cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 127 of 162
CVE-2009-2065P4MEDIUMCVSS 6.8≤ 3.0.9v0.1+77 more2009-06-15
CVE-2009-2065 [MEDIUM] CWE-287 CVE-2009-2065: Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only wh Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP
nvd
CVE-2007-0779P4MEDIUMCVSS 6.4v0.8v0.9.1+28 more2007-02-26
CVE-2007-0779 [MEDIUM] CVE-2007-0779: GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMo GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.
nvd
CVE-2018-18510P4MEDIUMCVSS 6.5fixed in 64.0≥ unspecified, < 642019-04-26
CVE-2018-18510 [MEDIUM] CVE-2018-18510: The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.
nvdosv
CVE-2016-9895P4MEDIUMCVSS 6.1fixed in 50.1fixed in 45.6.0+1 more2018-06-11
CVE-2016-9895 [MEDIUM] CWE-254 CVE-2016-9895: Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) th Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2016-1975P4MEDIUMCVSS 6.3≤ 44.0.22016-03-13
CVE-2016-1975 [MEDIUM] CWE-362 CVE-2016-1975: Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation i Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-5164P4MEDIUMCVSS 6.1fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5164 [MEDIUM] CWE-79 CVE-2018-5164: Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with t Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60.
nvdosv
CVE-2017-5466P4MEDIUMCVSS 6.1fixed in 53.0fixed in 52.1.0+1 more2018-06-11
CVE-2017-5466 [MEDIUM] CWE-79 CVE-2017-5466: If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:tex If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2019-11744P4MEDIUMCVSS 6.1fixed in 60.9fixed in 69.0+2 more2019-09-27
CVE-2019-11744 [MEDIUM] CWE-79 CVE-2019-11744: Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets w Some HTML elements, such as and , can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as
nvd
CVE-2017-5458P4MEDIUMCVSS 6.1fixed in 53.0≥ unspecified, < 532018-06-11
CVE-2017-5458 [MEDIUM] CWE-79 CVE-2017-5458: When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processe When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.
nvdosv
CVE-2017-7799P4MEDIUMCVSS 6.1fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7799 [MEDIUM] CWE-79 CVE-2017-7799: JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is not under third-party control, making this difficult to exploit, but the vulnerability could possibly be used for a cross-site scripting (XSS) attack. This vulnerability affects Firefox < 55.
nvdosv
CVE-2008-5507P4MEDIUMCVSS 6.0≥ 2.0, < 2.0.0.19≥ 3.0, < 3.0.52008-12-17
CVE-2008-5507 [MEDIUM] CWE-200 CVE-2008-5507: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScri
nvd
CVE-2006-0296P4MEDIUMCVSS 5.0v0.8v0.9+14 more2006-02-02
CVE-2006-0296 [MEDIUM] CVE-2006-0296: The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does n The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.
nvd
CVE-2021-43543P4MEDIUMCVSS 6.1fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43543 [MEDIUM] CWE-79 CVE-2021-43543: Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2016-1937P4MEDIUMCVSS 6.1≤ 43.0.42016-01-31
CVE-2016-1937 [MEDIUM] CWE-79 CVE-2016-1937: The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickj The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
nvdosv
CVE-2020-26956P4MEDIUMCVSS 6.1fixed in 83.0fixed in 832020-12-09
CVE-2020-26956 [MEDIUM] CWE-79 CVE-2020-26956: In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2012-3972P4MEDIUMCVSS 5.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3972 [MEDIUM] CWE-200 CVE-2012-3972: The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox E The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based buffer over-read.
nvd
CVE-2016-1941P4MEDIUMCVSS 6.1≤ 43.0.42016-01-31
CVE-2016-1941 [MEDIUM] CWE-79 CVE-2016-1941: The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
nvd
CVE-2019-17000P4MEDIUMCVSS 6.1fixed in 70.0vbefore 702020-01-08
CVE-2019-17000 [MEDIUM] CWE-79 CVE-2019-17000: An object tag with a data URI did not correctly inherit the document's Content Security Policy. This An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document's policy explicitly allowed data: URIs. This vulnerability affects Firefox < 70.
nvdosv
CVE-2005-0401P4MEDIUMCVSS 5.1v0.8v0.9+6 more2005-05-02
CVE-2005-0401 [MEDIUM] CVE-2005-0401: FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading ch FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."
nvd
CVE-2021-23955P4MEDIUMCVSS 6.1fixed in 85.0fixed in 852021-02-26
CVE-2021-23955 [MEDIUM] CWE-1021 CVE-2021-23955: The browser could have been confused into transferring a pointer lock state into another tab, which The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.
nvdosv
Mozilla Firefox vulnerabilities | cvebase