Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 108 of 162
CVE-2006-1531P4HIGHCVSS 7.5fixed in 1.5.0.22006-04-14
CVE-2006-1531 [HIGH] CVE-2006-1531: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvd
CVE-2006-1530P4HIGHCVSS 7.5fixed in 1.5.0.22006-04-14
CVE-2006-1530 [HIGH] CVE-2006-1530: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvd
CVE-2007-2292P4MEDIUMCVSS 4.3≤ 2.0.0.82007-04-26
CVE-2007-2292 [MEDIUM] CWE-20 CVE-2007-2292: CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8
CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.
nvd
CVE-2020-15666P4MEDIUMCVSS 6.5fixed in 80.0≥ unspecified, < 802020-10-01
CVE-2020-15666 [MEDIUM] CWE-209 CVE-2020-15666: When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500,
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network a
nvdosv
CVE-2020-15658P4MEDIUMCVSS 6.5fixed in 79.0≥ unspecified, < 792020-08-10
CVE-2020-15658 [MEDIUM] CWE-754 CVE-2020-15658: The code for downloading files did not properly take care of special characters, which led to an att
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvdosv
CVE-2019-11747P4MEDIUMCVSS 6.5fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11747 [MEDIUM] CWE-665 CVE-2019-11747: The "Forget about this site" feature in the History pane is intended to remove all saved user data t
The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the pre-load list also have their HSTS setting removed. On the next visit to tha
nvd
CVE-2021-29982P4MEDIUMCVSS 6.5fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29982 [MEDIUM] CWE-772 CVE-2021-29982: Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, re
Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory. This vulnerability affects Firefox < 91 and Thunderbird < 91.
nvdosv
CVE-2021-23984P4MEDIUMCVSS 6.5fixed in 87.0≥ unspecified, < 872021-03-31
CVE-2021-23984 [MEDIUM] CWE-290 CVE-2021-23984: A malicious extension could have opened a popup window lacking an address bar. The title of the popu
A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, a
nvd
CVE-2022-40958P4MEDIUMCVSS 6.5fixed in 105.0≥ unspecified, < 1052022-12-22
CVE-2022-40958 [MEDIUM] CWE-74 CVE-2022-40958: By injecting a cookie with certain special characters, an attacker on a shared subdomain which is no
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2022-40957P4MEDIUMCVSS 6.5fixed in 105.0≥ unspecified, < 1052022-12-22
CVE-2022-40957 [MEDIUM] CWE-240 CVE-2022-40957: Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially
Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2006-0292P4HIGHCVSS 7.5v0.8v0.9+14 more2006-02-02
CVE-2006-0292 [HIGH] CVE-2006-0292: The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly derefe
The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.
nvd
CVE-2023-5171P4MEDIUMCVSS 6.5fixed in 118≥ unspecified, < 1182023-09-27
CVE-2023-5171 [MEDIUM] CWE-416 CVE-2023-5171: During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allo
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2005-2267P4HIGHCVSS 7.5v0.8v0.9+10 more2005-07-13
CVE-2005-2267 [HIGH] CVE-2005-2267: Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary cod
Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.
nvd
CVE-2020-12407P4MEDIUMCVSS 6.5fixed in 77.0≥ unspecified, < 772020-07-09
CVE-2020-12407 [MEDIUM] CWE-125 CVE-2020-12407: Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditi
Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. The leaked memory content was visible to the user, but not observable from web content. This vulnerability affects Firefox < 77.
nvdosv
CVE-2019-11738P4MEDIUMCVSS 6.3fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11738 [MEDIUM] CVE-2019-11738: If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the
If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP permissions. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2021-29987P4MEDIUMCVSS 6.5fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29987 [MEDIUM] CWE-307 CVE-2021-29987: After requesting multiple permissions, and closing the first permission panel, subsequent permission
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible to trick a user into accepting a permission they did not want to. *This bug only affects Firefox on Linux. Other operating systems a
nvdosv
CVE-2020-26977P4MEDIUMCVSS 6.5fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26977 [MEDIUM] CVE-2020-26977: By attempting to connect a website using an unresponsive port, an attacker could have controlled the
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
nvd
CVE-2019-11765P4MEDIUMCVSS 6.5fixed in 70.0vbefore 702020-01-08
CVE-2019-11765 [MEDIUM] CWE-276 CVE-2019-11765: A compromised content process could send a message to the parent process that would cause the 'Click
A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepted the permission request an attacker-controlled permission would be granted rather than the 'Click to Play' permission. This vulner
nvdosv
CVE-2018-5131P4MEDIUMCVSS 5.9fixed in 59.0fixed in 52.7.0+1 more2018-06-11
CVE-2018-5131 [MEDIUM] CWE-200 CVE-2018-5131: Under certain circumstances the "fetch()" API can return transient local copies of resources that we
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while brows
nvd
CVE-2020-26955P4MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26955 [MEDIUM] CWE-565 CVE-2020-26955: When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are
nvd