Mozilla Firefox vulnerabilities
3,197 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,197
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL865HIGH944MEDIUM1312LOW71UNKNOWN5
Vulnerabilities
Page 108 of 160
CVE-2013-0801CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-0801 [CRITICAL] CVE-2013-0801: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-1681CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1681 [CRITICAL] CWE-399 CVE-2013-1681: Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox
Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-1678CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1678 [CRITICAL] CWE-119 CVE-2013-1678: The _cairo_xlib_surface_add_glyph function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 1
The _cairo_xlib_surface_add_glyph function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via unspecified vectors.
nvd
CVE-2013-1669CRITICALCVSS 10.0≤ 20.0.1v19.0+3 more2013-05-16
CVE-2013-1669 [CRITICAL] CVE-2013-1669: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-1677CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1677 [CRITICAL] CWE-399 CVE-2013-1677: The gfxSkipCharsIterator::SetOffsets function in Mozilla Firefox before 21.0, Firefox ESR 17.x befor
The gfxSkipCharsIterator::SetOffsets function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-1679CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1679 [CRITICAL] CWE-399 CVE-2013-1679: Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firef
Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-1671MEDIUMCVSS 4.3≤ 20.0.1v19.0+3 more2013-05-16
CVE-2013-1671 [MEDIUM] CWE-20 CVE-2013-1671: Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attac
Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.
nvd
CVE-2013-1670MEDIUMCVSS 4.3PoC≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1670 [MEDIUM] CWE-79 CVE-2013-1670: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x befo
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct
nvd
CVE-2013-1672MEDIUMCVSS 6.9≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1672 [MEDIUM] CWE-264 CVE-2013-1672: The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thun
The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.
nvd
CVE-2013-1675MEDIUMCVSS 6.5KEVfixed in 21.0≥ 17.0, < 17.0.62013-05-16
CVE-2013-1675 [MEDIUM] CWE-665 CVE-2013-1675: Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderb
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted w
nvd
CVE-2013-1673MEDIUMCVSS 6.9≤ 20.0.1v19.0+3 more2013-05-16
CVE-2013-1673 [MEDIUM] CWE-264 CVE-2013-1673: The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Mai
The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."
nvd
CVE-2013-0790CRITICALCVSS 10.0≤ 19.0.2v0.1+160 more2013-04-03
CVE-2013-0790 [CRITICAL] CVE-2013-0790: Unspecified vulnerability in the browser engine in Mozilla Firefox before 20.0 on Android allows rem
Unspecified vulnerability in the browser engine in Mozilla Firefox before 20.0 on Android allows remote attackers to cause a denial of service (stack memory corruption and application crash) or possibly execute arbitrary code via unknown vectors involving a plug-in.
nvd
CVE-2013-0795CRITICALCVSS 10.0≤ 19.0.2v19.0+6 more2013-04-03
CVE-2013-0795 [CRITICAL] CWE-264 CVE-2013-0795: The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before
The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 does not prevent use of the cloneNode method for cloning a protected node, which allows remote attackers to bypass the Same Origin Policy or possibly exe
nvd
CVE-2013-0796CRITICALCVSS 10.0fixed in 20.0≥ 17.0, < 17.0.52013-04-03
CVE-2013-0796 [CRITICAL] CVE-2013-0796: The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird befo
The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 on Linux does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (free of unallocated memory) via unspecified v
nvd
CVE-2013-0789CRITICALCVSS 10.0≤ 19.0.2v19.0+1 more2013-04-03
CVE-2013-0789 [CRITICAL] CVE-2013-0789: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMon
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other vectors.
nvd
CVE-2013-0788CRITICALCVSS 10.0≤ 19.0.2v19.0+6 more2013-04-03
CVE-2013-0788 [CRITICAL] CVE-2013-0788: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2013-0799HIGHCVSS 7.2≤ 19.0.2v19.0+6 more2013-04-03
CVE-2013-0799 [HIGH] CWE-119 CVE-2013-0799: Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x
Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and Thunderbird ESR 17.x before 17.0.5 on Windows allows local users to gain privileges via crafted arguments.
nvd
CVE-2013-0798MEDIUMCVSS 4.3≤ 19.0.2v19.0+1 more2013-04-03
CVE-2013-0798 [MEDIUM] CWE-264 CVE-2013-0798: Mozilla Firefox before 20.0 on Android uses world-writable and world-readable permissions for the ap
Mozilla Firefox before 20.0 on Android uses world-writable and world-readable permissions for the app_tmp installation directory in the local filesystem, which allows attackers to modify add-ons before installation via an application that leverages the time window during which app_tmp is used.
nvd
CVE-2013-0791MEDIUMCVSS 5.0≤ 20.0≥ 17.0, < 17.0.52013-04-03
CVE-2013-0791 [MEDIUM] CWE-119 CVE-2013-0791: The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla F
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption)
nvd
CVE-2013-0792MEDIUMCVSS 4.3≤ 19.0.2v19.0+1 more2013-04-03
CVE-2013-0792 [MEDIUM] CWE-200 CVE-2013-0792: Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, d
Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a grayscale PNG image.
nvd