Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 114 of 162
CVE-2005-2260P4HIGHCVSS 7.5v0.8v0.9+10 more2005-07-13
CVE-2005-2260 [HIGH] CVE-2005-2260: The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2
The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.
nvd
CVE-2013-1717P4MEDIUMCVSS 5.4≤ 22.0v19.0+13 more2013-08-07
CVE-2013-1717 [MEDIUM] CWE-264 CVE-2013-1717: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable path
nvd
CVE-2024-2609P4MEDIUMCVSS 6.1fixed in 115.10.0fixed in 124.0+1 more2024-03-19
CVE-2024-2609 [MEDIUM] CWE-356 CVE-2024-2609: The permission prompt input delay could expire while the window is not in focus. This makes it vulne
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvdosv
CVE-2024-5693P4MEDIUMCVSS 6.1fixed in 115.12fixed in 127.0+1 more2024-06-11
CVE-2024-5693 [MEDIUM] CWE-829 CVE-2024-5693: Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image d
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2011-3665P4HIGHCVSS 7.5v4.0v4.0.1+8 more2011-12-21
CVE-2011-3665 [HIGH] CWE-399 CVE-2011-3665: Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an Ogg VIDEO element that is not properly handled after scaling.
nvd
CVE-2023-4049P4MEDIUMCVSS 5.9fixed in 116.0≥ 102.0, < 102.14+2 more2023-08-01
CVE-2023-4049 [MEDIUM] CWE-362 CVE-2023-4049: Race conditions in reference counting code were found through code inspection. These could have resu
Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2020-12413P4MEDIUMCVSS 5.9fixed in 78.0≥ unspecified, < 782023-02-16
CVE-2020-12413 [MEDIUM] CWE-203 CVE-2020-12413: The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitig
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
nvd
CVE-2022-22746P4MEDIUMCVSS 5.9fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22746 [MEDIUM] CWE-362 CVE-2022-22746: A race condition could have allowed bypassing the fullscreen notification which could have lead to a
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2011-0071P4MEDIUMCVSS 5.0v3.6v3.6.2+101 more2011-05-07
CVE-2011-0071 [MEDIUM] CWE-22 CVE-2011-0071: Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderb
Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL.
nvd
CVE-2008-4067P4MEDIUMCVSS 4.3fixed in 2.0.0.17≥ 3.0, < 3.0.22008-09-24
CVE-2008-4067 [MEDIUM] CWE-22 CVE-2008-4067: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbi
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI.
nvd
CVE-2017-7791P4MEDIUMCVSS 5.3fixed in 55.0fixed in 52.3.0+1 more2018-06-11
CVE-2017-7791 [MEDIUM] CWE-20 CVE-2017-7791: On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will re
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2005-1154P4HIGHCVSS 7.5v0.8v0.9+8 more2005-05-02
CVE-2005-1154 [HIGH] CVE-2005-1154: Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary scr
Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."
nvd
CVE-2021-29955P4MEDIUMCVSS 5.3fixed in 87.0≥ unspecified, < 872021-06-24
CVE-2021-29955 [MEDIUM] CWE-74 CVE-2021-29955: A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker
A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.
nvd
CVE-2015-0798P4MEDIUMCVSS 5.0≤ 37.02015-04-08
CVE-2015-0798 [MEDIUM] CWE-264 CVE-2015-0798: The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release
The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.
nvd
CVE-2019-11698P4MEDIUMCVSS 5.3fixed in 60.7.0fixed in 67.0+1 more2019-07-23
CVE-2019-11698 [MEDIUM] CWE-20 CVE-2019-11698: If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookm
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This
nvd
CVE-2008-1237P4MEDIUMCVSS 6.8≤ 2.0.0.122008-03-27
CVE-2008-1237 [MEDIUM] CWE-399 CVE-2008-1237: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.
nvd
CVE-2026-15719P4MEDIUMCVSS 5.4fixed in 152.0.62026-07-14
CVE-2026-15719 [MEDIUM] CVE-2026-15719: We are aware that exploit code for this is public however we are not aware of any attacks in the wil
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
nvdmozilla
CVE-2007-3072P4HIGHCVSS 7.1v2.0v2.0.0.1+2 more2007-06-06
CVE-2007-3072 [HIGH] CWE-22 CVE-2007-3072: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attacke
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.
nvd
CVE-2012-3984P4MEDIUMCVSS 6.8fixed in 16.02012-10-10
CVE-2012-3984 [MEDIUM] CVE-2012-3984: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly hand
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page content via vectors involving absolute positioning and scrolling.
nvd
CVE-2013-0747P4MEDIUMCVSS 6.8fixed in 17.0.2fixed in 18.02013-01-13
CVE-2013-0747 [MEDIUM] CWE-20 CVE-2013-0747: The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefo
The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not properly enforce the Same Origin Policy, which allows remote attackers to conduct clickjacking attacks via crafted JavaScript code
nvd