|-&lt;br /&gt;
|wsec-serialization || Insecure deserialization&lt;br /&gt;
|-&lt;br /&gt;
|wsec-servermisconfig || Server misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-session || Issues related to sesson management (Session fixation, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-sqli || SQL Injection &lt;br /&gt;
|-&lt;br /&gt;
|wsec-ssrf || Server Side Request Forgery (SSRF) bugs in server products. CWE-918&lt;br /&gt;
|-&lt;br /&gt;
|wsec-takeover || Domain vulnerable to takeover&lt;br /&gt;
|-&lt;br /&gt;
|wsec-tls || TLS related issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-traversal || Directory traversal possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-weakpasswd || Weak passwords can be used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xml || XML related vulnerability including XML External Entity (XXE) processing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xss || Cross-Site Scripting (XSS) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
! Flags&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:15%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:25%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:60%&amp;quot; | Settings&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224024</id>
		<title>User:Tritter/Working/Web Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224024"/>
		<updated>2020-02-20T15:18:13Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* Severity Ratings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
In all cases, the severity of server and web application bugs is dependent on the [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/|critically of the service] and the value of the data that could be compromised. Thus while the table below provides &amp;lt;i&amp;gt;very&amp;lt;/i&amp;gt; broad guidelines, they cannot be directly used to determine the severity of a bug absent the consideration of the affected service. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to users of our services. Often-times there is no difference technically between a sec-critical and a sec-high, the difference is purely related to to the classification of the site and the risk to users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Remote Code Execution on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical] or [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#core-sites Core] site.&lt;br /&gt;
* Authentication Flaws (which lead to account compromise)&lt;br /&gt;
* Session Management Flaws (which lead to account compromise) &lt;br /&gt;
* Stored Cross-site Scripting (XSS)&lt;br /&gt;
* Reflected XSS on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical Site]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: Typically, sec-high issues are exploitable web vulnerabilities that can lead to the targeted compromise of a small number of users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Reflected XSS on a non Critical or Core site&lt;br /&gt;
* CSRF&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose the user or organization to immediate risk. The vulnerability combined with another moderate vulnerability could result in an attack of high or critical severity (aka stepping stone). The lack of standard defense in depth techniques and security controls.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* XSS blocked by CSP&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Missing Additional Security Controls (x-frame options, SECURE/HTTPOnly flags, etc)&lt;br /&gt;
* Error Handling Issues &lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Minor security vulnerabilities such as leaks or spoofs of non-sensitive information. Missing best practice security controls &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Lack of proper input validation (not resulting in XSS or injection)&lt;br /&gt;
* Content spoofing (non-html) &lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
=== wsectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
wsectype- keywords are assigned to bugs to indicate the type of a vulnerability. These should be assigned to every vulnerability. If you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:30%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:70%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|wsec-applogic || Issues relating to the application logic&lt;br /&gt;
|-&lt;br /&gt;
|wsec-appmisconfig || Application misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authentication || Website or server authentication security issues (lockouts, password policy, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authorization || Web/server authorization security issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-automation-attack || Application is vulnerable to automation attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-bruteforce || Application is vulnerable to bruteforce attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-client || Web client side related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-cookie || Cookie related errors (HTTPOnly / Secure Flag, incorrect domain / path)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crossdomain || Issue such as x-frame-options, crossdomain.xml, cross site sharing settings&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crypto || Crypto related items such as password hashing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-csrf || Cross-Site Request Forgery (CSRF) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|wsec-deplib || Known vulnerability in a dependant library&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dir-index || Directory index incorrectly accessible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-disclosure || Disclosure of sensitive data, personal information, etc from a web service&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dos || Used to denote web server Denial of Service bugs. For similar bugs in client software please use csectype-dos instead.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-email || Email related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-errorhandling || Any error handling issue&lt;br /&gt;
