cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 121 of 162
CVE-2025-13013P4MEDIUMCVSS 6.1fixed in 115.30.0fixed in 145.0+1 more2025-11-11
CVE-2025-13013 [MEDIUM] CWE-288 CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Fi Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
nvd
CVE-2013-1695P4MEDIUMCVSS 5.0≤ 21.0v19.0+4 more2013-06-26
CVE-2013-1695 [MEDIUM] CWE-264 CVE-2013-1695: Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for th Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME element.
nvd
CVE-2015-7215P4MEDIUMCVSS 5.0≤ 42.02015-12-16
CVE-2015-7215 [MEDIUM] CWE-200 CVE-2015-7215: The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allo The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.
nvdosv
CVE-2024-4772P4MEDIUMCVSS 5.9fixed in 126.0≥ unspecified, < 1262024-05-14
CVE-2024-4772 [MEDIUM] CWE-338 CVE-2024-4772: An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictab An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.
nvdosv
CVE-2018-5165P4MEDIUMCVSS 5.3fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5165 [MEDIUM] CVE-2018-5165: In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. This could cause users to select this setting intending to activate it and inadvertently turn
nvd
CVE-2017-7825P4MEDIUMCVSS 5.3fixed in 52.4.0fixed in 56.0+1 more2018-06-11
CVE-2017-7825 [MEDIUM] CWE-20 CVE-2017-7825: Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the add Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.
nvd
CVE-2017-7831P4MEDIUMCVSS 5.3≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7831 [MEDIUM] CWE-200 CVE-2017-7831: A vulnerability where the security wrapper does not deny access to some exposed properties using the A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy objects. These properties should be explicitly unavailable to proxy objects. This vulnerability affects Firefox < 57.
nvdosv
CVE-2020-6812P4MEDIUMCVSS 5.3fixed in 74.0≥ unspecified, < 74+1 more2020-03-25
CVE-2020-6812 [MEDIUM] CWE-200 CVE-2020-6812: The first time AirPods are connected to an iPhone, they become named after the user's name by defaul The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to sim
nvd
CVE-2012-0445P4MEDIUMCVSS 5.0v4.0v4.0.1+9 more2012-02-01
CVE-2012-0445 [MEDIUM] CWE-264 CVE-2012-0445: Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to bypass the HTML5 frame-navigation policy and replace arbitrary sub-frames by creating a form submission target with a sub-frame's name attribute.
nvd
CVE-2008-5012P4MEDIUMCVSS 5.0≤ 2.0.0.17v0.8+55 more2008-11-13
CVE-2008-5012 [MEDIUM] CWE-200 CVE-2008-5012: Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.1 Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue
nvd
CVE-2020-6813P4MEDIUMCVSS 5.3fixed in 74.0≥ unspecified, < 742020-03-25
CVE-2020-6813 [MEDIUM] CVE-2020-6813: When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.
nvdosv
CVE-2024-2611P4MEDIUMCVSS 5.5fixed in 115.9.0fixed in 124.0+1 more2024-03-19
CVE-2024-2611 [MEDIUM] CVE-2024-2611: A missing delay on when pointer lock was used could have allowed a malicious page to trick a user in A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2019-11761P4MEDIUMCVSS 5.4fixed in 70.0vbefore 702020-01-08
CVE-2019-11761 [MEDIUM] CWE-362 CVE-2019-11761: By using a form with a data URI it was possible to gain access to the privileged JSONView object tha By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2021-29965P4MEDIUMCVSS 5.3fixed in 89.0≥ unspecified, < 892021-06-24
CVE-2021-29965 [MEDIUM] CWE-610 CVE-2021-29965: A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the currently active website instead of the website that triggered the dialog. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.
nvd
CVE-2008-5512P4MEDIUMCVSS 6.8≥ 2.0, < 2.0.0.19≥ 3.0, < 3.0.52008-12-17
CVE-2008-5512 [MEDIUM] CWE-264 CVE-2008-5512: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Th Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."
nvd
CVE-2024-11696P4MEDIUMCVSS 5.4fixed in 128.5.0fixed in 133.0+1 more2024-11-26
CVE-2024-11696 [MEDIUM] CWE-347 CVE-2024-11696: The application failed to account for exceptions thrown by the `loadManifestFromFile` method during The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated ad
nvd
CVE-2023-4045P4MEDIUMCVSS 5.3fixed in 116.0≥ 102.0, < 102.14+2 more2023-08-01
CVE-2023-4045 [MEDIUM] CWE-346 CVE-2023-4045: Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2026-12298P4MEDIUMCVSS 5.4fixed in 152.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12298 [MEDIUM] CWE-125 CVE-2026-12298: Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2024-53976P4MEDIUMCVSS 5.4fixed in 133.02024-11-26
CVE-2024-53976 [MEDIUM] CWE-1021 CVE-2024-53976: Under certain circumstances, navigating to a webpage would result in the address missing from the lo Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
nvd
CVE-2025-54144P4MEDIUMCVSS 5.4fixed in 141.02025-08-19
CVE-2025-54144 [MEDIUM] CWE-601 CVE-2025-54144: The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attac The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link. This vulnerability was fixed in Firefox for iOS 141.
nvd
Mozilla Firefox vulnerabilities | cvebase