cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 135 of 162
CVE-2008-5510P4MEDIUMCVSS 5.0≥ 2.0, < 2.0.0.19≥ 3.0, < 3.0.52008-12-17
CVE-2008-5510 [MEDIUM] CVE-2008-5510: The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2 The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.
nvd
CVE-2014-1539P4MEDIUMCVSS 5.0≤ 29.0.12014-06-11
CVE-2014-1539 [MEDIUM] CWE-20 CVE-2014-1539: Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cur Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a DIV element, which makes it easier for remote attackers to conduct clickjacking attacks via JavaScript code that produces a fake cursor image.
nvd
CVE-2020-12405P4MEDIUMCVSS 5.3fixed in 77.0≥ unspecified, < 772020-07-09
CVE-2020-12405 [MEDIUM] CWE-362 CVE-2020-12405: When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvdosv
CVE-2008-0591P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-09
CVE-2008-0591 [MEDIUM] CVE-2008-0591: Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay tim Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".
nvd
CVE-2018-5106P4MEDIUMCVSS 5.3≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5106 [MEDIUM] CWE-200 CVE-2018-5106: Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when these tools are open. This can allow style editor information used within Developer Tools to leak cross-origin. This vulnerability affects Firefox < 58.
nvdosv
CVE-2006-6077P4MEDIUMCVSS 5.0≤ 1.5.0.8v1.5+8 more2006-11-24
CVE-2006-6077 [MEDIUM] CVE-2006-6077: The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manag The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a
nvd
CVE-2005-0150P4MEDIUMCVSS 5.0v0.8v0.9+6 more2005-05-26
CVE-2005-0150 [MEDIUM] CVE-2005-0150: Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookma Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.
nvd
CVE-2019-9797P4MEDIUMCVSS 5.3fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9797 [MEDIUM] CWE-346 CVE-2019-9797: Cross-origin images can be read in violation of the same-origin policy by exporting an image after u Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.
nvd
CVE-2017-7782P4MEDIUMCVSS 5.3fixed in 52.3.0fixed in 55.0+1 more2018-06-11
CVE-2017-7782 [MEDIUM] CWE-269 CVE-2017-7782: An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated b An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2005-2703P4MEDIUMCVSS 5.0≤ 1.0.6v1.0+5 more2005-09-23
CVE-2005-2703 [MEDIUM] CWE-94 CVE-2005-2703: Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.
nvd
CVE-2012-1960P4MEDIUMCVSS 5.0v4.0v4.0.1+14 more2012-07-18
CVE-2012-1960 [MEDIUM] CWE-200 CVE-2012-1960: The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information from process memory via a crafted color profile that triggers an out-of-bounds read operation.
nvd
CVE-2011-1187P4MEDIUMCVSS 5.0fixed in 12.02011-03-11
CVE-2011-1187 [MEDIUM] CWE-200 CVE-2011-1187: Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspe Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2016-5294P4MEDIUMCVSS 5.5fixed in 45.5.0fixed in 50.0+1 more2018-06-11
CVE-2016-5294 [MEDIUM] CWE-20 CVE-2016-5294: The Mozilla Updater can be made to choose an arbitrary target working directory for output files res The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2008-4069P4MEDIUMCVSS 5.0≤ 2.0.0.16v0.8+46 more2008-09-24
CVE-2008-4069 [MEDIUM] CWE-200 CVE-2008-4069: The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attacke The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.
nvd
CVE-2016-5267P4MEDIUMCVSS 5.3≤ 47.0.12016-08-05
CVE-2016-5267 [MEDIUM] CWE-20 CVE-2016-5267: Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to- Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set.
nvd
CVE-2006-2057P4MEDIUMCVSS 5.0v1.0.62006-04-26
CVE-2006-2057 [MEDIUM] CWE-88 CVE-2006-2057: Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to m Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is im
nvd
CVE-2017-7808P4MEDIUMCVSS 5.3fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7808 [MEDIUM] CWE-200 CVE-2017-7808: A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.
nvdosv
CVE-2019-9817P4MEDIUMCVSS 5.3fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9817 [MEDIUM] CWE-346 CVE-2019-9817: Images from a different domain can be read using a canvas object in some circumstances. This could b Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2016-1948P4MEDIUMCVSS 5.3v43.0.42016-01-31
CVE-2016-1948 [MEDIUM] CWE-310 CVE-2016-1948: Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme in Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.
nvd
CVE-2011-2986P4MEDIUMCVSS 5.0v4.0v4.0.1+1 more2011-08-18
CVE-2011-2986 [MEDIUM] CWE-200 CVE-2011-2986: Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other pr Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.
nvd
Mozilla Firefox vulnerabilities | cvebase