|-&lt;br /&gt;
|wsec-fileinclusion || Local or remote file inclusion possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-headers || Missing or misconfigured security headers&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http || Application is incorrectly accessible over http&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http-header-inject || Application vulnerable to header injection attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-impersonation || Impersonation / Spoofing attacks (UI Redress, etc) 	&lt;br /&gt;
|-&lt;br /&gt;
|wsec-injection || Injection attacks other than SQLi or XSS &lt;br /&gt;
|-&lt;br /&gt;
|wsec-input || Failure to perform input validation. Most often you will probably use the xss tag instead&lt;br /&gt;
|-&lt;br /&gt;
|wsec-logging || Logging issues such as requests for CEF log points.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-nullbyte || Application is vulnerable to null byte injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-objref || Insecure direct object references used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-oscmd || Application is vulnerable to Operating System command injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-other || Web/server security issues that don&#039;t fit into other categories&lt;br /&gt;
|-&lt;br /&gt;
|wsec-overflow || Application is vulnerable to overflow attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-redirect || Open redirect vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-selfxss || Self cross site scripting&lt;br /&gt;
|-&lt;br /&gt;
|wsec-serialization || Insecure deserialization&lt;br /&gt;
|-&lt;br /&gt;
|wsec-servermisconfig || Server misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-session || Issues related to sesson management (Session fixation, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-sqli || SQL Injection &lt;br /&gt;
|-&lt;br /&gt;
|wsec-ssrf || Server Side Request Forgery (SSRF) bugs in server products. CWE-918&lt;br /&gt;
|-&lt;br /&gt;
|wsec-takeover || Domain vulnerable to takeover&lt;br /&gt;
|-&lt;br /&gt;
|wsec-tls || TLS related issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-traversal || Directory traversal possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-weakpasswd || Weak passwords can be used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xml || XML related vulnerability including XML External Entity (XXE) processing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xss || Cross-Site Scripting (XSS) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
! Flags&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:15%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:25%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:60%&amp;quot; | Settings&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224022</id>
		<title>User:Tritter/Working/Client Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224022"/>
		<updated>2020-02-20T14:56:07Z</updated>

		<summary type="html">&lt;p&gt;Tritter: The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties, see this corresponding page. For details about the bug bounty for the Firefox browser, and specific other applications, see [this page]. For details about the bug bounty for Mozilla Servers and Web Properties, see [this page].&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we beleive a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Spoofing of full URL bar or bypass of SSL integrity checks&lt;br /&gt;
* Memory read that results in data being written into an inert container (ie string or image) that is subsequently accessible to content&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Memory corruption leading to a limited or arbitrary memory read or write.&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of browsing history&lt;br /&gt;
* Overflows resulting in native code execution &lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of browsing history through effecient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* The most severe or persistent types of DoS attacks, such as ones that require re-installing Firefox or can write unbounded storage to disk&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Status Codes, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the keywords may instead contain one of the following security status codes.&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Often none of the above severity ratings apply to a bug, because it is not a vulnerability but nonetheless is security sensitive and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is a bit of a catch-all bucket used for bugs that are not exploitable security issues but need to be kept confidential to protect sensitive information.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Bugs submitted by a user where the discussion is dependent on that user&#039;s browsing behavior (and cannot be effectively redacted)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to jit miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example). 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ui-redress || client security issues due to UI Redress attacks, either site-on-site (&amp;quot;clickjacking&amp;quot; and friends) or manipulation of the browser UI to fool users into taking the wrong action. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224021</id>
		<title>User:Tritter/Working/Client Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224021"/>
		<updated>2020-02-20T14:54:03Z</updated>

		<summary type="html">&lt;p&gt;Tritter: add csectype-jit&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties, see this corresponding page. For details about the bug bounty for the Firefox browser, and specific other applications, see [this page]. For details about the bug bounty for Mozilla Servers and Web Properties, see [this page].&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we beleive a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Spoofing of full URL bar or bypass of SSL integrity checks&lt;br /&gt;
