Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 115 of 162
CVE-2009-1836P4MEDIUMCVSS 6.8≤ 3.0.10v0.1+89 more2009-06-12
CVE-2009-1836 [MEDIUM] CWE-287 CVE-2009-1836: Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
nvd
CVE-2016-1956P4MEDIUMCVSS 6.5≤ 44.0.22016-03-13
CVE-2016-1956 [MEDIUM] CWE-399 CVE-2016-1956: Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
nvd
CVE-2021-29964P4HIGHCVSS 7.1fixed in 89.0≥ unspecified, < 892021-06-24
CVE-2021-29964 [HIGH] CWE-125 CVE-2021-29964: A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process inc
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
nvd
CVE-2007-0802P4MEDIUMCVSS 6.4v2.0.0.12007-02-07
CVE-2007-0802 [MEDIUM] CWE-20 CVE-2007-0802: Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by addin
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.
nvd
CVE-2012-0460P4MEDIUMCVSS 6.4v4.0v4.0.1+12 more2012-03-14
CVE-2012-0460 [MEDIUM] CWE-264 CVE-2012-0460: Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thun
Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote attackers to spoof the user interface via a crafted web page.
nvd
CVE-2018-5111P4MEDIUMCVSS 6.5≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5111 [MEDIUM] CWE-20 CVE-2018-5111: When the text of a specially formatted URL is dragged to the addressbar from page content, the displ
When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.
nvdosv
CVE-2021-43545P4MEDIUMCVSS 6.5fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43545 [MEDIUM] CWE-834 CVE-2021-43545: Using the Location API in a loop could have caused severe application hangs and crashes. This vulner
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2012-1950P4MEDIUMCVSS 6.4v4.0v4.0.1+20 more2012-07-18
CVE-2012-1950 [MEDIUM] CVE-2012-1950: The drag-and-drop implementation in Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.
The drag-and-drop implementation in Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 allows remote attackers to spoof the address bar by canceling a page load.
nvd
CVE-2019-11721P4MEDIUMCVSS 6.5fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11721 [MEDIUM] CVE-2019-11721: The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. T
The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.
nvdosv
CVE-2013-6673P4MEDIUMCVSS 5.9fixed in 26.0≥ 24.0, < 24.22013-12-11
CVE-2013-6673 [MEDIUM] CWE-310 CVE-2013-6673: Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey be
Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that is unacceptable to the user.
nvd
CVE-2016-5260P4MEDIUMCVSS 6.5≤ 47.0.12016-08-05
CVE-2016-5260 [MEDIUM] CWE-200 CVE-2016-5260: Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' w
Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.
nvdosv
CVE-2019-17023P4MEDIUMCVSS 6.5fixed in 72.0vbefore 722020-01-08
CVE-2019-17023 [MEDIUM] CWE-287 CVE-2019-17023: After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, res
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
nvd
CVE-2016-2829P4MEDIUMCVSS 6.5≤ 46.0.12016-06-13
CVE-2016-2829 [MEDIUM] CWE-284 CVE-2016-2829: Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.
nvdosv
CVE-2019-11750P4MEDIUMCVSS 6.5fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11750 [MEDIUM] CWE-843 CVE-2019-11750: A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. Thi
A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2020-6808P4MEDIUMCVSS 6.5fixed in 74.0≥ unspecified, < 742020-03-25
CVE-2020-6808 [MEDIUM] CWE-290 CVE-2020-6808: When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed t
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.location property, for example) was the originating javascript: URL which could lead to spoofing attacks; it is now correctly the URL of the
nvdosv
CVE-2021-23970P4MEDIUMCVSS 6.5fixed in 86.0fixed in 862021-02-26
CVE-2021-23970 [MEDIUM] CWE-617 CVE-2021-23970: Context-specific code was included in a shared jump table; resulting in assertions being triggered i
Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability affects Firefox < 86.
nvdosv
CVE-2019-17016P4MEDIUMCVSS 6.1fixed in 72.0vbefore 722020-01-08
CVE-2019-17016 [MEDIUM] CWE-79 CVE-2019-17016: When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incor
When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2022-40960P4MEDIUMCVSS 6.5fixed in 105.0≥ unspecified, < 1052022-12-22
CVE-2022-40960 [MEDIUM] CWE-416 CVE-2022-40960: Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-a
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2021-43540P4MEDIUMCVSS 6.5fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43540 [MEDIUM] CVE-2021-43540: WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-
WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension. This vulnerability affects Firefox < 95.
nvdosv
CVE-2022-22760P4MEDIUMCVSS 6.5fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22760 [MEDIUM] CWE-209 CVE-2022-22760: When importing resources using Web Workers, error messages would distinguish the difference between
When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd