Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 107 of 162
CVE-2014-1588P4MEDIUMCVSS 6.8≤ 33.02014-12-11
CVE-2014-1588 [MEDIUM] CVE-2014-1588: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0 and SeaMon
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2008-1236P4MEDIUMCVSS 6.8≤ 2.0.0.122008-03-27
CVE-2008-1236 [MEDIUM] CWE-399 CVE-2008-1236: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the layout engine.
nvd
CVE-2012-4203P4MEDIUMCVSS 6.8≤ 16.0.2v0.1+152 more2012-11-21
CVE-2012-4203 [MEDIUM] CWE-264 CVE-2012-4203: The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScrip
The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by leveraging a javascript: URL in a bookmark.
nvd
CVE-2015-4512P4MEDIUMCVSS 6.4≤ 40.0.32015-09-24
CVE-2015-4512 [MEDIUM] CWE-119 CVE-2015-4512: gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the
gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS
nvdosv
CVE-2008-0420P4CRITICALCVSS 9.3≤ 2.0.0.11v0.1+33 more2008-02-12
CVE-2008-0420 [CRITICAL] CWE-200 CVE-2008-0420: modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bou
nvd
CVE-2018-12366P4MEDIUMCVSS 6.5fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-12366 [MEDIUM] CWE-125 CVE-2018-12366: An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds rea
An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2012-1955P4MEDIUMCVSS 6.8v4.0v4.0.1+20 more2012-07-18
CVE-2012-1955 [MEDIUM] CVE-2012-1955: Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thun
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allow remote attackers to spoof the address bar via vectors involving history.forward and history.back calls.
nvd
CVE-2013-1730P4MEDIUMCVSS 6.8v17.0v17.0.1+16 more2013-09-18
CVE-2013-1730 [MEDIUM] CWE-119 CVE-2013-1730: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly handle movement of XBL-backed nodes between documents, which allows remote attackers to execute arbitrary code or cause a denial of service (JavaScript compartment mismatch, or assertion fa
nvd
CVE-2015-2727P4MEDIUMCVSS 6.8v38.02015-07-06
CVE-2015-2727 [MEDIUM] CVE-2015-2727: Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary fil
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
nvdosv
CVE-2017-7830P4MEDIUMCVSS 6.5fixed in 57.0fixed in 52.5.0+1 more2018-06-11
CVE-2017-7830 [MEDIUM] CVE-2017-7830: The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-ori
The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs loaded by users. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvd
CVE-2006-1529P4HIGHCVSS 7.5v1.0v1.0.1+9 more2006-04-14
CVE-2006-1529 [HIGH] CVE-2006-1529: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvd
CVE-2016-9067P4MEDIUMCVSS 6.5fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9067 [MEDIUM] CWE-416 CVE-2016-9067: Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This v
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
nvdosv
CVE-2012-4193P4MEDIUMCVSS 6.8fixed in 16.0.1≥ 10.0, < 10.0.92012-10-12
CVE-2012-4193 [MEDIUM] CWE-346 CVE-2012-4193: Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbir
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location obj
nvd
CVE-2015-0813P4MEDIUMCVSS 5.1≤ 31.5.3≤ 36.0.42015-04-01
CVE-2015-0813 [MEDIUM] CVE-2015-0813: Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox
Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.
nvdosv
CVE-2019-11742P4MEDIUMCVSS 6.5fixed in 60.9.0fixed in 69.0+1 more2019-09-27
CVE-2019-11742 [MEDIUM] CWE-829 CVE-2019-11742: A same-origin policy violation occurs allowing the theft of cross-origin images through a combinatio
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbir
nvd
CVE-2021-43536P4MEDIUMCVSS 6.5fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43536 [MEDIUM] CWE-200 CVE-2021-43536: Under certain circumstances, asynchronous functions could have caused a navigation to fail but expos
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvdosv
CVE-2016-5282P4MEDIUMCVSS 6.5≤ 48.0.22016-09-22
CVE-2016-5282 [MEDIUM] CWE-200 CVE-2016-5282: Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might a
Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.
nvdosv
CVE-2018-12385P4HIGHCVSS 7.0fixed in 62.0.2≥ unspecified, < 62.0.22018-10-18
CVE-2018-12385 [HIGH] CWE-20 CVE-2018-12385: A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data store
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploit
nvdosv
CVE-2016-2813P4MEDIUMCVSS 6.5≤ 45.0.22016-04-30
CVE-2016-2813 [MEDIUM] CVE-2016-2813: Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation a
Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.
nvd
CVE-2018-12402P4MEDIUMCVSS 6.5fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12402 [MEDIUM] CWE-346 CVE-2018-12402: The internal WebBrowserPersist code does not use correct origin context for a resource being saved.
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they
nvdosv