* Memory read that results in data being written into an inert container (ie string or image) that is subsequently accessible to content&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Memory corruption leading to a limited or arbitrary memory read or write.&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of browsing history&lt;br /&gt;
* Overflows resulting in native code execution &lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of browsing history through effecient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* Persistent DoS attacks that prevent the user from starting Firefox or another application in the future&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Status Codes, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the keywords may instead contain one of the following security status codes.&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Often none of the above severity ratings apply to a bug, because it is not a vulnerability but nonetheless is security sensitive and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is a bit of a catch-all bucket used for bugs that are not exploitable security issues but need to be kept confidential to protect sensitive information.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Bugs submitted by a user where the discussion is dependent on that user&#039;s browsing behavior (and cannot be effectively redacted)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-jit || client security issues due to jit miscompilation or similar&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example). 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ui-redress || client security issues due to UI Redress attacks, either site-on-site (&amp;quot;clickjacking&amp;quot; and friends) or manipulation of the browser UI to fool users into taking the wrong action. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224020</id>
		<title>User:Tritter/Working/Web Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224020"/>
		<updated>2020-02-20T14:53:33Z</updated>

		<summary type="html">&lt;p&gt;Tritter: /* wsectype- Keywords */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
In all cases, the severity of server and web application bugs is dependent on the critically of the service and the value of the data that could be compromised. Thus while the table below provides &amp;lt;i&amp;gt;very&amp;lt;/i&amp;gt; broad guideliens, they cannot be directly used to determine the severity of a bug absent the consideration of the affected service. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Remote Code Execution on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical] or [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#core-sites Core] site.&lt;br /&gt;
* Authentication Flaws (which lead to account compromise)&lt;br /&gt;
* Session Management Flaws (which lead to account compromise) &lt;br /&gt;
* Stored Cross-site Scripting (XSS)&lt;br /&gt;
* Reflected XSS on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical Site]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: Typically, sec-high issues are exploitable web vulnerabilities that can lead to the targeted compromise of a small number of users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Reflected XSS on a non Critical or Core site&lt;br /&gt;
* CSRF&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose the user or organization to immediate risk. The vulnerability combined with another moderate vulnerability could result in an attack of high or critical severity (aka stepping stone). The lack of standard defense in depth techniques and security controls.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* XSS blocked by CSP&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Missing Additional Security Controls (x-frame options, SECURE/HTTPOnly flags, etc)&lt;br /&gt;
* Error Handling Issues &lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Minor security vulnerabilities such as leaks or spoofs of non-sensitive information. Missing best practice security controls &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Lack of proper input validation (not resulting in XSS or injection)&lt;br /&gt;
* Content spoofing (non-html) &lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
=== wsectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
wsectype- keywords are assigned to bugs to indicate the type of a vulnerability. These should be assigned to every vulnerability. If you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:30%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:70%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|wsec-applogic || Issues relating to the application logic&lt;br /&gt;
|-&lt;br /&gt;
|wsec-appmisconfig || Application misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authentication || Website or server authentication security issues (lockouts, password policy, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authorization || Web/server authorization security issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-automation-attack || Application is vulnerable to automation attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-bruteforce || Application is vulnerable to bruteforce attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-client || Web client side related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-cookie || Cookie related errors (HTTPOnly / Secure Flag, incorrect domain / path)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crossdomain || Issue such as x-frame-options, crossdomain.xml, cross site sharing settings&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crypto || Crypto related items such as password hashing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-csrf || Cross-Site Request Forgery (CSRF) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|wsec-deplib || Known vulnerability in a dependant library&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dir-index || Directory index incorrectly accessible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-disclosure || Disclosure of sensitive data, personal information, etc from a web service&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dos || Used to denote web server Denial of Service bugs. For similar bugs in client software please use csectype-dos instead.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-email || Email related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-errorhandling || Any error handling issue&lt;br /&gt;
