cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 116 of 162
CVE-2023-32206P4MEDIUMCVSS 6.5fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32206 [MEDIUM] CWE-125 CVE-2023-32206: An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-25742P4MEDIUMCVSS 6.5fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25742 [MEDIUM] CVE-2023-25742: When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing th When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2022-22747P4MEDIUMCVSS 6.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22747 [MEDIUM] CWE-295 CVE-2022-22747: After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificat After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2022-26385P4MEDIUMCVSS 6.5fixed in 98.0≥ unspecified, < 982022-12-22
CVE-2022-26385 [MEDIUM] CWE-416 CVE-2022-26385: In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. Thi In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 98.
nvdosv
CVE-2021-4128P4MEDIUMCVSS 6.5fixed in 95.0≥ unspecified, < 952022-12-22
CVE-2021-4128 [MEDIUM] CWE-416 CVE-2021-4128: When transitioning in and out of fullscreen mode, a graphics object was not correctly protected; res When transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentially exploitable crash.*This bug only affects Firefox on MacOS. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.
nvd
CVE-2023-37205P4MEDIUMCVSS 6.5fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37205 [MEDIUM] CVE-2023-37205: The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerab The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115.
nvdosv
CVE-2023-28160P4MEDIUMCVSS 6.5fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28160 [MEDIUM] CWE-425 CVE-2023-28160: When following a redirect to a publicly accessible web extension file, the URL may have been transla When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking potentially sensitive information. This vulnerability affects Firefox < 111.
nvdosv
CVE-2022-36317P4MEDIUMCVSS 6.5fixed in 103.0≥ unspecified, < 1032022-12-22
CVE-2022-36317 [MEDIUM] CVE-2022-36317: When visiting a website with an overly long URL, the user interface would start to hang. Due to sess When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.
nvd
CVE-2023-29544P4MEDIUMCVSS 6.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29544 [MEDIUM] CWE-400 CVE-2023-29544: If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector c If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosv
CVE-2025-1934P4MEDIUMCVSS 6.5fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1934 [MEDIUM] CVE-2025-1934: It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, poten It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvd
CVE-2024-0754P4MEDIUMCVSS 6.5fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0754 [MEDIUM] CWE-248 CVE-2024-0754: Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.
nvdosv
CVE-2022-38475P4MEDIUMCVSS 6.5fixed in 104.0≥ unspecified, < 1042022-12-22
CVE-2022-38475 [MEDIUM] CWE-863 CVE-2022-38475: An attacker could have written a value to the first element in a zero-length JavaScript array. Altho An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not written to an invalid memory address. This vulnerability affects Firefox < 104.
nvdosv
CVE-2024-0752P4MEDIUMCVSS 6.5fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0752 [MEDIUM] CWE-416 CVE-2024-0752: A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122.
nvd
CVE-2024-3855P4MEDIUMCVSS 6.5fixed in 125.0≥ unspecified, < 1252024-04-16
CVE-2024-3855 [MEDIUM] CWE-125 CVE-2024-3855: In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
nvdosv
CVE-2024-10941P4MEDIUMCVSS 6.5fixed in 126.0≥ unspecified, < 1262024-11-06
CVE-2024-10941 [MEDIUM] CWE-86 CVE-2024-10941: A malicious website could have included an iframe with an malformed URI resulting in a non-exploitab A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.
nvdosv
CVE-2020-26958P4MEDIUMCVSS 6.1fixed in 83.0fixed in 832020-12-09
CVE-2020-26958 [MEDIUM] CWE-79 CVE-2020-26958: Firefox did not block execution of scripts with incorrect MIME types when the response was intercept Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-26978P4MEDIUMCVSS 6.1fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26978 [MEDIUM] CVE-2020-26978: Using techniques that built on the slipstream research, a malicious webpage could have exposed both Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2006-0293P4HIGHCVSS 7.5v1.52006-02-02
CVE-2006-0293 [HIGH] CVE-2006-0293: The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.
nvd
CVE-2025-23109P4MEDIUMCVSS 6.5fixed in 134.02025-01-11
CVE-2025-23109 [MEDIUM] CWE-346 CVE-2025-23109: Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the web Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.
nvd
CVE-2024-1551P4MEDIUMCVSS 6.1fixed in 115.8.0fixed in 123.0+1 more2024-02-20
CVE-2024-1551 [MEDIUM] CWE-565 CVE-2024-1551: Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attack Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, an
nvd
Mozilla Firefox vulnerabilities | cvebase