Mozilla Firefox vulnerabilities

3,197 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,197
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL865HIGH944MEDIUM1312LOW71UNKNOWN5

Vulnerabilities

Page 106 of 160
CVE-2013-1730MEDIUMCVSS 6.8v17.0v17.0.1+16 more2013-09-18
CVE-2013-1730 [MEDIUM] CWE-119 CVE-2013-1730: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly handle movement of XBL-backed nodes between documents, which allows remote attackers to execute arbitrary code or cause a denial of service (JavaScript compartment mismatch, or assertion fa
nvd
CVE-2013-1720MEDIUMCVSS 6.8≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1720 [MEDIUM] CWE-119 CVE-2013-1720: The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffe
nvd
CVE-2013-1726MEDIUMCVSS 6.2≤ 23.0.1v19.0+16 more2013-09-18
CVE-2013-1726 [MEDIUM] CWE-264 CVE-2013-1726: Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 2 Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
nvd
CVE-2013-1727MEDIUMCVSS 4.0PoC≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1727 [MEDIUM] CWE-79 CVE-2013-1727: Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and conseq Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.
nvd
CVE-2013-1729LOWCVSS 2.6≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1729 [LOW] CWE-200 CVE-2013-1729: The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Ma The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element.
nvd
CVE-2013-1704CRITICALCVSS 9.3≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1704 [CRITICAL] CWE-399 CVE-2013-1704: Use-after-free vulnerability in the nsINode::GetParentNode function in Mozilla Firefox before 23.0 a Use-after-free vulnerability in the nsINode::GetParentNode function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a DOM modification at the time of a SetBody mutation event.
nvd
CVE-2013-1701CRITICALCVSS 10.0v17.0v17.0.1+13 more2013-08-07
CVE-2013-1701 [CRITICAL] CVE-2013-1701: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2013-1710CRITICALCVSS 10.0PoC≤ 22.0v19.0+13 more2013-08-07
CVE-2013-1710 [CRITICAL] CWE-20 CVE-2013-1710: The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0 The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message F
nvd
CVE-2013-1702CRITICALCVSS 10.0≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1702 [CRITICAL] CVE-2013-1702: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMon Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-1705CRITICALCVSS 10.0≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1705 [CRITICAL] CWE-119 CVE-2013-1705: Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox befor Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Certificate Request Message Format (CRMF) request.
nvd
CVE-2013-1706HIGHCVSS 7.2v17.0v17.0.1+13 more2013-08-07
CVE-2013-1706 [HIGH] CWE-119 CVE-2013-1706: Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.
nvd
CVE-2013-1707HIGHCVSS 7.2≤ 22.0v19.0+13 more2013-08-07
CVE-2013-1707 [HIGH] CWE-119 CVE-2013-1707: Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x befo Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.
nvd
CVE-2013-1717MEDIUMCVSS 5.4≤ 22.0v19.0+13 more2013-08-07
CVE-2013-1717 [MEDIUM] CWE-264 CVE-2013-1717: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable path
nvd
CVE-2013-1712MEDIUMCVSS 6.9≤ 22.0v17.0+13 more2013-08-07
CVE-2013-1712 [MEDIUM] CVE-2013-1712: Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update
nvd
CVE-2013-1711MEDIUMCVSS 4.3≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1711 [MEDIUM] CWE-79 CVE-2013-1711: The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not pro The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.
nvd
CVE-2013-1713MEDIUMCVSS 4.3≤ 22.0v19.0+13 more2013-08-07
CVE-2013-1713 [MEDIUM] CWE-264 CVE-2013-1713: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 use an incorrect URI within unspecified comparisons during enforcement of the Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks or install arbitrary add-ons v
nvd
CVE-2013-1709MEDIUMCVSS 4.3v17.0v17.0.1+13 more2013-08-07
CVE-2013-1709 [MEDIUM] CWE-79 CVE-2013-1709: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in
nvd
CVE-2013-1708MEDIUMCVSS 4.3≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1708 [MEDIUM] CVE-2013-1708: Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of se Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function.
nvd
CVE-2013-1714MEDIUMCVSS 4.3v17.0v17.0.1+13 more2013-08-07
CVE-2013-1714 [MEDIUM] CWE-264 CVE-2013-1714: The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thund The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspec
nvd
CVE-2013-1715MEDIUMCVSS 6.9≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1715 [MEDIUM] CVE-2013-1715: Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in M Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.
nvd