cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 103 of 162
CVE-2009-2408P4MEDIUMCVSS 5.9fixed in 3.0.132009-07-30
CVE-2009-2408 [MEDIUM] CWE-295 CVE-2009-2408: Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificat
nvd
CVE-2011-3079P4CRITICALCVSS 10.0≤ 31.6≤ 37.0.2+1 more2012-05-01
CVE-2011-3079 [CRITICAL] CWE-399 CVE-2011-3079: The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.
nvd
CVE-2005-0147P4HIGHCVSS 7.5v0.8v0.9+3 more2005-05-02
CVE-2005-0147 [HIGH] CVE-2005-0147: Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy au Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.
nvd
CVE-2013-5596P4MEDIUMCVSS 6.8v24.0v24.0.1+11 more2013-10-30
CVE-2013-5596 [MEDIUM] CWE-119 CVE-2013-5596: The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24. The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly determine the thread for release of an image object, which allows remote attackers to execute arbitrary code or cause a denial of service (race condition and application crash) via
nvd
CVE-2019-17014P4HIGHCVSS 7.4fixed in 71.0vbefore 712020-01-08
CVE-2019-17014 [HIGH] CWE-863 CVE-2019-17014: If an image had not loaded correctly (such as when it is not actually an image), it could be dragged If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.
nvdosv
CVE-2011-3650P4CRITICALCVSS 9.3≤ 3.6.23v0.1+131 more2011-11-09
CVE-2011-3650 [CRITICAL] CWE-119 CVE-2011-3650: Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 d Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is
nvd
CVE-2019-20503P4MEDIUMCVSS 6.5≥ 0, < 74.0+build3-0ubuntu0.16.04.1≥ 0, < 74.0+build3-0ubuntu0.18.04.12020-03-11
CVE-2019-20503 [MEDIUM] firefox vulnerabilities firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the URL or other browser chrome, obtain sensitive information, bypass Content Security Policy (CSP) protections, or execute arbitrary code. (CVE-2019-20503, CVE-2020-6805, CVE-2020-6806, CVE-2020-6807, CVE-2020-6808, CVE-2020-68
osv
CVE-2020-12418P4MEDIUMCVSS 6.5fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12418 [MEDIUM] CWE-125 CVE-2020-12418: Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking proce Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2015-4520P4MEDIUMCVSS 6.4v38.0v38.0.1+6 more2015-09-24
CVE-2015-4520 [MEDIUM] CWE-254 CVE-2015-4520: Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS p Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.
nvdosv
CVE-2017-5407P4MEDIUMCVSS 6.5fixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5407 [MEDIUM] CWE-200 CVE-2017-5407: Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Fire
nvd
CVE-2012-3979P4MEDIUMCVSS 6.8≤ 14.0v0.1+149 more2012-08-29
CVE-2012-3979 [MEDIUM] CVE-2012-3979: Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __andr Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function.
nvd
CVE-2011-0051P4MEDIUMCVSS 6.8v3.6v3.6.2+96 more2011-03-02
CVE-2011-0051 [MEDIUM] CWE-20 CVE-2011-0051: Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properl Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.
nvd
CVE-2016-1967P4MEDIUMCVSS 6.5≤ 44.0.22016-03-13
CVE-2016-1967 [MEDIUM] CVE-2016-1967: Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing AP Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists
nvd
CVE-2010-1215P4MEDIUMCVSS 6.8v3.6.1v3.6.2+3 more2010-07-30
CVE-2010-1215 [MEDIUM] CWE-94 CVE-2010-1215: Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement acce Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."
nvd
CVE-2022-28282P4MEDIUMCVSS 6.5fixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28282 [MEDIUM] CWE-416 CVE-2022-28282: By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by d By using a link with rel="localization" a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvd
CVE-2014-1502P4MEDIUMCVSS 6.8fixed in 28.02014-03-19
CVE-2014-1502 [MEDIUM] CWE-346 CVE-2014-1502: The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefo The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.
nvd
CVE-2018-12397P4HIGHCVSS 7.1fixed in 60.3.0fixed in 63.0+1 more2019-02-28
CVE-2018-12397 [HIGH] CWE-200 CVE-2018-12397: A WebExtension can request access to local files without the warning prompt stating that the extensi A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63
nvd
CVE-2020-12421P4MEDIUMCVSS 6.5fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12421 [MEDIUM] CWE-295 CVE-2020-12421: When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected ( When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2024-26282P4HIGHCVSS 7.1fixed in 123.02024-02-22
CVE-2024-26282 [HIGH] CWE-80 CVE-2024-26282: Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.
nvd
CVE-2021-43542P4MEDIUMCVSS 6.5fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43542 [MEDIUM] CWE-209 CVE-2021-43542: Using XMLHttpRequest, an attacker could have identified installed applications by probing error mess Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd