Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 120 of 162
CVE-2018-5175P4MEDIUMCVSS 6.1fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5175 [MEDIUM] CWE-79 CVE-2018-5175: A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" po
A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the "require.js" library that is part of Firefox's Developer Tools, and then use a known technique using that library to byp
nvdosv
CVE-2018-5176P4MEDIUMCVSS 6.1fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5176 [MEDIUM] CWE-20 CVE-2018-5176: The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "jav
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization to
nvdosv
CVE-2022-31746P4MEDIUMCVSS 6.5fixed in 102.02022-12-22
CVE-2022-31746 [MEDIUM] CWE-200 CVE-2022-31746: Internal URLs are protected by a secret UUID key, which could have been leaked to web page through t
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.
nvd
CVE-2025-55028P4MEDIUMCVSS 6.5fixed in 142.02025-08-19
CVE-2025-55028 [MEDIUM] CWE-400 CVE-2025-55028: Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in so
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed in Firefox for iOS 142.
nvd
CVE-2020-26951P4MEDIUMCVSS 6.1fixed in 83.0fixed in 832020-12-09
CVE-2020-26951 [MEDIUM] CWE-79 CVE-2020-26951: A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, e
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbi
nvd
CVE-2018-5124P4MEDIUMCVSS 6.1fixed in 58.0.1vAll versions prior to Firefox 58.0.12019-04-26
CVE-2018-5124 [MEDIUM] CWE-79 CVE-2018-5124: Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code exec
Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.
nvdosv
CVE-2005-0230P4MEDIUMCVSS 5.1v1.02005-05-02
CVE-2005-0230 [MEDIUM] CVE-2005-0230: Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an
Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "f
nvd
CVE-2021-29944P4MEDIUMCVSS 6.1fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-29944 [MEDIUM] CWE-79 CVE-2021-29944: Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Se
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 88.
nvd
CVE-2017-5462P4MEDIUMCVSS 5.3fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5462 [MEDIUM] CWE-682 CVE-2017-5462: A flaw in DRBG number generation within the Network Security Services (NSS) library where the intern
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Fir
nvd
CVE-2022-45411P4MEDIUMCVSS 6.1fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45411 [MEDIUM] CWE-79 CVE-2022-45411: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an X
Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on fetch() and XMLHttpRequest; however some webservers have implemented non-sta
nvd
CVE-2024-10461P4MEDIUMCVSS 6.1fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10461 [MEDIUM] CWE-79 CVE-2024-10461: In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2022-29911P4MEDIUMCVSS 6.1fixed in 100.0≥ unspecified, < 1002022-12-22
CVE-2022-29911 [MEDIUM] CWE-1021 CVE-2022-29911: An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-acti
An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2024-4768P4MEDIUMCVSS 6.1fixed in 115.11.0fixed in 126.0+1 more2024-05-14
CVE-2024-4768 [MEDIUM] CWE-281 CVE-2024-4768: A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a us
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2024-1549P4MEDIUMCVSS 6.1fixed in 115.8.0fixed in 123.0+1 more2024-02-20
CVE-2024-1549 [MEDIUM] CVE-2024-1549: If a website set a large custom cursor, portions of the cursor could have overlapped with the permis
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2016-9064P4MEDIUMCVSS 5.9fixed in 45.5.0fixed in 50.0+1 more2018-06-11
CVE-2016-9064 [MEDIUM] CWE-295 CVE-2016-9064: Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the a
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update. This vulnerabili
nvd
CVE-2024-11694P4MEDIUMCVSS 6.1fixed in 115.8.0fixed in 133.0+2 more2024-11-26
CVE-2024-11694 [MEDIUM] CWE-79 CVE-2024-11694: Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass a
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ES
nvd
CVE-2024-7524P4MEDIUMCVSS 6.1fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7524 [MEDIUM] CWE-79 CVE-2024-7524: Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking
Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. Thi
nvd
CVE-2005-1159P4HIGHCVSS 7.5v0.8v0.9+8 more2005-05-02
CVE-2005-1159 [HIGH] CVE-2005-1159: The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla
The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly exec
nvd
CVE-2023-49061P4MEDIUMCVSS 6.1fixed in 120.02023-11-21
CVE-2023-49061 [MEDIUM] CWE-601 CVE-2023-49061: An attacker could have performed HTML template injection via Reader Mode and exfiltrated user inform
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
nvd
CVE-2024-43111P4MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43111 [MEDIUM] CWE-79 CVE-2024-43111: Long pressing on a download link could potentially allow Javascript commands to be executed within t
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
nvd