Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 134 of 162
CVE-2016-2827P4MEDIUMCVSS 6.5≤ 48.0.22016-09-22
CVE-2016-2827 [MEDIUM] CWE-125 CVE-2016-2827: The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attack
The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.
nvdosv
CVE-2016-5271P4MEDIUMCVSS 6.5≤ 48.0.22016-09-22
CVE-2016-5271 [MEDIUM] CWE-125 CVE-2016-5271: The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attac
The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.
nvdosv
CVE-2005-0255P4MEDIUMCVSS 5.0v1.02005-05-02
CVE-2005-0255 [MEDIUM] CVE-2005-0255: String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the n
String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes
nvd
CVE-2019-11715P4MEDIUMCVSS 6.1fixed in 60.8.0fixed in 68.0+1 more2019-07-23
CVE-2019-11715 [MEDIUM] CWE-79 CVE-2019-11715: Due to an error while parsing page content, it is possible for properly sanitized user input to be m
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2016-5262P4MEDIUMCVSS 6.1≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-5262 [MEDIUM] CWE-79 CVE-2016-5262: Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attrib
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.
nvd
CVE-2013-0772P4MEDIUMCVSS 5.8fixed in 19.02013-02-19
CVE-2013-0772 [MEDIUM] CWE-119 CVE-2013-0772: The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and
The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted GIF image.
nvd
CVE-2019-11763P4MEDIUMCVSS 6.1fixed in 70.0vbefore 702020-01-08
CVE-2019-11763 [MEDIUM] CWE-79 CVE-2019-11763: Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of e
nvd
CVE-2018-5143P4MEDIUMCVSS 6.1fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5143 [MEDIUM] CWE-79 CVE-2018-5143: URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users
URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a tab character is embedded in the "javascript:" URL the protocol is not removed and the script will execute. This could allow users to be socially engineered to run an XSS attack against themselves. This vu
nvdosv
CVE-2017-5393P4MEDIUMCVSS 6.1fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5393 [MEDIUM] CWE-79 CVE-2017-5393: The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org,
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.
nvdosv
CVE-2010-3400P4MEDIUMCVSS 5.8v3.5v3.5.1+11 more2010-09-15
CVE-2010-3400 [MEDIUM] CVE-2010-3400: The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 a
The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2008-5913.
nvd
CVE-2023-5758P4MEDIUMCVSS 6.1fixed in 119.02023-10-25
CVE-2023-5758 [MEDIUM] CWE-79 CVE-2023-5758: When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to
When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.
nvd
CVE-2022-34473P4MEDIUMCVSS 6.1fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34473 [MEDIUM] CWE-79 CVE-2022-34473: The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></c
The HTML Sanitizer should have sanitized the href attribute of SVG tags; however it incorrectly did not sanitize xlink:href attributes. This vulnerability affects Firefox < 102.
nvdosv
CVE-2024-43112P4MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43112 [MEDIUM] CWE-79 CVE-2024-43112: Long pressing on a download link could potentially provide a means for cross-site scripting This vul
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2015-7219P4MEDIUMCVSS 5.0≤ 42.02015-12-16
CVE-2015-7219 [MEDIUM] CWE-189 CVE-2015-7219: The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial o
The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers decompressed-buffer length miscalculation and incorrect memory allocation.
nvdosv
CVE-2009-2664P4MEDIUMCVSS 5.0≤ 3.5.1v0.1+92 more2009-08-04
CVE-2009-2664 [MEDIUM] CWE-399 CVE-2009-2664: The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before
The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions bef
nvd
CVE-2014-1565P4MEDIUMCVSS 5.0≤ 31.1.0v30.0+1 more2014-09-03
CVE-2014-1565 [MEDIUM] CWE-119 CVE-2014-1565: The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox
The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 does not properly create audio timelines, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) vi
nvdosv
CVE-2016-5265P4MEDIUMCVSS 5.5≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-5265 [MEDIUM] CWE-79 CVE-2016-5265: Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory.
nvd
CVE-2014-1483P4MEDIUMCVSS 5.0fixed in 27.02014-02-06
CVE-2014-1483 [MEDIUM] CWE-1021 CVE-2014-1483: Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Orig
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
nvd
CVE-2007-2162P4HIGHCVSS 7.8v2.0.0.32007-04-22
CVE-2007-2162 [HIGH] CVE-2007-2162: (1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial o
(1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.
nvd
CVE-2009-3078P4MEDIUMCVSS 5.0≤ 3.0.13v0.1+94 more2009-09-10
CVE-2009-3078 [MEDIUM] CWE-20 CVE-2009-3078: Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows rem
Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.
nvd