|-&lt;br /&gt;
|wsec-fileinclusion || Local or remote file inclusion possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-headers || Missing or misconfigured security headers&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http || Application is incorrectly accessible over http&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http-header-inject || Application vulnerable to header injection attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-impersonation || Impersonation / Spoofing attacks (UI Redress, etc) 	&lt;br /&gt;
|-&lt;br /&gt;
|wsec-injection || Injection attacks other than SQLi or XSS &lt;br /&gt;
|-&lt;br /&gt;
|wsec-input || Failure to perform input validation. Most often you will probably use the xss tag instead&lt;br /&gt;
|-&lt;br /&gt;
|wsec-logging || Logging issues such as requests for CEF log points.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-nullbyte || Application is vulnerable to null byte injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-objref || Insecure direct object references used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-oscmd || Application is vulnerable to Operating System command injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-other || Web/server security issues that don&#039;t fit into other categories&lt;br /&gt;
|-&lt;br /&gt;
|wsec-overflow || Application is vulnerable to overflow attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-redirect || Open redirect vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-selfxss || Self cross site scripting&lt;br /&gt;
|-&lt;br /&gt;
|wsec-serialization || Insecure deserialization&lt;br /&gt;
|-&lt;br /&gt;
|wsec-servermisconfig || Server misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-session || Issues related to sesson management (Session fixation, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-sqli || SQL Injection &lt;br /&gt;
|-&lt;br /&gt;
|wsec-ssrf || Server Side Request Forgery (SSRF) bugs in server products. CWE-918&lt;br /&gt;
|-&lt;br /&gt;
|wsec-takeover || Domain vulnerable to takeover&lt;br /&gt;
|-&lt;br /&gt;
|wsec-tls || TLS related issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-traversal || Directory traversal possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-weakpasswd || Weak passwords can be used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xml || XML related vulnerability including XML External Entity (XXE) processing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xss || Cross-Site Scripting (XSS) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
! Flags&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:15%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:25%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:60%&amp;quot; | Settings&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224019</id>
		<title>User:Tritter/Working/Web Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Web_Security_Severity_Ratings&amp;diff=1224019"/>
		<updated>2020-02-20T14:52:58Z</updated>

		<summary type="html">&lt;p&gt;Tritter: delete sec-review&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
In all cases, the severity of server and web application bugs is dependent on the critically of the service and the value of the data that could be compromised. Thus while the table below provides &amp;lt;i&amp;gt;very&amp;lt;/i&amp;gt; broad guideliens, they cannot be directly used to determine the severity of a bug absent the consideration of the affected service. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Remote Code Execution on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical] or [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#core-sites Core] site.&lt;br /&gt;
* Authentication Flaws (which lead to account compromise)&lt;br /&gt;
* Session Management Flaws (which lead to account compromise) &lt;br /&gt;
* Stored Cross-site Scripting (XSS)&lt;br /&gt;
* Reflected XSS on a [https://www.mozilla.org/en-US/security/bug-bounty/web-eligible-sites/#critical-sites Critical Site]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: Typically, sec-high issues are exploitable web vulnerabilities that can lead to the targeted compromise of a small number of users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Reflected XSS on a non Critical or Core site&lt;br /&gt;
* CSRF&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose the user or organization to immediate risk. The vulnerability combined with another moderate vulnerability could result in an attack of high or critical severity (aka stepping stone). The lack of standard defense in depth techniques and security controls.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* XSS blocked by CSP&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Missing Additional Security Controls (x-frame options, SECURE/HTTPOnly flags, etc)&lt;br /&gt;
* Error Handling Issues &lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Minor security vulnerabilities such as leaks or spoofs of non-sensitive information. Missing best practice security controls &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Lack of proper input validation (not resulting in XSS or injection)&lt;br /&gt;
* Content spoofing (non-html) &lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
=== wsectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
wsectype- keywords are assigned to bugs to indicate the type of a vulnerability. These should be assigned to every vulnerability.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:30%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:70%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|wsec-applogic || Issues relating to the application logic&lt;br /&gt;
|-&lt;br /&gt;
