Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 125 of 162
CVE-2017-7789P4MEDIUMCVSS 5.3fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7789 [MEDIUM] CVE-2017-7789: If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.
nvdosv
CVE-2016-1939P4MEDIUMCVSS 5.3≤ 43.0.42016-01-31
CVE-2016-1939 [MEDIUM] CVE-2016-1939: Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allo
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7208.
nvdosv
CVE-2018-12382P4MEDIUMCVSS 5.3v62.0≥ unspecified, < 622018-10-18
CVE-2018-12382 [MEDIUM] CWE-20 CVE-2018-12382: The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concer
The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loaded domain name, scrolling the loaded domain out of view to the right. This can lead to user confusion. *This vulnerability only affects Firefox for Android < 62.*
nvd
CVE-2004-0779P4HIGHCVSS 7.5v0.82004-08-18
CVE-2004-0779 [HIGH] CVE-2004-0779: The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that c
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
nvd
CVE-2018-5118P4MEDIUMCVSS 5.3≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5118 [MEDIUM] CWE-200 CVE-2018-5118: The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is cr
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue was discovered where the page could attempt to create these images through "file:" URLs from the local file system. This loading is blocked by the sandbox but could expose local data if combined with anothe
nvdosv
CVE-2018-5119P4MEDIUMCVSS 5.3≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5119 [MEDIUM] CWE-200 CVE-2018-5119: The reader view will display cross-origin content when CORS headers are set to prohibit the loading
The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could allow access to content that should be restricted in reader view. This vulnerability affects Firefox < 58.
nvdosv
CVE-2018-12400P4MEDIUMCVSS 5.3fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12400 [MEDIUM] CWE-200 CVE-2018-12400: In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as th
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63.
nvd
CVE-2008-5505P4MEDIUMCVSS 5.0≤ 3.0.4v3.0+3 more2008-12-17
CVE-2008-5505 [MEDIUM] CWE-264 CVE-2008-5505: Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by
Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.
nvd
CVE-2013-0759P4MEDIUMCVSS 5.0fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0759 [MEDIUM] CWE-287 CVE-2013-0759: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to spoof the address bar via vectors involving authentication information in the userinfo field of a URL, in conjunction with a 204
nvd
CVE-2017-7832P4MEDIUMCVSS 5.3≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7832 [MEDIUM] CWE-20 CVE-2017-7832: The combined, single character, version of the letter 'i' with any of the potential accents in unico
The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display a
nvdosv
CVE-2017-5463P4MEDIUMCVSS 5.3fixed in 53.0≥ unspecified, < 532018-06-11
CVE-2017-5463 [MEDIUM] CWE-20 CVE-2017-5463: Android intents can be used to launch Firefox for Android in reader mode with a user specified URL.
Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of the addressbar as displayed to users. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.
nvd
CVE-2018-5110P4MEDIUMCVSS 5.3≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5110 [MEDIUM] CWE-20 CVE-2018-5110: If cursor visibility is toggled by script using from 'none' to an image and back through script, the
If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible within Firefox. Note: This vulnerability only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 58.
nvd
CVE-2011-0067P4MEDIUMCVSS 5.0v3.6v3.6.2+101 more2011-05-07
CVE-2011-0067 [MEDIUM] CWE-20 CVE-2011-0067: Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properl
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.
nvd
CVE-2017-5426P4MEDIUMCVSS 5.3fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5426 [MEDIUM] CWE-732 CVE-2017-5426: On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plug
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. Note: this issue only affects Linux. Other operating systems
nvdosv
CVE-2019-11718P4MEDIUMCVSS 5.3fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11718 [MEDIUM] CWE-74 CVE-2019-11718: Activity Stream can display content from sent from the Snippet Service website. This content is writ
Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Fire
nvdosv
CVE-2018-5142P4MEDIUMCVSS 5.3fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5142 [MEDIUM] CVE-2018-5142: If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs
If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.
nvdosv
CVE-2023-4046P4MEDIUMCVSS 5.3fixed in 116.0≥ 102.0, < 102.14+2 more2023-08-01
CVE-2023-4046 [MEDIUM] CWE-770 CVE-2023-4046: In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis
In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2017-7817P4MEDIUMCVSS 5.3≤ 55.0.3≥ unspecified, < 562018-06-11
CVE-2017-7817 [MEDIUM] CWE-20 CVE-2017-7817: A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification
A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. This allows an attacker to spoof which page is actually loaded and in use. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 5
nvd
CVE-2017-7763P4MEDIUMCVSS 5.3fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7763 [MEDIUM] CWE-20 CVE-2017-7763: Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2023-6206P4MEDIUMCVSS 5.4fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6206 [MEDIUM] CWE-1021 CVE-2023-6206: The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking dela
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvdosv