Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 112 of 162
CVE-2020-12425P4MEDIUMCVSS 6.5fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12425 [MEDIUM] CWE-125 CVE-2020-12425: Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could
Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.
nvdosv
CVE-2020-15652P4MEDIUMCVSS 6.5fixed in 79.0≥ 78.0, < 78.1+1 more2020-08-10
CVE-2020-15652 [MEDIUM] CWE-346 CVE-2020-15652: By observing the stack trace for JavaScript errors in web workers, it was possible to leak the resul
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
nvd
CVE-2017-7781P4MEDIUMCVSS 5.9fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7781 [MEDIUM] CVE-2017-7781: An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coord
An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can yield a result "POINT_AT_INFINITY" when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret. This vulnerability affects Firefox < 55.
nvdosv
CVE-2021-29945P4MEDIUMCVSS 6.5fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-29945 [MEDIUM] CWE-682 CVE-2021-29945: The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read an
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2006-1723P4HIGHCVSS 7.5v1.0v1.0.1+9 more2006-04-14
CVE-2006-1723 [HIGH] CVE-2006-1723: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, all
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006
nvd
CVE-2006-2778P4MEDIUMCVSS 5.0≤ 1.5.0.32006-06-02
CVE-2006-2778 [MEDIUM] CVE-2006-2778: The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attacke
The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.
nvd
CVE-2020-26961P4MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26961 [MEDIUM] CVE-2020-26961: When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the respo
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR <
nvd
CVE-2021-38492P4MEDIUMCVSS 6.5fixed in 92.0≥ 91.0, < 91.1+1 more2021-11-03
CVE-2021-38492 [MEDIUM] CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which migh
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 7
nvd
CVE-2018-18499P4MEDIUMCVSS 6.5fixed in 62.0≥ unspecified, < 622019-02-28
CVE-2018-18499 [MEDIUM] CWE-346 CVE-2018-18499: A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http
A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.
nvd
CVE-2019-11748P4MEDIUMCVSS 6.5fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11748 [MEDIUM] CWE-281 CVE-2019-11748: WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camer
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This avoids the possibility of trusted WebRTC resources being invisibly embe
nvd
CVE-2021-29975P4MEDIUMCVSS 6.5fixed in 90.0≥ unspecified, < 902021-08-05
CVE-2021-29975 [MEDIUM] CVE-2021-29975: Through a series of DOM manipulations, a message, over which the attacker had control of the text bu
Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly shown in the address bar) resulting in possible user confusion. This vulnerability affects Firefox < 90.
nvdosv
CVE-2016-9074P4MEDIUMCVSS 5.9fixed in 45.5.0fixed in 50.0+1 more2018-06-11
CVE-2016-9074 [MEDIUM] CWE-200 CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This is
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2020-16042P4MEDIUMCVSS 6.5≥ 0, < 84.0+build3-0ubuntu0.16.04.1≥ 0, < 84.0+build3-0ubuntu0.18.04.1+1 more2020-12-15
CVE-2020-16042 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass the CSS sanitizer, bypass security restrictions,
spoof the URL bar, or execute arbitrary code. (CVE-2020-16042,
CVE-2020-26971, CVE-2020-26972, CVE-2020-26793, CVE-2020-26974,
CVE-2020-26976, CVE-20
osv
CVE-2023-6205P4MEDIUMCVSS 6.5fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6205 [MEDIUM] CWE-416 CVE-2023-6205: It was possible to cause the use of a MessagePort after it had already been freed, which could poten
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2019-11697P4MEDIUMCVSS 6.5fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11697 [MEDIUM] CWE-20 CVE-2019-11697: If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extensi
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious exten
nvdosv
CVE-2020-15661P4MEDIUMCVSS 6.5fixed in 28.02020-08-10
CVE-2020-15661 [MEDIUM] CWE-522 CVE-2020-15661: A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit c
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.
nvd
CVE-2022-22742P4MEDIUMCVSS 6.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22742 [MEDIUM] CWE-125 CVE-2022-22742: When inserting text while in edit mode, some characters might have lead to out-of-bounds memory acce
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-29535P4MEDIUMCVSS 6.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29535 [MEDIUM] CVE-2023-29535: Following a Garbage Collector compaction, weak maps may have been accessed before they were correctl
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvd
CVE-2024-0746P4MEDIUMCVSS 6.5fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0746 [MEDIUM] CWE-416 CVE-2024-0746: A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerabi
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2021-23996P4MEDIUMCVSS 6.5fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-23996 [MEDIUM] CVE-2021-23996: By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the web
By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, resulting in a spoofing attack that could have been used for phishing or other attacks on a user. This vulnerability affects Firefox < 88.
nvdosv