cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 118 of 162
CVE-2026-0883P4MEDIUMCVSS 5.3fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0883 [MEDIUM] CWE-200 CVE-2026-0883: Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Fir Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvd
CVE-2026-9308P4MEDIUMCVSS 5.4fixed in 151.22026-06-01
CVE-2026-9308 [MEDIUM] CWE-79 CVE-2026-9308: Firefox for iOS Reader View replaced page content in its HTML template before replacing other intern Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.
nvd
CVE-2026-9309P4MEDIUMCVSS 5.4fixed in 151.22026-06-01
CVE-2026-9309 [MEDIUM] CWE-79 CVE-2026-9309: Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was
nvd
CVE-2024-8388P4MEDIUMCVSS 5.3fixed in 130.02024-09-03
CVE-2024-8388 [MEDIUM] CVE-2024-8388: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notifi Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser UI if the sudden appearance of the prompt distracted the user from noticing the visual transition happening behind the pr
nvd
CVE-2024-10460P4MEDIUMCVSS 5.3fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10460 [MEDIUM] CWE-346 CVE-2024-10460: The origin of an external protocol handler prompt could have been obscured using a data: URL within The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-12329P4MEDIUMCVSS 5.3≥ 140.0, < 140.12.02026-06-16
CVE-2026-12329 [MEDIUM] CWE-119 CVE-2026-12329: Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.1 Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
nvd
CVE-2026-0888P4MEDIUMCVSS 5.3fixed in 147.02026-01-13
CVE-2026-0888 [MEDIUM] CWE-200 CVE-2026-0888: Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunder Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
nvd
CVE-2026-12308P4MEDIUMCVSS 5.3fixed in Firefox 152
CVE-2026-12308 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12308 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12308 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2026-12306P4MEDIUMCVSS 5.3fixed in Firefox 152
CVE-2026-12306 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12306 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12306 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2026-12307P4MEDIUMCVSS 5.3fixed in Firefox 152
CVE-2026-12307 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12307 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12307 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2015-4504P4MEDIUMCVSS 6.4≤ 40.0.32015-09-24
CVE-2015-4504 [MEDIUM] CWE-119 CVE-2015-4504: The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote a The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.
nvdosv
CVE-2026-6767P4MEDIUMCVSS 5.3fixed in 115.35.0fixed in 150.0+1 more2026-04-21
CVE-2026-6767 [MEDIUM] CWE-119 CVE-2026-6767: Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6765P4MEDIUMCVSS 5.3fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6765 [MEDIUM] CWE-359 CVE-2026-6765: Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2009-3984P4MEDIUMCVSS 6.8≤ 3.0.15v0.1+97 more2009-12-17
CVE-2009-3984 [MEDIUM] CVE-2009-3984: Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote atta Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.
nvd
CVE-2015-7216P4MEDIUMCVSS 6.8≤ 42.02015-12-16
CVE-2015-7216 [MEDIUM] CWE-20 CVE-2015-7216: The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly ena The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.
nvdosv
CVE-2015-0811P4MEDIUMCVSS 6.4≤ 36.0.42015-04-01
CVE-2015-0811 [MEDIUM] CWE-119 CVE-2015-0811: The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive i The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.
nvdosv
CVE-2011-2980P4HIGHCVSS 7.2≤ 3.6.19v1.0+105 more2011-08-18
CVE-2011-2980 [HIGH] CVE-2011-2980: Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox befor Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows local users to gain privileges by leveraging write access in an unspecified directory to place a Trojan horse DLL that is loaded into the running Firefox process.
nvd
CVE-2016-2822P4MEDIUMCVSS 6.5v45.1.0v45.1.1+1 more2016-06-13
CVE-2016-2822 [MEDIUM] CWE-284 CVE-2016-2822: Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the add Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
nvd
CVE-2015-0807P4MEDIUMCVSS 6.8≤ 36.0.4v31.0+6 more2015-04-01
CVE-2015-0807 [MEDIUM] CVE-2015-0807: The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6 The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted w
nvdosv
CVE-2011-3666P4MEDIUMCVSS 6.8≤ 3.6.24v0.1+124 more2011-12-21
CVE-2011-3666 [MEDIUM] CVE-2011-3666: Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files t Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.
nvd
Mozilla Firefox vulnerabilities | cvebase