|wsec-appmisconfig || Application misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authentication || Website or server authentication security issues (lockouts, password policy, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-authorization || Web/server authorization security issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-automation-attack || Application is vulnerable to automation attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-bruteforce || Application is vulnerable to bruteforce attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-client || Web client side related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-cookie || Cookie related errors (HTTPOnly / Secure Flag, incorrect domain / path)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crossdomain || Issue such as x-frame-options, crossdomain.xml, cross site sharing settings&lt;br /&gt;
|-&lt;br /&gt;
|wsec-crypto || Crypto related items such as password hashing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-csrf || Cross-Site Request Forgery (CSRF) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|wsec-deplib || Known vulnerability in a dependant library&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dir-index || Directory index incorrectly accessible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-disclosure || Disclosure of sensitive data, personal information, etc from a web service&lt;br /&gt;
|-&lt;br /&gt;
|wsec-dos || Used to denote web server Denial of Service bugs. For similar bugs in client software please use csectype-dos instead.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-email || Email related vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-errorhandling || Any error handling issue&lt;br /&gt;
|-&lt;br /&gt;
|wsec-fileinclusion || Local or remote file inclusion possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-headers || Missing or misconfigured security headers&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http || Application is incorrectly accessible over http&lt;br /&gt;
|-&lt;br /&gt;
|wsec-http-header-inject || Application vulnerable to header injection attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-impersonation || Impersonation / Spoofing attacks (UI Redress, etc) 	&lt;br /&gt;
|-&lt;br /&gt;
|wsec-injection || Injection attacks other than SQLi or XSS &lt;br /&gt;
|-&lt;br /&gt;
|wsec-input || Failure to perform input validation. Most often you will probably use the xss tag instead&lt;br /&gt;
|-&lt;br /&gt;
|wsec-logging || Logging issues such as requests for CEF log points.&lt;br /&gt;
|-&lt;br /&gt;
|wsec-nullbyte || Application is vulnerable to null byte injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-objref || Insecure direct object references used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-oscmd || Application is vulnerable to Operating System command injection&lt;br /&gt;
|-&lt;br /&gt;
|wsec-other || Web/server security issues that don&#039;t fit into other categories&lt;br /&gt;
|-&lt;br /&gt;
|wsec-overflow || Application is vulnerable to overflow attacks&lt;br /&gt;
|-&lt;br /&gt;
|wsec-redirect || Open redirect vulnerability&lt;br /&gt;
|-&lt;br /&gt;
|wsec-selfxss || Self cross site scripting&lt;br /&gt;
|-&lt;br /&gt;
|wsec-serialization || Insecure deserialization&lt;br /&gt;
|-&lt;br /&gt;
|wsec-servermisconfig || Server misconfiguration&lt;br /&gt;
|-&lt;br /&gt;
|wsec-session || Issues related to sesson management (Session fixation, etc)&lt;br /&gt;
|-&lt;br /&gt;
|wsec-sqli || SQL Injection &lt;br /&gt;
|-&lt;br /&gt;
|wsec-ssrf || Server Side Request Forgery (SSRF) bugs in server products. CWE-918&lt;br /&gt;
|-&lt;br /&gt;
|wsec-takeover || Domain vulnerable to takeover&lt;br /&gt;
|-&lt;br /&gt;
|wsec-tls || TLS related issues&lt;br /&gt;
|-&lt;br /&gt;
|wsec-traversal || Directory traversal possible&lt;br /&gt;
|-&lt;br /&gt;
|wsec-weakpasswd || Weak passwords can be used&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xml || XML related vulnerability including XML External Entity (XXE) processing&lt;br /&gt;
|-&lt;br /&gt;
|wsec-xss || Cross-Site Scripting (XSS) bugs in server products&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 80%;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
! Flags&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:15%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:25%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:60%&amp;quot; | Settings&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:90%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224018</id>
		<title>User:Tritter/Working/Client Security Severity Ratings</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=User:Tritter/Working/Client_Security_Severity_Ratings&amp;diff=1224018"/>
		<updated>2020-02-20T14:52:30Z</updated>

		<summary type="html">&lt;p&gt;Tritter: Delete sec-review&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
The page pertains specifically to Client Applications: the Firefox web browser and mobile applications.  For severity ratings for Mozilla Servers and Web Properties, see this corresponding page. For details about the bug bounty for the Firefox browser, and specific other applications, see [this page]. For details about the bug bounty for Mozilla Servers and Web Properties, see [this page].&lt;br /&gt;
&lt;br /&gt;
==Severity Ratings ==&lt;br /&gt;
&lt;br /&gt;
Severity ratings are used to indicate how severe we beleive a bug is, and help provide guidance for its urgency and priority. Generally, we ask that they only be assigned by those with experience evaluating vulnerabilities in coordination with the security team. Presently we meet weekly to triage unclassified bugs.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Severity Ratings &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
The following items are keywords for the severity of an issue.&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-critical&#039;&#039;&#039;: Critical vulnerabilities are urgent security issues that present an ongoing or immediate danger to Firefox users. There is no difference technically between a sec-critical and a sec-high, the difference is purely related to risk to users.  Certain sec-critical vulnerabilities will cause an immediate dot-release to be issued.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-critical Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Vulnerabilities actively exploited or publicly disclosed&lt;br /&gt;
