cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 119 of 162
CVE-2011-2367P4MEDIUMCVSS 6.4v4.0v4.0.12011-06-30
CVE-2011-2367 [MEDIUM] CWE-264 CVE-2011-2367: The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operat The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors.
nvd
CVE-2021-23973P4MEDIUMCVSS 6.5fixed in 86.0fixed in 862021-02-26
CVE-2021-23973 [MEDIUM] CWE-209 CVE-2021-23973: When trying to load a cross-origin resource in an audio/video context a decoding error may have resu When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2017-5420P4MEDIUMCVSS 6.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5420 [MEDIUM] CWE-20 CVE-2017-5420: A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displa A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.
nvdosv
CVE-2016-5298P4MEDIUMCVSS 6.5fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-5298 [MEDIUM] CWE-20 CVE-2016-5298: A mechanism where disruption of the loading of a new web page can cause the previous page's favicon A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when the new page is loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected. This vulnerability affects Firefox < 50.
nvd
CVE-2020-15648P4MEDIUMCVSS 6.5fixed in 78.0.2≥ unspecified, < 78.0.22020-08-10
CVE-2020-15648 [MEDIUM] CWE-1021 CVE-2020-15648: Using object or embed tags, it was possible to frame other websites, even if they disallowed framing Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
nvdosv
CVE-2020-6798P4MEDIUMCVSS 6.1fixed in 73.0≥ unspecified, < 73+1 more2020-03-02
CVE-2020-6798 [MEDIUM] CWE-79 CVE-2020-6798: If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsin If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because
nvd
CVE-2021-23971P4MEDIUMCVSS 6.5fixed in 86.0fixed in 862021-02-26
CVE-2021-23971 [MEDIUM] CVE-2021-23971: When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redire When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect. This vulnerability affects Firefox < 86.
nvdosv
CVE-2021-23958P4MEDIUMCVSS 6.5fixed in 85.0fixed in 852021-02-26
CVE-2021-23958 [MEDIUM] CWE-668 CVE-2021-23958: The browser could have been confused into transferring a screen sharing state into another tab, whic The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.
nvdosv
CVE-2021-38491P4MEDIUMCVSS 6.5fixed in 92.0≥ unspecified, < 922021-11-03
CVE-2021-38491 [MEDIUM] CVE-2021-38491: Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loa Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox < 92.
nvdosv
CVE-2019-11699P4MEDIUMCVSS 6.5fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11699 [MEDIUM] CVE-2019-11699: A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addres A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. This vulnerability affects Firefox < 67.
nvdosv
CVE-2020-26967P4MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26967 [MEDIUM] CVE-2020-26967: When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other than those that it injected into the page. This would lead to internal errors and unexpected behavior in the Screenshots code. This vulnerability affects Firefox < 83.
nvdosv
CVE-2020-12408P4MEDIUMCVSS 6.5fixed in 77.0≥ unspecified, < 772020-07-09
CVE-2020-12408 [MEDIUM] CVE-2020-12408: When browsing a document hosted on an IP address, an attacker could insert certain characters to fli When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the address bar. This vulnerability affects Firefox < 77.
nvdosv
CVE-2021-23983P4MEDIUMCVSS 6.5fixed in 87.0≥ unspecified, < 872021-03-31
CVE-2021-23983 [MEDIUM] CWE-787 CVE-2021-23983: By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker co By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.
nvdosv
CVE-2022-42929P4MEDIUMCVSS 6.5fixed in 106.0≥ unspecified, < 1062022-12-22
CVE-2022-42929 [MEDIUM] CWE-400 CVE-2022-42929: If a website called `window.print()` in a particular way, it could cause a denial of service of the If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvd
CVE-2020-12414P4MEDIUMCVSS 6.5fixed in 27.02020-07-09
CVE-2020-12414 [MEDIUM] CWE-459 CVE-2020-12414: IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewC IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.
nvd
CVE-2020-15677P4MEDIUMCVSS 6.1fixed in 81.0≥ unspecified, < 812020-10-01
CVE-2020-15677 [MEDIUM] CWE-601 CVE-2020-15677: By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site d By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2023-4578P4MEDIUMCVSS 6.5fixed in 117.0≥ unspecified, < 1172023-09-11
CVE-2023-4578 [MEDIUM] CWE-770 CVE-2023-4578: When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling ` When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117,
nvd
CVE-2020-15676P4MEDIUMCVSS 6.1fixed in 81.0≥ unspecified, < 812020-10-01
CVE-2020-15676 [MEDIUM] CWE-79 CVE-2020-15676: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2022-28287P4MEDIUMCVSS 6.5fixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28287 [MEDIUM] CWE-664 CVE-2022-28287: In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, l In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99.
nvdosv
CVE-2023-37456P4MEDIUMCVSS 6.5fixed in 1152023-07-12
CVE-2023-37456 [MEDIUM] CWE-476 CVE-2023-37456: The session restore helper crashed whenever there was no parameter sent to the message handler. This The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.
nvd
Mozilla Firefox vulnerabilities | cvebase