Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 133 of 162
CVE-2023-32208P4MEDIUMCVSS 5.3fixed in 113.0≥ unspecified, < 1132023-06-19
CVE-2023-32208 [MEDIUM] CVE-2023-32208: Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects F
Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.
nvdosv
CVE-2024-53975P4MEDIUMCVSS 5.4fixed in 133.02024-11-26
CVE-2024-53975 [MEDIUM] CVE-2024-53975: Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the
Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.
nvd
CVE-2005-2429P4MEDIUMCVSS 5.0v2.02005-08-03
CVE-2005-2429 [MEDIUM] CVE-2005-2429: Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sect
Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.
nvd
CVE-2022-36318P4MEDIUMCVSS 5.3fixed in 103.0≥ unspecified, < 1032022-12-22
CVE-2022-36318 [MEDIUM] CWE-362 CVE-2022-36318: When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
nvd
CVE-2025-27426P4MEDIUMCVSS 5.4fixed in 136.02025-03-04
CVE-2025-27426 [MEDIUM] CWE-601 CVE-2025-27426: Malicious websites utilizing a server-side redirect to an internal error page could result in a spoo
Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.
nvd
CVE-2026-12323P4MEDIUMCVSS 5.4fixed in 152.0.02026-06-16
CVE-2026-12323 [MEDIUM] CWE-1021 CVE-2026-12323: Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Th
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2024-10468P4MEDIUMCVSS 5.3fixed in 132.0≥ unspecified, < 1322024-10-29
CVE-2024-10468 [MEDIUM] CWE-362 CVE-2024-10468: Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.
nvdosv
CVE-2025-4090P4MEDIUMCVSS 5.3fixed in 138.02025-04-29
CVE-2025-4090 [MEDIUM] CWE-532 CVE-2025-4090: A vulnerability existed in Thunderbird for Android where potentially sensitive library locations wer
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvd
CVE-2015-0832P4MEDIUMCVSS 5.0≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0832 [MEDIUM] CWE-254 CVE-2015-0832: Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and wit
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.
nvdosv
CVE-2007-5337P4MEDIUMCVSS 4.3≤ 2.0.0.72007-10-21
CVE-2007-5337 [MEDIUM] CWE-200 CVE-2007-5337: Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other fi
nvd
CVE-2007-1095P4MEDIUMCVSS 6.8≤ 2.0.0.7v0.1+54 more2007-02-26
CVE-2007-1095 [MEDIUM] CVE-2007-1095: Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnl
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.
nvd
CVE-2007-3656P4MEDIUMCVSS 6.8v1.0v1.0.1+29 more2007-07-10
CVE-2007-3656 [MEDIUM] CWE-200 CVE-2007-3656: Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check wh
Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.
nvd
CVE-2015-4502P4MEDIUMCVSS 4.3≤ 40.0.32015-09-24
CVE-2015-4502 [MEDIUM] CWE-254 CVE-2015-4502: js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which a
js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.
nvdosv
CVE-2012-4184P4MEDIUMCVSS 4.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4184 [MEDIUM] CWE-79 CVE-2012-4184: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x befo
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute arbitrary JavaScript code with chrome pr
nvd
CVE-2014-8631P4MEDIUMCVSS 4.3≤ 33.02014-12-11
CVE-2014-8631 [MEDIUM] CWE-284 CVE-2014-8631: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 supports native-interface passing, which allows remote attackers to bypass intended DOM object restrictions via a call to an unspecified method.
nvd
CVE-2021-38509P4MEDIUMCVSS 4.3fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-38509 [MEDIUM] CWE-1021 CVE-2021-38509: Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2011-3664P4MEDIUMCVSS 6.8≤ 8.0v0.1+134 more2011-12-21
CVE-2011-3664 [MEDIUM] CVE-2011-3664: Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not prop
Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2025-4087P4MEDIUMCVSS 4.8fixed in 128.10fixed in 138.02025-04-29
CVE-2025-4087 [MEDIUM] CWE-125 CVE-2025-4087: A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior d
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Thunderbird 138, and Thunderbird 128.10.
nvd
CVE-2016-1933P4MEDIUMCVSS 6.5≤ 43.0.42016-01-31
CVE-2016-1933 [MEDIUM] CWE-189 CVE-2016-1933: Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remo
Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted GIF image.
nvdosv
CVE-2016-2839P4MEDIUMCVSS 6.5≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-2839 [MEDIUM] CWE-20 CVE-2016-2839: Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with libav header allocation in FFmpeg 0.10, which allows remote attackers to cause a denial of service (application crash) via a crafted video.
nvdosv