Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 138 of 162
CVE-2025-4089P4MEDIUMCVSS 5.1fixed in 138.02025-04-29
CVE-2025-4089 [MEDIUM] CWE-77 CVE-2025-4089: Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could
Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvd
CVE-2015-2718P4MEDIUMCVSS 4.3≤ 37.0.22015-05-14
CVE-2015-2718 [MEDIUM] CWE-200 CVE-2015-2718: The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote attackers to bypass the Same
The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive webchannel-response data via a crafted web site containing an IFRAME element referencing a different web site that is intended to read this data.
nvdosv
CVE-2015-0819P4MEDIUMCVSS 4.3≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0819 [MEDIUM] CWE-19 CVE-2015-0819: The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call ori
The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.
nvdosv
CVE-2012-3975P4MEDIUMCVSS 4.3≤ 14.0v1.0+129 more2012-08-29
CVE-2012-3975 [MEDIUM] CWE-200 CVE-2012-3975: The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey befor
The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.
nvd
CVE-2024-5691P4MEDIUMCVSS 4.7fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5691 [MEDIUM] CWE-693 CVE-2024-5691: By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a b
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2018-5172P4MEDIUMCVSS 4.3fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5172 [MEDIUM] CWE-79 CVE-2018-5172: The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script f
The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privileg
nvdosv
CVE-2012-1963P4MEDIUMCVSS 4.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1963 [MEDIUM] CWE-264 CVE-2012-1963: The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.
The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture O
nvd
CVE-2015-4483P4MEDIUMCVSS 4.3≤ 39.0.32015-08-16
CVE-2015-4483 [MEDIUM] CWE-264 CVE-2015-4483: Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection
Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.
nvdosv
CVE-2025-5264P4MEDIUMCVSS 4.8fixed in 115.24.0fixed in 139.0+1 more2025-05-27
CVE-2025-5264 [MEDIUM] CWE-77 CVE-2025-5264: Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker cou
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
nvd
CVE-2020-6797P4MEDIUMCVSS 4.3fixed in 73.0≥ unspecified, < 73+1 more2020-03-02
CVE-2020-6797 [MEDIUM] CWE-20 CVE-2020-6797: By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbit
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating sy
nvd
CVE-2025-5265P4MEDIUMCVSS 4.8fixed in 115.24.0fixed in 139.0+1 more2025-05-27
CVE-2025-5265 [MEDIUM] CWE-77 CVE-2025-5265: Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker c
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.
*This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 139, Firefox ESR
nvd
CVE-2024-6601P4MEDIUMCVSS 4.7fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6601 [MEDIUM] CWE-367 CVE-2024-6601: A race condition could lead to a cross-origin container obtaining permissions of the top-level origi
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdosv
CVE-2011-2598P4MEDIUMCVSS 4.3v4.0v4.0.12011-06-30
CVE-2011-2598 [MEDIUM] CWE-200 CVE-2011-2598: The WebGL implementation in Mozilla Firefox 4.x allows remote attackers to obtain screenshots of the
The WebGL implementation in Mozilla Firefox 4.x allows remote attackers to obtain screenshots of the windows of arbitrary desktop applications via vectors involving an SVG filter, an IFRAME element, and uninitialized data in graphics memory.
nvd
CVE-2026-12313P4MEDIUMCVSS 4.7fixed in 152.0≥ 140.0, < 140.12.02026-06-16
CVE-2026-12313 [MEDIUM] CWE-269 CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerabi
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2015-0799P4MEDIUMCVSS 4.3≤ 37.02015-04-08
CVE-2015-0799 [MEDIUM] CWE-20 CVE-2015-0799: The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle atta
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.
nvdosv
CVE-2007-4038P4MEDIUMCVSS 4.3≤ 2.0.0.42007-07-27
CVE-2007-4038 [MEDIUM] CVE-2007-4038: Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thu
Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invokin
nvd
CVE-2014-8632P4MEDIUMCVSS 4.3≤ 33.02014-12-11
CVE-2014-8632 [MEDIUM] CWE-284 CVE-2014-8632: The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does no
The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.
nvd
CVE-2010-3182P4MEDIUMCVSS 6.9v3.6v3.6.2+90 more2010-10-21
CVE-2010-3182 [MEDIUM] CVE-2010-3182: A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunde
A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
nvd
CVE-2013-1673P4MEDIUMCVSS 6.9≤ 20.0.1v19.0+3 more2013-05-16
CVE-2013-1673 [MEDIUM] CWE-264 CVE-2013-1673: The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Mai
The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."
nvd
CVE-2020-26954P4MEDIUMCVSS 4.3fixed in 83.0fixed in 862020-12-09
CVE-2020-26954 [MEDIUM] CVE-2020-26954: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Andro
nvd