Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 124 of 162
CVE-2022-34474P4MEDIUMCVSS 6.1fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34474 [MEDIUM] CWE-601 CVE-2022-34474: Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it r
Even when an iframe was sandboxed with allow-top-navigation-by-user-activation, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.
nvdosv
CVE-2025-10536P4MEDIUMCVSS 6.2fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10536 [MEDIUM] CWE-200 CVE-2025-10536: Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 1
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvd
CVE-2022-34475P4MEDIUMCVSS 6.1fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34475 [MEDIUM] CWE-79 CVE-2022-34475: SVG <code><use></code> tags that referenced a same-origin document could have resulted in scri
SVG tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a same-origin JavaScript file containing the script to be executed. This vulnerability affects Firefox < 102.
nvdosv
CVE-2018-5117P4MEDIUMCVSS 5.3fixed in 58.0fixed in 52.6.0+1 more2018-06-11
CVE-2018-5117 [MEDIUM] CVE-2018-5117: If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird <
nvd
CVE-2018-5168P4MEDIUMCVSS 5.3fixed in 52.8.0fixed in 60.0+1 more2018-06-11
CVE-2018-5168 [MEDIUM] CVE-2018-5168: Sites can bypass security checks on permissions to install lightweight themes by manipulating the "b
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and F
nvd
CVE-2024-8386P4MEDIUMCVSS 6.1fixed in 130.0≥ unspecified, < 1302024-09-03
CVE-2024-8386 [MEDIUM] CWE-601 CVE-2024-8386: If a site had been granted the permission to open popup windows, it could cause Select elements to a
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvd
CVE-2022-36316P4MEDIUMCVSS 6.1fixed in 103.0≥ unspecified, < 1032022-12-22
CVE-2022-36316 [MEDIUM] CWE-601 CVE-2022-36316: When using the Performance API, an attacker was able to notice subtle differences between Performanc
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.
nvdosv
CVE-2025-11712P4MEDIUMCVSS 6.1fixed in 140.4.0fixed in 144.02025-10-14
CVE-2025-11712 [MEDIUM] CWE-116 CVE-2025-11712: A malicious page could have used the type attribute of an OBJECT tag to override the default browser
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunder
nvd
CVE-2025-6430P4MEDIUMCVSS 6.1fixed in 128.12.0fixed in 140.02025-06-24
CVE-2025-6430 [MEDIUM] CWE-79 CVE-2025-6430: When a file download is specified via the `Content-Disposition` header, that directive would be igno
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
nvd
CVE-2014-1491P4MEDIUMCVSS 4.3fixed in 24.3fixed in 27.02014-02-06
CVE-2014-1491 [MEDIUM] CWE-326 CVE-2014-1491: Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firef
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanis
nvd
CVE-2016-2809P4MEDIUMCVSS 5.5≤ 45.0.22016-04-30
CVE-2016-2809 [MEDIUM] CWE-264 CVE-2016-2809: The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assist
The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.
nvd
CVE-2019-11717P4MEDIUMCVSS 5.3fixed in 60.8.0fixed in 68.0+1 more2019-07-23
CVE-2019-11717 [MEDIUM] CWE-116 CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2014-1583P4MEDIUMCVSS 5.0≤ 32.0v30.0+2 more2014-10-15
CVE-2014-1583 [MEDIUM] CVE-2014-1583: The Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x before 31.2 does not properly rest
The Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x before 31.2 does not properly restrict toJSON calls, which allows remote attackers to bypass the Same Origin Policy via crafted API calls that access sensitive information within the JSON data of an alarm.
nvdosv
CVE-2006-6497P4MEDIUMCVSS 6.8≤ 1.5.0.8v2.02006-12-20
CVE-2006-6497 [MEDIUM] CVE-2006-6497: Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.
Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors.
nvd
CVE-2006-6498P4MEDIUMCVSS 6.8v1.5v1.5.0.1+8 more2006-12-20
CVE-2006-6498 [MEDIUM] CVE-2006-6498: Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1
Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown impact
nvd
CVE-2017-7764P4MEDIUMCVSS 5.3fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7764 [MEDIUM] CWE-20 CVE-2017-7764: Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unico
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syl
nvd
CVE-2009-0355P4MEDIUMCVSS 5.4≤ 3.0.5v0.1+79 more2009-02-04
CVE-2009-0355 [MEDIUM] CWE-264 CVE-2009-0355: components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes
components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.
nvd
CVE-2018-12403P4MEDIUMCVSS 5.3fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12403 [MEDIUM] CVE-2018-12403: If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed conten
If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63.
nvdosv
CVE-2019-17021P4MEDIUMCVSS 5.3fixed in 72.0vbefore 722020-01-08
CVE-2019-17021 [MEDIUM] CWE-362 CVE-2019-17021: During the initialization of a new content process, a race condition occurs that can allow a content
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2018-12381P4MEDIUMCVSS 5.3fixed in 60.2.0fixed in 62.0+1 more2018-10-18
CVE-2018-12381 [MEDIUM] CWE-610 CVE-2018-12381: Manually dragging and dropping an Outlook email message into the browser will trigger a page navigat
Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Fi
nvd