cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 111 of 162
CVE-2025-0237P4MEDIUMCVSS 5.4fixed in 128.6.0fixed in 134.02025-01-07
CVE-2025-0237 [MEDIUM] CWE-863 CVE-2025-0237: The WebChannel API, which is used to transport various information across processes, did not check t The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvdosv
CVE-2005-0527P4MEDIUMCVSS 5.1v1.02005-05-02
CVE-2005-0527 [MEDIUM] CVE-2005-0527: Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged cont Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."
nvd
CVE-2006-6501P4MEDIUMCVSS 6.8≥ 1.5, < 1.5.0.9≥ 2.0, < 2.0.0.12006-12-20
CVE-2006-6501 [MEDIUM] CWE-264 CVE-2006-6501: Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird b Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
nvd
CVE-2007-1736P4HIGHCVSS 7.5v2.0.0.32007-03-28
CVE-2007-1736 [HIGH] CVE-2007-1736: Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against t Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.
nvd
CVE-2008-0413P4CRITICALCVSS 9.3≤ 2.0.0.112008-02-08
CVE-2008-0413 [CRITICAL] CWE-399 CVE-2008-0413: The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via (1) a large switch statement, (2) certain uses of watch and eval, (3) certain uses of the mousedown event listener, and other vectors
nvd
CVE-2009-1307P4MEDIUMCVSS 6.8≤ 3.0.8v0.1+78 more2009-04-22
CVE-2009-1307 [MEDIUM] CWE-20 CVE-2009-1307: The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass
nvd
CVE-2012-5354P4MEDIUMCVSS 6.8fixed in 16.02012-10-10
CVE-2012-5354 [MEDIUM] CVE-2012-5354: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly hand Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability tha
nvd
CVE-2015-7214P4MEDIUMCVSS 5.0v38.0v38.0.1+8 more2015-12-16
CVE-2015-7214 [MEDIUM] CWE-200 CVE-2015-7214: Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Sa Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.
nvdosv
CVE-2013-1700P4HIGHCVSS 7.2≤ 21.0v19.0+4 more2013-06-26
CVE-2013-1700 [HIGH] CWE-264 CVE-2013-1700: The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle i The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location.
nvd
CVE-2013-1706P4HIGHCVSS 7.2v17.0v17.0.1+13 more2013-08-07
CVE-2013-1706 [HIGH] CWE-119 CVE-2013-1706: Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.
nvd
CVE-2013-1707P4HIGHCVSS 7.2≤ 22.0v19.0+13 more2013-08-07
CVE-2013-1707 [HIGH] CWE-119 CVE-2013-1707: Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x befo Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.
nvd
CVE-2018-12398P4MEDIUMCVSS 6.5fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12398 [MEDIUM] CVE-2018-12398: By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
nvdosv
CVE-2018-18494P4MEDIUMCVSS 6.5fixed in 60.4.0fixed in 64.0+1 more2019-02-28
CVE-2018-18494 [MEDIUM] CWE-346 CVE-2018-18494: A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascr A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2018-5133P4MEDIUMCVSS 6.5fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5133 [MEDIUM] CWE-200 CVE-2018-5133: If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes a search. This stored preference is also executed whenever an EME video pl
nvdosv
CVE-2018-5132P4MEDIUMCVSS 6.5fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5132 [MEDIUM] CWE-200 CVE-2018-5132: The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.
nvdosv
CVE-2019-11736P4HIGHCVSS 7.0fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11736 [HIGH] CWE-362 CVE-2019-11736: The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenanc
nvd
CVE-2018-18497P4MEDIUMCVSS 6.5fixed in 64.0≥ unspecified, < 642019-02-28
CVE-2018-18497 [MEDIUM] CVE-2018-18497: Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed w Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.
nvdosv
CVE-2020-12424P4MEDIUMCVSS 6.5fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12424 [MEDIUM] CWE-276 CVE-2020-12424: When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.
nvdosv
CVE-2019-11700P4MEDIUMCVSS 6.5fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11700 [MEDIUM] CWE-862 CVE-2019-11700: A hyperlink using the res: protocol can be used to open local files at a known location in Internet A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.
nvd
CVE-2019-11702P4MEDIUMCVSS 6.5fixed in 67.0.2≥ unspecified, < 67.0.22019-07-23
CVE-2019-11702 [MEDIUM] CWE-862 CVE-2019-11702: A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.
nvd
Mozilla Firefox vulnerabilities | cvebase