cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 126 of 162
CVE-2024-11695P4MEDIUMCVSS 5.4fixed in 128.5.0fixed in 133.0+1 more2024-11-26
CVE-2024-11695 [MEDIUM] CWE-1021 CVE-2024-11695: A crafted URL containing Arabic script and whitespace characters could have hidden the true origin o A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2023-5723P4MEDIUMCVSS 5.3fixed in 119.0≥ unspecified, < 1192023-10-25
CVE-2023-5723 [MEDIUM] CVE-2023-5723: An attacker with temporary script access to a site could have set a cookie containing invalid charac An attacker with temporary script access to a site could have set a cookie containing invalid characters using `document.cookie` that could have led to unknown errors. This vulnerability affects Firefox < 119.
nvdosv
CVE-2024-9398P4MEDIUMCVSS 5.3fixed in 131.0≥ unspecified, < 1312024-10-01
CVE-2024-9398 [MEDIUM] CWE-203 CVE-2024-9398: By checking the result of calls to `window.open` with specifically set protocol handlers, an attacke By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2026-12299P4MEDIUMCVSS 5.4fixed in 115.37.0fixed in 152.0+1 more2026-06-16
CVE-2026-12299 [MEDIUM] CWE-843 CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, F JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-0890P4MEDIUMCVSS 5.4fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0890 [MEDIUM] CWE-290 CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in F Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvd
CVE-2025-10531P4MEDIUMCVSS 5.4fixed in 143.02025-09-16
CVE-2025-10531 [MEDIUM] CWE-288 CVE-2025-10531: Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firef Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2026-12330P4MEDIUMCVSS 5.4fixed in 115.37.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12330 [MEDIUM] CWE-119 CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12.
nvd
CVE-2024-3862P4MEDIUMCVSS 5.3fixed in 125.0≥ unspecified, < 1252024-04-16
CVE-2024-3862 [MEDIUM] CWE-908 CVE-2024-3862: The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.
nvdosv
CVE-2026-6778P4MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6778 [MEDIUM] CWE-476 CVE-2026-6778: Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-12301P4MEDIUMCVSS 5.3fixed in Firefox 152
CVE-2026-12301 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12301 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12301 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2026-12300P4MEDIUMCVSS 5.3fixed in Firefox 152
CVE-2026-12300 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12300 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12300 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2026-6783P4MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6783 [MEDIUM] CWE-190 CVE-2026-6783: Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnera Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-6775P4MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6775 [MEDIUM] CWE-119 CVE-2026-6775: Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 a Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-6779P4MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6779 [MEDIUM] CWE-20 CVE-2026-6779: Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thun Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2014-1577P4MEDIUMCVSS 6.4v31.0v31.1.0+2 more2014-10-15
CVE-2014-1577 [MEDIUM] CVE-2014-1577: The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via an i
nvdosv
CVE-2007-3285P4MEDIUMCVSS 6.8≤ 2.0.0.4v0.8+39 more2007-06-20
CVE-2007-3285 [MEDIUM] CWE-264 CVE-2007-3285: Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type che Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.
nvd
CVE-2011-3062P4MEDIUMCVSS 6.8fixed in 10.0.4fixed in 12.02012-03-30
CVE-2011-3062 [MEDIUM] CWE-682 CVE-2011-3062: Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attac Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
nvd
CVE-2014-1506P4MEDIUMCVSS 6.4≤ 27.0.1v0.1+198 more2014-03-19
CVE-2014-1506 [MEDIUM] CWE-22 CVE-2014-1506: Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Androi Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.
nvd
CVE-2012-1942P4HIGHCVSS 7.2v12.02012-06-05
CVE-2012-1942 [HIGH] CWE-264 CVE-2012-1942: The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMo The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain privileges by loading a DLL file in a privileged context.
nvd
CVE-2011-0059P4MEDIUMCVSS 6.8v3.6v3.6.2+96 more2011-03-02
CVE-2011-0059 [MEDIUM] CWE-352 CVE-2011-0059: Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3. Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.
nvd
Mozilla Firefox vulnerabilities | cvebase