cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 109 of 162
CVE-2023-28163P4MEDIUMCVSS 6.5fixed in 111.0≥ unspecified, < 1122023-06-02
CVE-2023-28163 [MEDIUM] CWE-22 CVE-2023-28163: When downloading files through the Save As dialog on Windows with suggested filenames containing env When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. *This bug only affects Firefox on Windows. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thu
nvd
CVE-2023-25741P4MEDIUMCVSS 6.5fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25741 [MEDIUM] CWE-203 CVE-2023-25741: When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.
nvdosv
CVE-2023-32211P4MEDIUMCVSS 6.5fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32211 [MEDIUM] CVE-2023-32211: A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefo A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2022-22748P4MEDIUMCVSS 6.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22748 [MEDIUM] CWE-79 CVE-2022-22748: Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2022-29916P4MEDIUMCVSS 6.5fixed in 100.0≥ unspecified, < 1002022-12-22
CVE-2022-29916 [MEDIUM] CWE-200 CVE-2022-29916: Firefox behaved slightly differently for already known resources when loading CSS resources involvin Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2023-25751P4MEDIUMCVSS 6.5fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-25751 [MEDIUM] CVE-2023-25751: Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2022-45416P4MEDIUMCVSS 6.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45416 [MEDIUM] CWE-203 CVE-2022-45416: Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have possibly figured out which keys were being pressed. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2022-46880P4MEDIUMCVSS 6.5fixed in 105.0≥ unspecified, < 1052022-12-22
CVE-2022-46880 [MEDIUM] CWE-416 CVE-2022-46880: A missing check related to tex units could have led to a use-after-free and potentially exploitable A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 105. This vulnerability affects Firefox ESR < 102.6, Firefox < 105, and Thunderbird
nvd
CVE-2023-6872P4MEDIUMCVSS 6.5fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6872 [MEDIUM] CVE-2023-6872: Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the brow Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the browsing habits of users running in a private tab. This vulnerability affects Firefox < 121.
nvdosv
CVE-2022-22745P4MEDIUMCVSS 6.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22745 [MEDIUM] CWE-200 CVE-2022-22745: Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violat Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-25738P4MEDIUMCVSS 6.5fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25738 [MEDIUM] CWE-125 CVE-2023-25738: Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thu
nvd
CVE-2022-29914P4MEDIUMCVSS 6.5fixed in 100.0≥ unspecified, < 1002022-12-22
CVE-2022-29914 [MEDIUM] CWE-1021 CVE-2022-29914: When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2022-31742P4MEDIUMCVSS 6.5fixed in 101≥ unspecified, < 1012022-12-22
CVE-2022-31742 [MEDIUM] CWE-203 CVE-2022-31742: An attacker could have exploited a timing attack by sending a large number of allowCredential entrie An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR
nvd
CVE-2022-31738P4MEDIUMCVSS 6.5fixed in 101≥ unspecified, < 1012022-12-22
CVE-2022-31738 [MEDIUM] CWE-290 CVE-2022-31738: When exiting fullscreen mode, an iframe could have confused the browser about the current state of f When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2023-6869P4MEDIUMCVSS 6.5fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6869 [MEDIUM] CVE-2023-6869: A `&lt;dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. A ` ` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.
nvdosv
CVE-2020-26957P4MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26957 [MEDIUM] CWE-665 CVE-2020-26957: OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. Th OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
nvd
CVE-2023-29546P4MEDIUMCVSS 6.5fixed in 112.02023-06-19
CVE-2023-29546 [MEDIUM] CVE-2023-29546: When recording the screen while in Private Browsing on Firefox for Android the address bar and keybo When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
nvd
CVE-2024-1556P4MEDIUMCVSS 6.5fixed in 123.0≥ unspecified, < 1232024-02-20
CVE-2024-1556 [MEDIUM] CWE-754 CVE-2024-1556: The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid m The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123.
nvdosv
CVE-2023-23604P4MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23604 [MEDIUM] CWE-863 CVE-2023-23604: A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `D A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have lead to bypassing web security checks. This vulnerability affects Firefox < 109.
nvdosv
CVE-2023-4580P4MEDIUMCVSS 6.5fixed in 117.0≥ unspecified, < 1172023-09-11
CVE-2023-4580 [MEDIUM] CWE-311 CVE-2023-4580: Push notifications stored on disk in private browsing mode were not being encrypted potentially allo Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
Mozilla Firefox vulnerabilities | cvebase