Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 142 of 162
CVE-2014-1498P4MEDIUMCVSS 5.0fixed in 28.02014-03-19
CVE-2014-1498 [MEDIUM] CWE-347 CVE-2014-1498: The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.
nvd
CVE-2010-0169P4MEDIUMCVSS 5.0v3.0v3.0.1+17 more2010-03-25
CVE-2010-0169 [MEDIUM] CVE-2010-0169: The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x
The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the
nvd
CVE-2013-5612P4MEDIUMCVSS 4.3fixed in 26.02013-12-11
CVE-2013-5612 [MEDIUM] CWE-79 CVE-2013-5612: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 ma
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
nvd
CVE-2014-1496P4MEDIUMCVSS 5.5fixed in 28.0≥ 24.0, < 24.42014-03-19
CVE-2014-1496 [MEDIUM] CWE-269 CVE-2014-1496: Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey be
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
nvd
CVE-2008-2807P4MEDIUMCVSS 5.0≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2807 [MEDIUM] CWE-200 CVE-2008-2807: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .prope
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 encoding in a French .properties file.
nvd
CVE-2007-1762P4MEDIUMCVSS 5.0v2.0.0.1v2.0.0.2+1 more2007-03-30
CVE-2007-1762 [MEDIUM] CVE-2007-1762: Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the
Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / (slash) characters in the URL.
nvd
CVE-2012-4207P4MEDIUMCVSS 4.3fixed in 17.0≥ 10.0, < 10.0.112012-11-21
CVE-2012-4207 [MEDIUM] CWE-79 CVE-2012-4207: The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2020-16012P4MEDIUMCVSS 4.3fixed in 83.02021-01-08
CVE-2020-16012 [MEDIUM] CVE-2020-16012: Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2015-4518P4MEDIUMCVSS 4.3≤ 41.0.22015-11-05
CVE-2015-4518 [MEDIUM] CWE-79 CVE-2015-4518: The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes
The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL.
nvdosv
CVE-2012-0479P4MEDIUMCVSS 4.3v4.0v4.0.1+16 more2012-04-25
CVE-2012-0479 [MEDIUM] CVE-2012-0479: Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thun
Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.
nvd
CVE-2008-5508P4MEDIUMCVSS 4.3≥ 2.0, < 2.0.0.19≥ 3.0, < 3.0.52008-12-17
CVE-2008-5508 [MEDIUM] CWE-20 CVE-2008-5508: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.
nvd
CVE-2016-1965P4MEDIUMCVSS 4.3≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1965 [MEDIUM] CWE-254 CVE-2016-1965: Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that re
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.
nvd
CVE-2013-1711P4MEDIUMCVSS 4.3≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1711 [MEDIUM] CWE-79 CVE-2013-1711: The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not pro
The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.
nvd
CVE-2012-4208P4MEDIUMCVSS 4.3fixed in 17.02012-11-21
CVE-2012-4208 [MEDIUM] CWE-200 CVE-2012-4208: The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonke
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.
nvd
CVE-2013-5595P4MEDIUMCVSS 4.3≤ 24.0v19.0+21 more2013-10-30
CVE-2013-5595 [MEDIUM] CWE-119 CVE-2013-5595: The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x befor
The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly allocate memory for unspecified functions, which allows remote attackers to conduct buffer overflow attacks via a crafted web page.
nvd
CVE-2013-5593P4MEDIUMCVSS 4.3v24.0v24.0.1+11 more2013-10-30
CVE-2013-5593 [MEDIUM] CWE-20 CVE-2013-5593: The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thun
The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation o
nvd
CVE-2014-1499P4MEDIUMCVSS 4.3fixed in 28.02014-03-19
CVE-2014-1499 [MEDIUM] CVE-2014-1499: Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain nam
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
nvd
CVE-2012-5841P4MEDIUMCVSS 4.3fixed in 10.0.11fixed in 17.02012-11-21
CVE-2012-5841 [MEDIUM] CWE-79 CVE-2012-5841: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 implement cross-origin wrappers with a filtering behavior that does not properly restrict write actions, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.
nvd
CVE-2012-3985P4MEDIUMCVSS 4.3fixed in 16.02012-10-10
CVE-2012-3985 [MEDIUM] CWE-79 CVE-2012-3985: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly impl
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.
nvd
CVE-2015-2711P4MEDIUMCVSS 4.3≤ 37.0.22015-05-14
CVE-2015-2711 [MEDIUM] CWE-200 CVE-2015-2711: Mozilla Firefox before 38.0 does not recognize a referrer policy delivered by a referrer META elemen
Mozilla Firefox before 38.0 does not recognize a referrer policy delivered by a referrer META element in cases of context-menu navigation and middle-click navigation, which allows remote attackers to obtain sensitive information by reading web-server Referer logs that contain private data in a URL, as demonstrated by a private path component.
nvdosv