Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 140 of 162
CVE-2002-2437P4MEDIUMCVSS 5.0≤ 3.6.24v3.0+56 more2011-12-07
CVE-2002-2437 [MEDIUM] CWE-264 CVE-2002-2437: The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey b
The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
nvd
CVE-2015-4490P4MEDIUMCVSS 4.3≤ 39.0.32015-08-16
CVE-2015-4490 [MEDIUM] CWE-79 CVE-2015-4490: The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 doe
The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by lev
nvdosv
CVE-2006-6971P4MEDIUMCVSS 5.0v2.0.0.12007-02-07
CVE-2006-6971 [MEDIUM] CWE-20 CVE-2006-6971: Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Ph
Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP address in (1) dotted-hex, (2) dotted-octal, (3) single decimal integer, (4) single hex integer, or (5) single octal integer format, which is not captured by the blacklist filter.
nvd
CVE-2015-0827P4MEDIUMCVSS 4.3≤ 35.0.1v0.1+214 more2015-02-25
CVE-2015-0827 [MEDIUM] CWE-119 CVE-2015-0827: Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Fi
Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic.
nvdosv
CVE-2007-3089P4MEDIUMCVSS 4.3≤ 2.0.0.4v0.8+39 more2007-06-06
CVE-2007-3089 [MEDIUM] CWE-79 CVE-2007-3089: Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) durin
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRA
nvd
CVE-2007-0780P4MEDIUMCVSS 6.8≥ 1.5, < 1.5.0.10≥ 2.0, < 2.0.0.22007-02-26
CVE-2007-0780 [MEDIUM] CWE-79 CVE-2007-0780: browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0
browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.
nvd
CVE-2011-2990P4MEDIUMCVSS 5.0v4.0v4.0.1+1 more2011-08-18
CVE-2011-2990 [MEDIUM] CWE-255 CVE-2011-2990: The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through
The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows attackers to obtain sensitive information by reading a report, related to incorrect host resolution t
nvd
CVE-2014-1480P4MEDIUMCVSS 4.3fixed in 27.02014-02-06
CVE-2014-1480 [MEDIUM] CWE-1021 CVE-2014-1480: The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not p
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.
nvd
CVE-2016-2810P4MEDIUMCVSS 5.0≤ 45.0.22016-04-30
CVE-2016-2810 [MEDIUM] CWE-264 CVE-2016-2810: Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature acce
Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.
nvd
CVE-2019-11728P4MEDIUMCVSS 4.7fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11728 [MEDIUM] CWE-668 CVE-2019-11728: The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports
The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.
nvdosv
CVE-2008-0414P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-08
CVE-2008-0414 [MEDIUM] CWE-20 CVE-2008-0414: Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to
Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to trick the user into uploading arbitrary files via label tags that shift focus to a file input field, aka "focus spoofing."
nvd
CVE-2013-0748P4MEDIUMCVSS 4.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0748 [MEDIUM] CWE-200 CVE-2013-0748: The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10
The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 makes it easier for remote attackers to bypass the ASLR protection mechanism by calling the toString function
nvd
CVE-2016-1943P4MEDIUMCVSS 4.7v43.0.42016-01-31
CVE-2016-1943 [MEDIUM] CWE-17 CVE-2016-1943: Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scro
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
nvd
CVE-2007-0801P4MEDIUMCVSS 4.3v1.5.0.92007-02-07
CVE-2007-0801 [MEDIUM] CVE-2007-0801: The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files
The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.
nvd
CVE-2015-7327P4MEDIUMCVSS 4.3≤ 40.0.32015-09-24
CVE-2015-7327 [MEDIUM] CWE-200 CVE-2015-7327: Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API
Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.
nvd
CVE-2009-3375P4MEDIUMCVSS 4.3v3.0v3.0.1+16 more2009-10-29
CVE-2009-3375 [MEDIUM] CWE-264 CVE-2009-3375: content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before
content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.
nvd
CVE-2010-3774P4MEDIUMCVSS 4.3v3.6v3.6.2+112 more2010-12-10
CVE-2010-3774 [MEDIUM] CWE-20 CVE-2010-3774: The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5
The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remote attackers to spoof the location bar via a crafted web site.
nvd
CVE-2021-38508P4MEDIUMCVSS 4.3fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-38508 [MEDIUM] CWE-1021 CVE-2021-38508: By displaying a form validity message in the correct location at the same time as a permission promp
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2016-2832P4MEDIUMCVSS 4.3≤ 46.0.12016-06-13
CVE-2016-2832 [MEDIUM] CWE-200 CVE-2016-2832: Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a f
Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
nvdosv
CVE-2016-2820P4MEDIUMCVSS 4.3≤ 45.0.22016-04-30
CVE-2016-2820 [MEDIUM] CWE-284 CVE-2016-2820: The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 do
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
nvdosv