Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 129 of 162
CVE-2017-7820P4MEDIUMCVSS 5.3≤ 55.0.3≥ unspecified, < 562018-06-11
CVE-2017-7820 [MEDIUM] CVE-2017-7820: The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the
The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content can provide its own result for that operator, possibly tricking the browser or extension into mishandling the element. This vulnerability affects Firefox < 56.
nvdosv
CVE-2018-5138P4MEDIUMCVSS 5.3fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5138 [MEDIUM] CWE-20 CVE-2018-5138: A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opene
A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel inside another app) and the default browser is Firefox for Android. This could allow an attacker to spoof which page is actually loaded and in use. Note: this issue only affects Firefox for Android. Other versi
nvd
CVE-2004-2225P4MEDIUMCVSS 5.0v0.8v0.9+5 more2004-12-31
CVE-2004-2225 [MEDIUM] CVE-2004-2225: Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download dire
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
nvd
CVE-2020-15680P4MEDIUMCVSS 5.3fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15680 [MEDIUM] CVE-2020-15680: If a valid external protocol handler was referenced in an image tag, the resulting broken image size
If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered. This vulnerability affects Firefox < 82.
nvdosv
CVE-2016-5291P4MEDIUMCVSS 5.5fixed in 45.5.0fixed in 50.0+1 more2018-06-11
CVE-2016-5291 [MEDIUM] CWE-20 CVE-2016-5291: A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. Thi
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2020-12392P4MEDIUMCVSS 5.5fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12392 [MEDIUM] CWE-22 CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and
nvd
CVE-2015-4503P4MEDIUMCVSS 5.0≤ 40.0.32015-09-24
CVE-2015-4503 [MEDIUM] CWE-200 CVE-2015-4503: The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that we
The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS
nvd
CVE-2022-28286P4MEDIUMCVSS 5.4fixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28286 [MEDIUM] CWE-1021 CVE-2022-28286: Due to a layout change, iframe contents could have been rendered outside of its border. This could h
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvd
CVE-2023-25730P4MEDIUMCVSS 5.4fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25730 [MEDIUM] CWE-1021 CVE-2023-25730: A background script invoking <code>requestFullscreen</code> and then blocking the main thread could
A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2023-29532P4MEDIUMCVSS 5.5fixed in 112.0≥ unspecified, < 1122023-06-19
CVE-2023-29532 [MEDIUM] CVE-2023-29532: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.
*Note: This attack requires local syste
nvd
CVE-2016-1940P4MEDIUMCVSS 5.3≤ 43.0.42016-01-31
CVE-2016-1940 [MEDIUM] CWE-17 CVE-2016-1940: Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data:
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.
nvd
CVE-2023-6857P4MEDIUMCVSS 5.3fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6857 [MEDIUM] CWE-362 CVE-2023-6857: When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be sma
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary.
*This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2018-5109P4MEDIUMCVSS 5.3≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5109 [MEDIUM] CWE-346 CVE-2018-5109: An audio capture session can started under an incorrect origin from the site making the capture requ
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.
nvdosv
CVE-2023-37455P4MEDIUMCVSS 5.4fixed in 1152023-07-12
CVE-2023-37455 [MEDIUM] CWE-1021 CVE-2023-37455: The permission request prompt from the site in the background tab was overlaid on top of the site in
The permission request prompt from the site in the background tab was overlaid on top of the site in the foreground tab. This vulnerability affects Firefox for iOS < 115.
nvd
CVE-2024-6612P4MEDIUMCVSS 5.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6612 [MEDIUM] CWE-200 CVE-2024-6612: CSP violations generated links in the console tab of the developer tools, pointing to the violating
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosv
CVE-2025-5267P4MEDIUMCVSS 5.4fixed in 128.11.0fixed in 139.02025-05-27
CVE-2025-5267 [MEDIUM] CWE-1021 CVE-2025-5267: A clickjacking vulnerability could have been used to trick a user into leaking saved payment card de
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
nvd
CVE-2026-12322P4MEDIUMCVSS 5.4fixed in 152.0.02026-06-16
CVE-2026-12322 [MEDIUM] CWE-1021 CVE-2026-12322: Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thu
Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2026-12321P4MEDIUMCVSS 5.4fixed in 152.0.02026-06-16
CVE-2026-12321 [MEDIUM] CWE-670 CVE-2026-12321: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2025-1018P4MEDIUMCVSS 5.3fixed in 135.02025-02-04
CVE-2025-1018 [MEDIUM] CWE-1021 CVE-2025-1018: The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the use
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2019-9808P4MEDIUMCVSS 5.3fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9808 [MEDIUM] CWE-346 CVE-2019-9808: If WebRTC permission is requested from documents with data: or blob: URLs, the permission notificati
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66.
nvdosv