* Certain types of vulnerabilities that are worm-able or exceptionally easy to exploit &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-high&#039;&#039;&#039;: High-severity vulnerabilities are exploitable vulnerabilities which can lead to the widespread compromise of many users requiring no more than normal browsing actions. This includes most types of memory corruption, UXSS, cross-origin data leaks, and disclosure of other sensitive user data (including the user&#039;s IP address if a proxy is used.)&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-high Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Theft of arbitrary files from local system&lt;br /&gt;
* Spoofing of full URL bar or bypass of SSL integrity checks&lt;br /&gt;
* Memory read that results in data being written into an inert container (ie string or image) that is subsequently accessible to content&lt;br /&gt;
* JavaScript injection into browser chrome or other origins&lt;br /&gt;
* Failure to use TLS where needed to ensure confidential/security &lt;br /&gt;
* Memory corruption leading to a limited or arbitrary memory read or write.&lt;br /&gt;
* Proxy bypass&lt;br /&gt;
* Disclosure of browsing history&lt;br /&gt;
* Overflows resulting in native code execution &lt;br /&gt;
* Launching of arbitrary local application with provided arguments&lt;br /&gt;
* Installation &amp;amp; execution of plugins/modules with chrome/native privileges, without user consent or via user dialog fatigue&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-moderate&#039;&#039;&#039;:  Moderate severity represents a fairly wide range of issues, that include: Vulnerabilities that would be considered a sec-high but require the user to perform unusual or complex actions or is limited in scope of affected users or capability, . Vulnerabilities which can provide an attacker additional information or positioning that could be used in combination with other vulnerabilities. Disclosure of sensitive information that represents a violation of privacy but by itself does not expose sensitive user data or uniquily identify the user. Many types of application Denial of Service.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-moderate Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Disclosure of OS username&lt;br /&gt;
* Disclosure of browsing history through effecient and fast timing side channels&lt;br /&gt;
* Detection of arbitrary local files&lt;br /&gt;
* Launching of arbitrary local application without arguments&lt;br /&gt;
* Persistent DoS attacks that prevent the user from starting Firefox or another application in the future&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-low&#039;&#039;&#039;: Low severity represents vulnerabilities that clearly have security implications, but typically are unexploitable, very limited in scope, or require excessive time or processing to exploit.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-low Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Detection of a previous visit to a specific site, or when the affected site has a certain configuration&lt;br /&gt;
* Identification of users by profiling browsing behavior.&lt;br /&gt;
* Corruption of chrome dialogs or user input without the ability to spoof arbitrary messages&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;Mitigating Circumstances&#039;&#039;&#039;:&lt;br /&gt;
If there are mitigating circumstances that severely constrain the vulnerability, then the issue could be reduced by one level of severity.  Examples of mitigating circumstances include difficulty in reproducing due to very specific timing or load order requirements, a complex or unusual set of actions the user would have to take beyond normal browsing behaviors, or an unusual software configuration not provided by our Preferences page.  &lt;br /&gt;
&lt;br /&gt;
As a rough guide, to be considered for reduction in severity, the vulnerability should be exploitable less than 10% of the time.  If in the future, default software configurations change or techniques are developed to improve the reliability of the exploit it should be elevated back to the original rating.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Additional Status Codes, Whiteboard Tracking Tags &amp;amp; Flags==&lt;br /&gt;
&lt;br /&gt;
If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the keywords may instead contain one of the following security status codes.&lt;br /&gt;
&lt;br /&gt;
=== Alternate Keywords ===&lt;br /&gt;
&lt;br /&gt;
Often none of the above severity ratings apply to a bug, because it is not a vulnerability but nonetheless is security sensitive and needs to be kept private. These keywords apply to those.&lt;br /&gt;
&lt;br /&gt;
While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, we encourage you tag things &amp;lt;u&amp;gt;sec-want&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;sec-audit&amp;lt;/u&amp;gt; if you feel it applies.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible&amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! Alternate Keywords &amp;amp; Examples&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
;&#039;&#039;&#039;sec-other&#039;&#039;&#039;: sec-other is a bit of a catch-all bucket used for bugs that are not exploitable security issues but need to be kept confidential to protect sensitive information.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-other Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Gaps in fuzzing coverage to be addressed&lt;br /&gt;
* Bugs submitted by a user where the discussion is dependent on that user&#039;s browsing behavior (and cannot be effectively redacted)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-audit&#039;&#039;&#039;: Bugs marked sec-audit are typically for tasks to investigate a particular component of concern, or pattern of concern. It should NEVER be used for an actual, identified vulnerability. Either a sec-audit bug should cause additional bugs to be opened for specific instances, or a specific bug should cause a sec-audit bug to be opened for investigating variants of the original.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-audit Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Look for pattern x in library y&lt;br /&gt;
