Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 131 of 162
CVE-2010-3399P4MEDIUMCVSS 5.8v3.5.10v3.5.11+5 more2010-09-15
CVE-2010-3399 [MEDIUM] CVE-2010-3399: The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11
The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a context pointer in conjunction with its successor pointer for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerabilit
nvd
CVE-2017-7839P4MEDIUMCVSS 6.1≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7839 [MEDIUM] CWE-79 CVE-2017-7839: Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leadin
Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar.
nvdosv
CVE-2017-7840P4MEDIUMCVSS 6.1≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7840 [MEDIUM] CWE-79 CVE-2017-7840: JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supp
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this JavaScript will be executed. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks if users were convinced to add mali
nvdosv
CVE-2019-11724P4MEDIUMCVSS 6.1fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11724 [MEDIUM] CWE-863 CVE-2019-11724: Application permissions give additional remote troubleshooting permission to the site input.mozilla.
Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability affects Firefox < 68.
nvdosv
CVE-2015-0824P4MEDIUMCVSS 5.0≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0824 [MEDIUM] CWE-119 CVE-2015-0824: The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0
The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.
nvdosv
CVE-2019-17001P4MEDIUMCVSS 6.1v69.02020-01-08
CVE-2019-17001 [MEDIUM] CVE-2019-17001: A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execu
A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.*Note: This flaw only affected Firefox 69 and was not present in earlier versions.*. This vulnerability affects Firefox < 70.
nvdosv
CVE-2011-3656P4MEDIUMCVSS 6.1fixed in 3.6.24≥ 4.0, ≤ 7.02021-06-02
CVE-2011-3656 [MEDIUM] CWE-79 CVE-2011-3656: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows r
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.
nvd
CVE-2009-0652P4MEDIUMCVSS 5.8≤ 3.0.6v1.0+48 more2009-02-20
CVE-2009-0652 [MEDIUM] CVE-2009-0652: The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions befor
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters
nvd
CVE-2020-26962P4MEDIUMCVSS 6.1fixed in 83.0fixed in 832020-12-09
CVE-2020-26962 [MEDIUM] CWE-1021 CVE-2020-26962: Cross-origin iframes that contained a login form could have been recognized by the login autofill se
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.
nvdosv
CVE-2019-11701P4MEDIUMCVSS 6.1fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11701 [MEDIUM] CWE-79 CVE-2019-11701: The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) a
The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.
nvdosv
CVE-2021-23959P4MEDIUMCVSS 6.1fixed in 85.0fixed in 852021-02-26
CVE-2021-23959 [MEDIUM] CWE-79 CVE-2021-23959: An XSS bug in internal error pages could have led to various spoofing attacks, including other error
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
nvd
CVE-2006-5783P4HIGHCVSS 7.8v1.5.0.72006-11-07
CVE-2006-5783 [HIGH] CVE-2006-5783: Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a
Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a long URL in an A tag. NOTE: this issue has been disputed by several vendors, who could not reproduce the report. In addition, the scope of the impact - system freeze - suggests an issue that is not related to Firefox. Due to this impact, CVE concurs with the dispu
nvd
CVE-2024-43113P4MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43113 [MEDIUM] CWE-79 CVE-2024-43113: The contextual menu for links could provide an opportunity for cross-site scripting attacks This vul
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2012-0441P4MEDIUMCVSS 5.0v4.0v4.0.1+18 more2012-06-05
CVE-2012-0441 [MEDIUM] CWE-119 CVE-2012-0441: The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4,
The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length i
nvd
CVE-2025-55030P4MEDIUMCVSS 6.1fixed in 142.02025-08-19
CVE-2025-55030 [MEDIUM] CWE-640 CVE-2025-55030: Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrec
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks. This vulnerability was fixed in Firefox for iOS 142.
nvd
CVE-2015-7207P4MEDIUMCVSS 5.0≤ 42.02015-12-16
CVE-2015-7207 [MEDIUM] CWE-200 CVE-2015-7207: Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing AP
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
nvdosv
CVE-2015-2729P4MEDIUMCVSS 5.0v31.0v31.1.0+7 more2015-07-06
CVE-2015-2729 [MEDIUM] CWE-119 CVE-2015-2729: The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Fire
The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecifi
nvdosv
CVE-2016-1976P4MEDIUMCVSS 5.5≤ 44.0.22016-03-13
CVE-2016-1976 [MEDIUM] CVE-2016-1976: Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozil
Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2006-1273P4HIGHCVSS 7.8v1.0.7v1.5.0.12006-03-19
CVE-2006-1273 [HIGH] CVE-2006-1273: Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via a
Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source. NOTE: Red Hat has disputed this issue, suggesting that "It is likely the reporter was running the IE Tab extensi
nvd
CVE-2017-7823P4MEDIUMCVSS 5.4fixed in 52.4.0fixed in 56.0+1 more2018-06-11
CVE-2017-7823 [MEDIUM] CWE-79 CVE-2017-7823: The content security policy (CSP) "sandbox" directive did not create a unique origin for the documen
The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 5
nvd