Mozilla Firefox vulnerabilities

3,197 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,197
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL865HIGH944MEDIUM1312LOW71UNKNOWN5

Vulnerabilities

Page 145 of 160
CVE-2006-4565CRITICALCVSS 9.3≤ 1.5.0.62006-09-15
CVE-2006-4565 [CRITICAL] CWE-119 CVE-2006-4565: Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMon Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."
nvd
CVE-2006-4566MEDIUMCVSS 5.0≤ 1.5.0.62006-09-15
CVE-2006-4566 [MEDIUM] CVE-2006-4566: Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.
nvd
CVE-2006-4340MEDIUMCVSS 4.0≤ 1.5.0.62006-09-15
CVE-2006-4340 [MEDIUM] CWE-20 CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5. Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulner
nvd
CVE-2006-4568MEDIUMCVSS 4.3≤ 1.5.0.62006-09-15
CVE-2006-4568 [MEDIUM] CWE-79 CVE-2006-4568: Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the secu Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.
nvd
CVE-2006-4567LOWCVSS 2.6≤ 1.5.0.62006-09-15
CVE-2006-4567 [LOW] CVE-2006-4567: Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to inst
nvd
CVE-2006-4569LOWCVSS 2.6≤ 1.5.0.62006-09-15
CVE-2006-4569 [LOW] CVE-2006-4569: The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the contex The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2006-4561HIGHCVSS 7.5v1.5.0.62006-09-06
CVE-2006-4561 [HIGH] CVE-2006-4561: Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of th Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perfo
nvd
CVE-2006-4310MEDIUMCVSS 4.3PoCv1.5.0.62006-08-23
CVE-2006-4310 [MEDIUM] CWE-20 CVE-2006-4310: Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted F Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI.
nvd
CVE-2006-4253HIGHCVSS 7.6PoCv0.8v0.9+21 more2006-08-21
CVE-2006-4253 [HIGH] CWE-264 CVE-2006-4253: Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be fr
nvd
CVE-2006-3812LOWCVSS 2.6v1.5v1.5.0.1+3 more2006-07-29
CVE-2006-3812 [LOW] CVE-2006-3812: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.
nvd
CVE-2006-3811HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3811 [HIGH] CVE-2006-3811: Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonke Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in o
nvd
CVE-2006-3806HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3806 [HIGH] CWE-189 CVE-2006-3806: Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird b Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."
nvd
CVE-2006-3805HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3805 [HIGH] CVE-2006-3805: The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey b The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.
nvd
CVE-2006-3807HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3807 [HIGH] CVE-2006-3807: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling "named JavaScript functions" that use the constructor.
nvd
CVE-2006-3677HIGHCVSS 7.5PoCv1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3677 [HIGH] CWE-16 CVE-2006-3677: Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arb Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
nvd
CVE-2006-3809HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3809 [HIGH] CVE-2006-3809: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows script Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a privileged context.
nvd
CVE-2006-3808HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3808 [HIGH] CVE-2006-3808: Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote Proxy AutoConfig (PAC) serve Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote Proxy AutoConfig (PAC) servers to execute code with elevated privileges via a PAC script that sets the FindProxyForURL function to an eval method on a privileged object.
nvd
CVE-2006-3801HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3801 [HIGH] CVE-2006-3801: Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript r Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code.
nvd
CVE-2006-3113HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3113 [HIGH] CVE-2006-3113: Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows re Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to be deleted in a way that triggers memory corruption.
nvd
CVE-2006-3802MEDIUMCVSS 5.8v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3802 [MEDIUM] CVE-2006-3802: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.
nvd