cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 113 of 162
CVE-2022-45403P4MEDIUMCVSS 6.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45403 [MEDIUM] CWE-203 CVE-2022-45403: Service Workers should not be able to infer information about opaque cross-origin responses; but tim Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvdosv
CVE-2021-29983P4MEDIUMCVSS 6.5fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29983 [MEDIUM] CVE-2021-29983: Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interaction Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91.
nvd
CVE-2020-15662P4MEDIUMCVSS 6.5fixed in 28.02020-08-10
CVE-2020-15662 [MEDIUM] CVE-2020-15662: A rogue webpage could override the injected WKUserScript used by the download feature, this exploit A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS < 28.
nvd
CVE-2022-40961P4MEDIUMCVSS 6.5fixed in 105.0≥ unspecified, < 1052022-12-22
CVE-2022-40961 [MEDIUM] CWE-787 CVE-2022-40961: During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow caus During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.
nvd
CVE-2023-6210P4MEDIUMCVSS 6.5fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6210 [MEDIUM] CVE-2023-6210: When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allow When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.
nvdosv
CVE-2004-0866P4HIGHCVSS 7.5v0.9.22004-09-16
CVE-2004-0866 [HIGH] CVE-2004-0866: Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such a Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
CVE-2021-23998P4MEDIUMCVSS 6.5fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-23998 [MEDIUM] CWE-345 CVE-2021-23998: Through complicated navigations with new windows, an HTTP page could have inherited a secure lock ic Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2021-38497P4MEDIUMCVSS 6.5fixed in 93.0≥ unspecified, < 932021-11-03
CVE-2021-38497 [MEDIUM] CWE-346 CVE-2021-38497: Through use of reportValidity() and window.open(), a plain-text validation message could have been o Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosv
CVE-2020-15682P4MEDIUMCVSS 6.5fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15682 [MEDIUM] CWE-346 CVE-2020-15682: When a link to an external protocol was clicked, a prompt was presented that allowed the user to cho When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they
nvdosv
CVE-2024-11706P4MEDIUMCVSS 6.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11706 [MEDIUM] CWE-476 CVE-2024-11706: A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `S A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.
nvdosv
CVE-2023-29547P4MEDIUMCVSS 6.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29547 [MEDIUM] CVE-2023-29547: When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosv
CVE-2022-31743P4MEDIUMCVSS 6.5fixed in 101.0≥ unspecified, < 1012022-12-22
CVE-2022-31743 [MEDIUM] CWE-79 CVE-2022-31743: Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity wit Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.
nvdosv
CVE-2022-45419P4MEDIUMCVSS 6.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45419 [MEDIUM] CWE-295 CVE-2022-45419: If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connect If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.
nvd
CVE-2023-23601P4MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23601 [MEDIUM] CWE-346 CVE-2023-23601: Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab whic Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2016-9076P4MEDIUMCVSS 5.9fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9076 [MEDIUM] CWE-20 CVE-2016-9076: An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in po An issue where a "" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulnerability affects Firefox < 50.
nvdosv
CVE-2023-37210P4MEDIUMCVSS 6.5fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37210 [MEDIUM] CWE-346 CVE-2023-37210: A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
nvdosv
CVE-2024-9936P4MEDIUMCVSS 6.5fixed in 131.0.3≥ unspecified, < 131.0.32024-10-14
CVE-2024-9936 [MEDIUM] CWE-362 CVE-2024-9936: When manipulating the selection node cache, an attacker may have been able to cause unexpected behav When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.
nvdosv
CVE-2025-11711P4MEDIUMCVSS 6.5fixed in 115.29.0fixed in 144.0+1 more2025-10-14
CVE-2025-11711 [MEDIUM] CWE-591 CVE-2025-11711: There was a way to change the value of JavaScript Object properties that were supposed to be non-wri There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
nvd
CVE-2026-12319P4MEDIUMCVSS 6.5fixed in 152.0.02026-06-16
CVE-2026-12319 [MEDIUM] CWE-400 CVE-2026-12319: Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 15 Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2005-2261P4HIGHCVSS 7.5v0.8v0.9+10 more2005-07-13
CVE-2005-2261 [HIGH] CVE-2005-2261: Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0 Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.
nvd
Mozilla Firefox vulnerabilities | cvebase