Mozilla Firefox vulnerabilities

3,197 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,197
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL865HIGH944MEDIUM1312LOW71UNKNOWN5

Vulnerabilities

Page 126 of 160
CVE-2010-3171MEDIUMCVSS 5.8PoCv3.5.10v3.5.11+5 more2010-09-15
CVE-2010-3171 [MEDIUM] CWE-310 CVE-2010-3171: The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed
nvd
CVE-2010-3166CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-3166 [CRITICAL] CWE-119 CVE-2010-3166: Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a bidirectional text run.
nvd
CVE-2010-2766CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2766 [CRITICAL] CWE-94 CVE-2010-2766: The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.
nvd
CVE-2010-2767CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2767 [CRITICAL] CWE-399 CVE-2010-2767: The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunde The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via craft
nvd
CVE-2010-2765CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2765 [CRITICAL] CWE-189 CVE-2010-2765: Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x b Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading to a heap-based buffer overflow.
nvd
CVE-2010-3167CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-3167 [CRITICAL] CWE-119 CVE-2010-3167: The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer v
nvd
CVE-2010-2770CRITICALCVSS 9.3v3.6v3.6.2+104 more2010-09-09
CVE-2010-2770 [CRITICAL] CWE-119 CVE-2010-2770: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1. Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.
nvd
CVE-2010-3168CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-3168 [CRITICAL] CWE-119 CVE-2010-3168: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1. Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to cause a denial of service (deleted memory access and application crash) or possibly execute arbitrary
nvd
CVE-2010-2760CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2760 [CRITICAL] CVE-2010-2760: Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3. Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue ex
nvd
CVE-2010-3169CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-3169 [CRITICAL] CVE-2010-3169: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6. Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-2762MEDIUMCVSS 6.8v3.6v3.6.2+5 more2010-09-09
CVE-2010-2762 [MEDIUM] CWE-264 CVE-2010-2762: The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Fir The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privilege
nvd
CVE-2010-2764MEDIUMCVSS 4.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2764 [MEDIUM] CWE-264 CVE-2010-2764: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1. Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers to discover the existence of intranet web servers via cross-origin requests.
nvd
CVE-2010-2768MEDIUMCVSS 4.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2768 [MEDIUM] CWE-79 CVE-2010-2768: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1. Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
nvd
CVE-2010-2769MEDIUMCVSS 4.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2769 [MEDIUM] CWE-79 CVE-2010-2769: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Th Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.
nvd
CVE-2010-2763MEDIUMCVSS 4.3≤ 3.5.11v1.0+79 more2010-09-09
CVE-2010-2763 [MEDIUM] CWE-79 CVE-2010-2763: The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Fir The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.
nvd
CVE-2010-3131CRITICALCVSS 9.3PoCv3.6v3.6.2+86 more2010-08-26
CVE-2010-3131 [CRITICAL] CVE-2010-3131: Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunder Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder
nvd
CVE-2010-1214CRITICALCVSS 9.3PoCv3.5.1v3.5.2+12 more2010-07-30
CVE-2010-1214 [CRITICAL] CWE-189 CVE-2010-1214: Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.
nvd
CVE-2010-2752CRITICALCVSS 9.3PoCv3.5.1v3.5.2+12 more2010-07-30
CVE-2010-2752 [CRITICAL] CWE-189 CVE-2010-2752: Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Th Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an
nvd
CVE-2010-1212CRITICALCVSS 9.3v3.6.1v3.6.2+3 more2010-07-30
CVE-2010-1212 [CRITICAL] CWE-119 CVE-2010-1212: js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1. js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) propagation of deep aborts in the TraceRecorder::record_JSOP_BINDNAME function,
nvd
CVE-2010-2755CRITICALCVSS 10.0v3.6.72010-07-30
CVE-2010-2755 [CRITICAL] CVE-2010-2755: layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the param layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerabili
nvd