Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 130 of 162
CVE-2015-7217P4MEDIUMCVSS 4.3≤ 42.02015-12-16
CVE-2015-7217 [MEDIUM] CWE-119 CVE-2015-7217: The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly ena
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.
nvdosv
CVE-2025-3035P4MEDIUMCVSS 5.3fixed in 137.02025-04-01
CVE-2025-3035 [MEDIUM] CWE-359 CVE-2025-3035: By first using the AI chatbot in one tab and later activating it in another tab, the document title
By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability was fixed in Firefox 137.
nvd
CVE-2025-8041P4MEDIUMCVSS 5.3fixed in 141.02025-08-19
CVE-2025-8041 [MEDIUM] CWE-451 CVE-2025-8041: In the address bar, Firefox for Android truncated the display of URLs from the end instead of priori
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in Firefox 141.
nvd
CVE-2026-6777P4MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6777 [MEDIUM] CWE-20 CVE-2026-6777: Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunde
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2015-0822P4MEDIUMCVSS 4.3≤ 35.0.1v0.1+214 more2015-02-25
CVE-2015-0822 [MEDIUM] CWE-200 CVE-2015-0822: The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Th
The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.
nvdosv
CVE-2025-0243P4MEDIUMCVSS 5.1fixed in 128.6.0fixed in 133.02025-01-07
CVE-2025-0243 [MEDIUM] CWE-787 CVE-2025-0243: Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderb
nvd
CVE-2005-2706P4MEDIUMCVSS 6.4≤ 1.0.6v1.0+5 more2005-09-23
CVE-2005-2706 [MEDIUM] CVE-2005-2706: Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript w
Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.
nvd
CVE-2012-4205P4MEDIUMCVSS 6.8fixed in 17.02012-11-21
CVE-2012-4205 [MEDIUM] CWE-352 CVE-2012-4205: Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system pr
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.
nvd
CVE-2016-1523P4MEDIUMCVSS 6.5v38.0v38.0.1+11 more2016-02-13
CVE-2016-1523 [MEDIUM] CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozi
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
nvd
CVE-2007-1084P4MEDIUMCVSS 6.8≤ 2.0.0.1v0.8+28 more2007-02-23
CVE-2007-1084 [MEDIUM] CWE-16 CVE-2007-1084: Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows r
Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.
nvd
CVE-2016-9077P4HIGHCVSS 7.0fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9077 [HIGH] CWE-362 CVE-2016-9077: Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering
Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.
nvdosv
CVE-2006-5748P4MEDIUMCVSS 5.0v1.5v1.5.0.1+6 more2006-11-08
CVE-2006-5748 [MEDIUM] CVE-2006-5748: Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thu
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger memory corruption.
nvd
CVE-2007-1256P4MEDIUMCVSS 6.8v2.0v2.0.0.1+1 more2007-03-03
CVE-2007-1256 [MEDIUM] CVE-2007-1256: Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document sou
Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.
nvd
CVE-2014-1582P4MEDIUMCVSS 4.3≤ 32.0v30.0+2 more2014-10-15
CVE-2014-1582 [MEDIUM] CWE-310 CVE-2014-1582: The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly conside
The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary reco
nvdosv
CVE-2013-1689P4MEDIUMCVSS 6.5≤ 19.0.2v20.0+1 more2019-12-10
CVE-2013-1689 [MEDIUM] CWE-20 CVE-2013-1689: Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), rel
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
nvd
CVE-2014-1530P4MEDIUMCVSS 6.1fixed in 29.0≥ 24.0, < 24.52014-04-30
CVE-2014-1530 [MEDIUM] CWE-79 CVE-2014-1530: The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbir
The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.
nvdosv
CVE-2006-0297P4MEDIUMCVSS 5.1v1.52006-02-02
CVE-2006-0297 [MEDIUM] CVE-2006-0297: Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail,
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
nvd
CVE-2013-5611P4MEDIUMCVSS 5.8≤ 25.0.1v0.1+195 more2013-12-11
CVE-2013-5611 [MEDIUM] CVE-2013-5611: Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which
Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.
nvd
CVE-2016-2833P4MEDIUMCVSS 6.1≤ 46.0.12016-06-13
CVE-2016-2833 [MEDIUM] CWE-79 CVE-2016-2833: Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java a
Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.
nvdosv
CVE-2010-1125P4MEDIUMCVSS 5.8v3.0v3.0.1+26 more2010-03-26
CVE-2010-1125 [MEDIUM] CWE-200 CVE-2010-1125: The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMo
The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.
nvd