Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 136 of 162
CVE-2016-1947P4MEDIUMCVSS 4.7v43.0v43.0.1+3 more2016-01-31
CVE-2016-1947 [MEDIUM] CWE-19 CVE-2016-1947: Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which mak
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
nvdosv
CVE-2012-3986P4MEDIUMCVSS 4.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-3986 [MEDIUM] CWE-20 CVE-2012-3986: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
nvd
CVE-2012-5837P4MEDIUMCVSS 6.8≤ 16.0.2v0.1+152 more2012-11-21
CVE-2012-5837 [MEDIUM] CWE-79 CVE-2012-5837: The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, whi
The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
nvd
CVE-2014-1584P4MEDIUMCVSS 4.3≤ 32.0v30.0+2 more2014-10-15
CVE-2014-1584 [MEDIUM] CWE-310 CVE-2014-1584: The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 skips pinning checks upon
The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 skips pinning checks upon an unspecified issuer-verification error, which makes it easier for remote attackers to bypass an intended pinning configuration and spoof a web site via a crafted certificate that leads to presentation of the Untrusted Connection dialog to the user.
nvdosv
CVE-2006-3352P4MEDIUMCVSS 6.4v0.8v0.9+24 more2006-07-06
CVE-2006-3352 [MEDIUM] CVE-2006-3352: Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted informati
Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribut
nvd
CVE-2026-12311P4MEDIUMCVSS 4.7fixed in 152.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12311 [MEDIUM] CWE-200 CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerabi
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2015-4505P4MEDIUMCVSS 6.6v38.0v38.0.1+6 more2015-09-24
CVE-2015-4505 [MEDIUM] CWE-264 CVE-2015-4505: updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local
updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.
nvd
CVE-2019-11720P4MEDIUMCVSS 6.1fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11720 [MEDIUM] CWE-79 CVE-2019-11720: Some unicode characters are incorrectly treated as whitespace during the parsing of web content inst
Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.
nvdosv
CVE-2011-2670P4MEDIUMCVSS 6.1fixed in 3.6vbefore 3.62020-01-13
CVE-2011-2670 [MEDIUM] CWE-79 CVE-2011-2670: Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
nvd
CVE-2010-3178P4MEDIUMCVSS 5.8v3.6v3.6.2+90 more2010-10-21
CVE-2010-3178 [MEDIUM] CWE-264 CVE-2010-3178: Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly handle certain modal calls made by javascript: URLs in circumstances related to opening a new window and performing cross-domain navigation, which allows remote attackers to bypass the Same Origin Policy vi
nvd
CVE-2006-5160P4HIGHCVSS 8.1v0.8v0.9+25 more2006-10-05
CVE-2006-5160 [HIGH] CVE-2006-5160: Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as clai
Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states that "I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and
nvd
CVE-2005-1160P4MEDIUMCVSS 5.1v0.8v0.9+8 more2005-05-02
CVE-2005-1160 [MEDIUM] CVE-2005-1160: The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote
The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
nvd
CVE-2014-1586P4MEDIUMCVSS 5.0≤ 32.0v30.0+2 more2014-10-15
CVE-2014-1586 [MEDIUM] CVE-2014-1586: content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Th
content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to obtain sensitive information from the local camera in certain IFRAME situations by maintaining a session after the user temporarily navigate
nvdosv
CVE-2014-1585P4MEDIUMCVSS 5.0v31.0v31.1.0+2 more2014-10-15
CVE-2014-1585 [MEDIUM] CVE-2014-1585: The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firef
The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not properly recognize Stop Sharing actions for videos in IFRAME elements, which allows remote attackers to obtain sensitive information from the local camera by maintaining a session after the user
nvdosv
CVE-2015-0808P4MEDIUMCVSS 5.0≤ 36.0.42015-04-01
CVE-2015-0808 [MEDIUM] CWE-17 CVE-2015-0808: The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox bef
The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvdosv
CVE-2012-0456P4MEDIUMCVSS 5.0≤ 3.6.27≥ 4.0, ≤ 10.0+3 more2012-03-14
CVE-2012-0456 [MEDIUM] CWE-200 CVE-2012-0456: The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10
The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to obtain sensitive information from process memory via vectors that trigger an out-of-bounds rea
nvd
CVE-2008-2805P4MEDIUMCVSS 5.0≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2805 [MEDIUM] CWE-20 CVE-2008-2805: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the uplo
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client computer via vectors involving originalTarget and DOM Range.
nvd
CVE-2014-8637P4MEDIUMCVSS 5.0≤ 34.0.52015-01-14
CVE-2014-8637 [MEDIUM] CWE-200 CVE-2014-8637: Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP imag
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.
nvdosv
CVE-2009-3988P4MEDIUMCVSS 5.0≤ 3.0.17v3.0+23 more2010-02-22
CVE-2009-3988 [MEDIUM] CWE-264 CVE-2009-3988: Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not pro
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
nvd
CVE-2006-2784P4MEDIUMCVSS 5.1≤ 1.5.0.32006-06-02
CVE-2006-2784 [MEDIUM] CWE-264 CVE-2006-2784: The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attacker
The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so th
nvd