Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 128 of 162
CVE-2019-11741P4MEDIUMCVSS 6.1fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11741 [MEDIUM] CWE-79 CVE-2019-11741: A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack o
A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org and accounts.firefox.com have close ties to the Firefox product, malicious manipulation of these sites within the browser can potentially be used to modif
nvdosv
CVE-2014-1552P4MEDIUMCVSS 5.8≤ 30.02014-07-23
CVE-2014-1552 [MEDIUM] CWE-264 CVE-2014-1552: Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attrib
Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect.
nvdosv
CVE-2017-5383P4MEDIUMCVSS 5.3fixed in 51.0fixed in 45.7.0+1 more2018-06-11
CVE-2017-5383 [MEDIUM] CWE-20 CVE-2017-5383: URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger pu
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2022-29910P4MEDIUMCVSS 6.1fixed in 100.0≥ unspecified, < 1002022-12-22
CVE-2022-29910 [MEDIUM] CWE-601 CVE-2022-29910: When closed or sent to the background, Firefox for Android would not properly record and persist HST
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 100.
nvd
CVE-2023-29540P4MEDIUMCVSS 6.1fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29540 [MEDIUM] CWE-601 CVE-2023-29540: Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external
Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosv
CVE-2013-1737P4MEDIUMCVSS 5.0v17.0v17.0.1+16 more2013-09-18
CVE-2013-1737 [MEDIUM] CWE-264 CVE-2013-1737: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expan
nvd
CVE-2015-7211P4MEDIUMCVSS 5.0≤ 42.02015-12-16
CVE-2015-7211 [MEDIUM] CWE-20 CVE-2015-7211: Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows re
Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.
nvdosv
CVE-2015-7197P4MEDIUMCVSS 5.0≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-7197 [MEDIUM] CWE-264 CVE-2015-7197: Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allows remote attackers to bypass intended mixed-content restrictions via crafted JavaScript code.
nvdosv
CVE-2024-4775P4MEDIUMCVSS 5.9fixed in 126.0≥ unspecified, < 1262024-05-14
CVE-2024-4775 [MEDIUM] CWE-431 CVE-2024-4775: An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially
An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.
nvdosv
CVE-2018-5114P4MEDIUMCVSS 5.3≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5114 [MEDIUM] CWE-200 CVE-2018-5114: If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remai
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.
nvdosv
CVE-2017-7842P4MEDIUMCVSS 5.3≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7842 [MEDIUM] CWE-200 CVE-2017-7842: If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "" elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer on requests. This vulnerability affects Firefox < 57.
nvdosv
CVE-2016-2817P4MEDIUMCVSS 5.4≤ 45.0.22016-04-30
CVE-2016-2817 [MEDIUM] CWE-264 CVE-2016-2817: The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox bef
The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) da
nvdosv
CVE-2017-7833P4MEDIUMCVSS 5.3≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7833 [MEDIUM] CWE-20 CVE-2017-7833: Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name
Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some font sets on the addressbar. The non-Latin character will not be visible to most viewers. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerabi
nvdosv
CVE-2017-7838P4MEDIUMCVSS 5.3≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7838 [MEDIUM] CWE-20 CVE-2017-7838: Punycode format text will be displayed for entire qualified international domain names in some insta
Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion. This vulnerability
nvdosv
CVE-2020-6829P4MEDIUMCVSS 5.3fixed in 80.0≥ unspecified, < 802020-10-28
CVE-2020-6829 [MEDIUM] CVE-2020-6829: When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; wh
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvd
CVE-2013-1699P4MEDIUMCVSS 5.0≤ 21.0v19.0+4 more2013-06-26
CVE-2013-1699 [MEDIUM] CWE-310 CVE-2013-1699: The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not pr
The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level domains, which allows remote attackers to spoof the address bar via unspecified homograph characters.
nvd
CVE-2019-9801P4MEDIUMCVSS 5.3fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9801 [MEDIUM] CWE-20 CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch th
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. O
nvd
CVE-2017-7816P4MEDIUMCVSS 5.3≤ 55.0.3≥ unspecified, < 562018-06-11
CVE-2017-7816 [MEDIUM] CWE-20 CVE-2017-7816: WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, vi
WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavior. This vulnerability affects Firefox < 56.
nvdosv
CVE-2017-7812P4MEDIUMCVSS 5.3≤ 55.0.3≥ unspecified, < 562018-06-11
CVE-2017-7812 [MEDIUM] CWE-200 CVE-2017-7812: If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can
If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to open. This can allow malicious web content to open a locally stored file through "file:" URLs. This vulnerability affects Firefox < 56.
nvdosv
CVE-2009-3370P4MEDIUMCVSS 5.0v3.0v3.0.1+16 more2009-10-29
CVE-2009-3370 [MEDIUM] CVE-2009-3370: Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history
Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.
nvd