cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 141 of 162
CVE-2008-2810P4MEDIUMCVSS 6.8≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2810 [MEDIUM] CWE-264 CVE-2008-2810: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut.
nvd
CVE-2024-1548P4MEDIUMCVSS 4.3fixed in 115.8.0fixed in 123.0+1 more2024-02-20
CVE-2024-1548 [MEDIUM] CVE-2024-1548: A website could have obscured the fullscreen notification by using a dropdown select input element. A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2023-5725P4MEDIUMCVSS 4.3fixed in 119.0≥ unspecified, < 1192023-10-25
CVE-2023-5725 [MEDIUM] CVE-2023-5725: A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance cou A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2013-1712P4MEDIUMCVSS 6.9≤ 22.0v17.0+13 more2013-08-07
CVE-2013-1712 [MEDIUM] CVE-2013-1712: Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update
nvd
CVE-2012-3974P4MEDIUMCVSS 6.9≤ 14.0v1.0+133 more2012-08-29
CVE-2012-3974 [MEDIUM] CWE-399 CVE-2012-3974: Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10. Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.
nvd
CVE-2024-5690P4MEDIUMCVSS 4.3fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5690 [MEDIUM] CWE-203 CVE-2024-5690: By monitoring the time certain operations take, an attacker could have guessed which external protoc By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2024-11692P4MEDIUMCVSS 4.3fixed in 128.5.0fixed in 133.0+1 more2024-11-26
CVE-2024-11692 [MEDIUM] CWE-290 CVE-2024-11692: An attacker could cause a select dropdown to be shown over another tab; this could have led to user An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvdosv
CVE-2024-0748P4MEDIUMCVSS 4.3fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0748 [MEDIUM] CVE-2024-0748: A compromised content process could have updated the document URI. This could have allowed an attack A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.
nvdosv
CVE-2006-1738P4MEDIUMCVSS 5.0v1.0v1.0.1+7 more2006-04-14
CVE-2006-1738 [MEDIUM] CVE-2006-1738: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.
nvd
CVE-2015-4484P4MEDIUMCVSS 5.0≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4484 [MEDIUM] CWE-119 CVE-2015-4484: The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Fire The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.
nvdosv
CVE-2007-0996P4MEDIUMCVSS 5.8v1.5v1.5.0.1+10 more2007-02-27
CVE-2007-0996 [MEDIUM] CVE-2007-0996: The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0 The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
nvd
CVE-2006-4566P4MEDIUMCVSS 5.0≤ 1.5.0.62006-09-15
CVE-2006-4566 [MEDIUM] CVE-2006-4566: Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.
nvd
CVE-2009-0777P4MEDIUMCVSS 5.8≤ 3.0.6v1.0+48 more2009-03-05
CVE-2009-0777 [MEDIUM] CWE-20 CVE-2009-0777: Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisi Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
nvd
CVE-2005-2263P4MEDIUMCVSS 5.0v0.8v0.9+10 more2005-07-13
CVE-2005-2263 [MEDIUM] CVE-2005-2263: The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote att The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.
nvd
CVE-2009-1302P4MEDIUMCVSS 5.0v3.0v3.0.1+7 more2009-04-22
CVE-2009-1302 [MEDIUM] CWE-399 CVE-2009-1302: The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey b The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the
nvd
CVE-2015-7208P4MEDIUMCVSS 5.0≤ 42.02015-12-16
CVE-2015-7208 [MEDIUM] CWE-200 CVE-2015-7208: Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote a Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.
nvdosv
CVE-2005-2395P4MEDIUMCVSS 5.0v1.0.4v1.0.52005-07-27
CVE-2005-2395 [MEDIUM] CVE-2005-2395: Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication sche Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
nvd
CVE-2011-3670P4MEDIUMCVSS 5.0≤ 3.6.25v0.1+130 more2012-02-01
CVE-2011-3670 [MEDIUM] CWE-200 CVE-2011-3670: Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, an Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages.
nvd
CVE-2006-1741P4MEDIUMCVSS 4.3≥ 1.0, < 1.0.8v1.52006-04-14
CVE-2006-1741 [MEDIUM] CWE-79 CVE-2006-1741: Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey be Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) u
nvd
CVE-2004-0905P4MEDIUMCVSS 4.6v0.8v0.9+3 more2004-09-14
CVE-2004-0905 [MEDIUM] CVE-2004-0905: Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
nvd
Mozilla Firefox vulnerabilities | cvebase