Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 145 of 162
CVE-2024-6613P4MEDIUMCVSS 5.5fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6613 [MEDIUM] CWE-209 CVE-2024-6613: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosv
CVE-2007-4357P4MEDIUMCVSS 5.0≤ 2.0.0.62007-08-15
CVE-2007-4357 [MEDIUM] CVE-2007-4357: Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar
Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar via a link to a data: URI containing an encoded URL. NOTE: the severity of this issue has been disputed by a reliable third party, since the intended functionality of the status bar allows it to be modified.
nvd
CVE-2010-0162P4MEDIUMCVSS 4.3v3.0v3.0.1+23 more2010-02-22
CVE-2010-0162 [MEDIUM] CWE-79 CVE-2010-0162: Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not pro
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cro
nvd
CVE-2012-3992P4MEDIUMCVSS 4.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-3992 [MEDIUM] CWE-79 CVE-2012-3992: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and hi
nvd
CVE-2012-0451P4MEDIUMCVSS 4.3v4.0v4.0.1+12 more2012-03-14
CVE-2012-0451 [MEDIUM] CWE-94 CVE-2012-0451: CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th
CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP head
nvd
CVE-2016-1958P4MEDIUMCVSS 4.3≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1958 [MEDIUM] CWE-254 CVE-2016-1958: browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allo
browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.
nvd
CVE-2013-0793P4MEDIUMCVSS 4.3≤ 19.0.2v19.0+6 more2013-04-03
CVE-2013-0793 [MEDIUM] CWE-79 CVE-2013-0793: Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird
Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over naviga
nvd
CVE-2012-1961P4MEDIUMCVSS 4.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1961 [MEDIUM] CWE-20 CVE-2012-1961: Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thun
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly handle duplicate values in X-Frame-Options headers, which makes it easier for remote attackers to conduct clickjacking attacks via a FRAME element referencing a web site that produ
nvd
CVE-2010-2768P4MEDIUMCVSS 4.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2768 [MEDIUM] CWE-79 CVE-2010-2768: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.
nvd
CVE-2013-1714P4MEDIUMCVSS 4.3v17.0v17.0.1+13 more2013-08-07
CVE-2013-1714 [MEDIUM] CWE-264 CVE-2013-1714: The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thund
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspec
nvd
CVE-2012-1957P4MEDIUMCVSS 4.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1957 [MEDIUM] CWE-79 CVE-2012-1957: An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.
An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly handle EMBED elements within description elements in RSS feeds, which allows remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2010-3177P4MEDIUMCVSS 4.3v3.6v3.6.2+90 more2010-10-21
CVE-2010-3177 [MEDIUM] CWE-79 CVE-2010-3177: Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3
Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) file or (2) directory on a Gopher server.
nvd
CVE-2013-1692P4MEDIUMCVSS 4.3≤ 21.0v19.0+11 more2013-06-26
CVE-2013-1692 [MEDIUM] CWE-264 CVE-2013-1692: Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderb
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web site.
nvd
CVE-2010-2764P4MEDIUMCVSS 4.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2764 [MEDIUM] CWE-264 CVE-2010-2764: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers to discover the existence of intranet web servers via cross-origin requests.
nvd
CVE-2018-12367P4MEDIUMCVSS 4.3fixed in 60.1.0fixed in 61.0+1 more2018-10-18
CVE-2018-12367 [MEDIUM] CWE-20 CVE-2018-12367: In the previous mitigations for Spectre, the resolution or precision of various methods was reduced
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Fire
nvd
CVE-2012-0474P4MEDIUMCVSS 4.3v4.0v4.0.1+16 more2012-04-25
CVE-2012-0474 [MEDIUM] CWE-79 CVE-2012-0474: Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x throu
Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka "Uni
nvd
CVE-2015-7187P4MEDIUMCVSS 4.3≤ 41.0.22015-11-05
CVE-2015-7187 [MEDIUM] CWE-254 CVE-2015-7187: The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which m
The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.
nvdosv
CVE-2010-0654P4MEDIUMCVSS 4.3v3.5.1v3.5.2+12 more2010-02-18
CVE-2010-0654 [MEDIUM] CWE-200 CVE-2010-0654: Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x
Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information
nvd
CVE-2012-1944P4MEDIUMCVSS 4.3v4.0v4.0.1+18 more2012-06-05
CVE-2012-1944 [MEDIUM] CWE-79 CVE-2012-1944: The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10
The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTM
nvd
CVE-2013-1728P4MEDIUMCVSS 4.3≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1728 [MEDIUM] CWE-119 CVE-2013-1728: The IonMonkey JavaScript engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonk
The IonMonkey JavaScript engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21, when Valgrind mode is used, does not properly initialize memory, which makes it easier for remote attackers to obtain sensitive information via unspecified vectors.
nvd