cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 105 of 162
CVE-2023-37206P4MEDIUMCVSS 6.5fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37206 [MEDIUM] CWE-59 CVE-2023-37206: Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulnerability affects Firefox < 115.
nvdosv
CVE-2024-10463P4MEDIUMCVSS 6.5fixed in 115.17.0fixed in 132.0+2 more2024-10-29
CVE-2024-10463 [MEDIUM] CWE-203 CVE-2024-10463: Video frames could have been leaked between origins in some situations. This vulnerability affects F Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2023-29548P4MEDIUMCVSS 6.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29548 [MEDIUM] CVE-2023-29548: A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvd
CVE-2022-22739P4MEDIUMCVSS 6.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22739 [MEDIUM] CVE-2022-22739: Malicious websites could have tricked users into accepting launching a program to handle an external Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-25728P4MEDIUMCVSS 6.5fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25728 [MEDIUM] CWE-203 CVE-2023-25728: The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child The Content-Security-Policy-Report-Only header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2022-22754P4MEDIUMCVSS 6.5fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22754 [MEDIUM] CWE-863 CVE-2022-22754: If a user installed an extension of a particular type, the extension could have auto-updated itself If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2023-4577P4MEDIUMCVSS 6.5fixed in 117.0≥ unspecified, < 1172023-09-11
CVE-2023-4577 [MEDIUM] CVE-2023-4577: When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbag When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2023-23603P4MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23603 [MEDIUM] CWE-770 CVE-2023-23603: Regular expressions used to filter out forbidden properties and values from style directives in call Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2023-4573P4MEDIUMCVSS 6.5fixed in 117.0≥ 115.0, < 115.2+1 more2023-09-11
CVE-2023-4573 [MEDIUM] CWE-416 CVE-2023-4573: When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which c When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
nvdosv
CVE-2022-45404P4MEDIUMCVSS 6.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45404 [MEDIUM] CWE-451 CVE-2022-45404: Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to g Through a series of popup and window.print() calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2023-23602P4MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23602 [MEDIUM] CWE-754 CVE-2023-23602: A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Pol A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2024-10464P4MEDIUMCVSS 6.5fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10464 [MEDIUM] CWE-125 CVE-2024-10464: Repeated writes to history interface attributes could have been used to cause a Denial of Service co Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2024-0747P4MEDIUMCVSS 6.5fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0747 [MEDIUM] CWE-693 CVE-2024-0747: When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Pol When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2023-29545P4MEDIUMCVSS 6.5fixed in 112.02023-06-19
CVE-2023-29545 [MEDIUM] CVE-2023-29545: Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing en Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR
nvd
CVE-2024-7526P4MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7526 [MEDIUM] CWE-908 CVE-2024-7526: ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2022-28283P4MEDIUMCVSS 6.5fixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28283 [MEDIUM] CWE-552 CVE-2022-28283: The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage t The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include local files or other files that should have been inaccessible. This vulnerability affects Firefox < 99.
nvdosv
CVE-2023-32210P4MEDIUMCVSS 6.5fixed in 113.0≥ unspecified, < 1132023-06-19
CVE-2023-32210 [MEDIUM] CVE-2023-32210: Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading a Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain circumstances it might have been possible to cause a document to be loaded with a higher privileged principal than intended. This vulnerability affects Firefox < 113.
nvdosv
CVE-2023-37204P4MEDIUMCVSS 6.5fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37204 [MEDIUM] CVE-2023-37204: A website could have obscured the fullscreen notification by using an option element by introducing A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
nvdosv
CVE-2024-7518P4MEDIUMCVSS 6.5fixed in 129≥ unspecified, < 1292024-08-06
CVE-2024-7518 [MEDIUM] CWE-1021 CVE-2024-7518: Select options could obscure the fullscreen notification dialog. This could be used by a malicious s Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvdosv
CVE-2022-38472P4MEDIUMCVSS 6.5fixed in 104.0≥ 102.0, < 102.2+1 more2022-12-22
CVE-2022-38472 [MEDIUM] CWE-346 CVE-2022-38472: An attacker could have abused XSLT error handling to associate attacker-controlled content with anot An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR <
nvd
Mozilla Firefox vulnerabilities | cvebase