* Audit file z for string buffer abuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
;&#039;&#039;&#039;sec-vector&#039;&#039;&#039;:  Flaws not in Mozilla controlled software, but can cause security problems for Mozilla users.&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-vector Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* Bugs in plugins&lt;br /&gt;
* Bugs in system libraries used by Firefox&lt;br /&gt;
|}&lt;br /&gt;
;&#039;&#039;&#039;sec-want&#039;&#039;&#039;: New features or improvement ideas related to security. As with sec-audit, it should NEVER be applied to an actual vulnerability; but a sec-want may cause new bugs to be opened for specific vulnerabilities, or a vulnerability may spawn a follow-up bug tagged sec-want.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable collapsible &amp;quot; style=&amp;quot;width: 100%&amp;quot;&lt;br /&gt;
! &#039;&#039;sec-want Examples:&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* User interface refinements&lt;br /&gt;
* Security-relevant standards improvements or implementation&lt;br /&gt;
* Support for new types of authentication &lt;br /&gt;
* Code refactoring / cleanup&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A historical keyword is &amp;lt;b&amp;gt;sec-incident&amp;lt;/b&amp;gt;, which is no longer used.&lt;br /&gt;
&lt;br /&gt;
=== csectype- Keywords ===&lt;br /&gt;
&lt;br /&gt;
csectype- keywords are assigned to bugs to indicate the type of a vulnerability. Ideally these would be assigned to every vulnerability, but frequently they are not. While we request that only the security team assign &amp;lt;u&amp;gt;sec-high&amp;lt;/u&amp;gt; and similar ratings, if you feel you can identify the type of a security bug &amp;lt;b&amp;gt;&amp;lt;u&amp;gt;we encourage you to classify it yourself.&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|csectype-bounds || client security issues due to incorrect boundary conditions (read or write)&lt;br /&gt;
|-&lt;br /&gt;
|csectype-disclosure || Disclosure of sensitive user data, personal information, etc in a client product. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-dos || Used to tag client Denial of Service bugs. For web server denial of service bugs please use wsec-dos as these tend to be more severe.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-intoverflow || client security issues due to integer overflow 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-oom || A client crash or hang that occurs in Out Of Memory conditions&lt;br /&gt;
|-&lt;br /&gt;
|csectype-other || client security issues that don&#039;t fit into other categories 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-priv-escalation || client privilege escalation security issues 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-sop || violations of the client Same Origin Policy (Universal-XSS bugs, for example). 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uaf || client security issues due to a use-after-free&lt;br /&gt;
|-&lt;br /&gt;
|csectype-ui-redress || client security issues due to UI Redress attacks, either site-on-site (&amp;quot;clickjacking&amp;quot; and friends) or manipulation of the browser UI to fool users into taking the wrong action. 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-undefined || Bugs--or potential bugs--due to undefined compiler behavior.&lt;br /&gt;
|-&lt;br /&gt;
|csectype-uninitialized || client security issues due to use of uninitialized memory 	 	&lt;br /&gt;
|-&lt;br /&gt;
|csectype-wildptr || client security issues due to pointer misuse not otherwise covered (see csectype-uaf, csectype-uninitialized, csectype-intoverflow, csectype-bounds)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Whiteboard Tags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Code &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[bad-ram?]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates crashes identified that have no apparant cause and fit the profile of potential bit-flips caused by bad memory.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[pixel-stealing]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates vulnerabilities related to side-channel attacks on cross-origin resources.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;b&amp;gt;[fingerprinting]&amp;lt;/b&amp;gt;&lt;br /&gt;
|This indicates user privacy concerns relating to fingerprinting, or web breakage detected from fingerprinting defenses.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Flags ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 800px;&amp;quot; class=&amp;quot;wikitable collapsible  fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Flag &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Settings&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty&lt;br /&gt;
| Shows the status of a bug with regards to a bounty payout per our bounty guidlines&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and a payment will be made&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a payment will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|-&lt;br /&gt;
| sec-bounty-hof&lt;br /&gt;
| Shows the status of a bug with regards to a bounty hall of fame entry&lt;br /&gt;
|&lt;br /&gt;
{|class=&amp;quot;wikitable fullwidth-table&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width:5%&amp;quot; | Setting &lt;br /&gt;
! style=&amp;quot;width:10%&amp;quot;| Description&lt;br /&gt;
|-&lt;br /&gt;
|&#039;?&#039;|| Bug is nominated for review by the bounty committee&lt;br /&gt;
|-&lt;br /&gt;
|&#039;+&#039;|| Bug has been accepted and an entry in the hall of fame will occur&lt;br /&gt;
|-&lt;br /&gt;
|&#039;-&#039;|| Bug does not meet criteria and a hall of fame entry will &#039;&#039;not&#039;&#039; be made&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Tritter</name></author>
	</entry>
</feed>