Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 143 of 162
CVE-2012-4195P4MEDIUMCVSS 4.3fixed in 10.0.10fixed in 16.0.22012-10-29
CVE-2012-4195 [MEDIUM] CWE-79 CVE-2012-4195: The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10,
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (X
nvd
CVE-2015-4476P4MEDIUMCVSS 4.3≤ 40.0.32015-09-24
CVE-2015-4476 [MEDIUM] CWE-254 CVE-2015-4476: Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar at
Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.
nvd
CVE-2015-4515P4MEDIUMCVSS 4.3≤ 41.0.22015-11-05
CVE-2015-4515 [MEDIUM] CWE-200 CVE-2015-4515: Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attacker
Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM request and reads the Workstation field of an NTLM type 3 message.
nvdosv
CVE-2014-8642P4MEDIUMCVSS 4.3≤ 34.0.52015-01-14
CVE-2014-8642 [MEDIUM] CWE-310 CVE-2014-8642: Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck exten
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certifi
nvdosv
CVE-2021-38506P4MEDIUMCVSS 4.3fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-38506 [MEDIUM] CWE-1021 CVE-2021-38506: Through a series of navigations, Firefox could have entered fullscreen mode without notification or
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2010-0172P4MEDIUMCVSS 4.3v3.62010-03-25
CVE-2010-0172 [MEDIUM] CVE-2010-0172: toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Promp
toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authenticati
nvd
CVE-2011-3866P4MEDIUMCVSS 4.3≤ 7.02011-09-29
CVE-2011-3866 [MEDIUM] CWE-264 CVE-2011-3866: Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.
nvd
CVE-2018-12399P4MEDIUMCVSS 4.3fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12399 [MEDIUM] CWE-287 CVE-2018-12399: When a new protocol handler is registered, the API accepts a title argument which can be used to mis
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.
nvdosv
CVE-2024-26281P4MEDIUMCVSS 4.7fixed in 123.02024-02-22
CVE-2024-26281 [MEDIUM] CWE-79 CVE-2024-26281: Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorize
Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.
nvd
CVE-2020-26953P4MEDIUMCVSS 4.3fixed in 83.0fixed in 832020-12-09
CVE-2020-26953 [MEDIUM] CWE-1021 CVE-2020-26953: It was possible to cause the browser to enter fullscreen mode without displaying the security UI; th
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2015-0812P4MEDIUMCVSS 4.3v36.0.42015-04-01
CVE-2015-0812 [MEDIUM] CWE-17 CVE-2015-0812: Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installat
Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.
nvdosv
CVE-2016-5253P4MEDIUMCVSS 4.7≤ 47.0.12016-08-05
CVE-2016-5253 [MEDIUM] CWE-264 CVE-2016-5253: The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files
The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.
nvd
CVE-2020-35111P4MEDIUMCVSS 4.3fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-35111 [MEDIUM] CVE-2020-35111: When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest ca
When an extension with the proxy permission registered to receive , the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2021-43538P4MEDIUMCVSS 4.3fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43538 [MEDIUM] CWE-362 CVE-2021-43538: By misusing a race in our notification code, an attacker could have forcefully hidden the notificati
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2011-3004P4MEDIUMCVSS 4.3v4.0v4.0.1+2 more2011-09-29
CVE-2011-3004 [MEDIUM] CWE-20 CVE-2011-3004: The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly ha
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.
nvd
CVE-2005-0587P4MEDIUMCVSS 6.5fixed in 1.0.12005-03-25
CVE-2005-0587 [MEDIUM] CWE-59 CVE-2005-0587: Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitra
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.
nvd
CVE-2019-11749P4MEDIUMCVSS 4.3fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11749 [MEDIUM] CVE-2019-11749: A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUs
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2013-1672P4MEDIUMCVSS 6.9≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1672 [MEDIUM] CWE-264 CVE-2013-1672: The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thun
The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.
nvd
CVE-2012-4206P4MEDIUMCVSS 6.9≤ 16.0.2v0.1+160 more2012-11-21
CVE-2012-4206 [MEDIUM] CVE-2012-4206: Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR
Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory.
nvd
CVE-2023-5721P4MEDIUMCVSS 4.3fixed in 119.0≥ unspecified, < 1192023-10-25
CVE-2023-5721 [MEDIUM] CWE-1021 CVE-2023-5721: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd