Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 146 of 162
CVE-2012-3976P4MEDIUMCVSS 4.3fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3976 [MEDIUM] CWE-200 CVE-2012-3976: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not proper
Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.
nvd
CVE-2015-2742P4MEDIUMCVSS 4.3≤ 38.1.02015-07-06
CVE-2015-2742 [MEDIUM] CWE-200 CVE-2015-2742: Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of cras
Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.
nvd
CVE-2014-1559P4MEDIUMCVSS 4.3≤ 30.02014-07-23
CVE-2014-1559 [MEDIUM] CVE-2014-1559: Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.
nvdosv
CVE-2006-2782P4MEDIUMCVSS 4.3≤ 1.5.0.32006-06-02
CVE-2006-2782 [MEDIUM] CVE-2006-2782: Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attac
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.
nvd
CVE-2013-1713P4MEDIUMCVSS 4.3≤ 22.0v19.0+13 more2013-08-07
CVE-2013-1713 [MEDIUM] CWE-264 CVE-2013-1713: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 use an incorrect URI within unspecified comparisons during enforcement of the Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks or install arbitrary add-ons v
nvd
CVE-2010-2763P4MEDIUMCVSS 4.3≤ 3.5.11v1.0+79 more2010-09-09
CVE-2010-2763 [MEDIUM] CWE-79 CVE-2010-2763: The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Fir
The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.
nvd
CVE-2015-0825P4MEDIUMCVSS 4.3≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0825 [MEDIUM] CWE-119 CVE-2015-0825: Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox
Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.
nvdosv
CVE-2015-7186P4MEDIUMCVSS 4.3≤ 41.0.22015-11-05
CVE-2015-7186 [MEDIUM] CWE-200 CVE-2015-7186: Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Orig
Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document.
nvd
CVE-2015-7185P4MEDIUMCVSS 4.3≤ 41.0.22015-11-05
CVE-2015-7185 [MEDIUM] CWE-254 CVE-2015-7185: Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscr
Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.
nvd
CVE-2016-5251P4MEDIUMCVSS 4.3≤ 47.0.12016-08-05
CVE-2016-5251 [MEDIUM] CWE-20 CVE-2016-5251: Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters
Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL.
nvdosv
CVE-2015-0810P4MEDIUMCVSS 4.3≤ 36.0.42015-04-01
CVE-2015-0810 [MEDIUM] CWE-20 CVE-2015-0810: Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote
Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.
nvd
CVE-2011-2366P4MEDIUMCVSS 4.3≤ 4.0.1v0.1+115 more2011-06-30
CVE-2011-2366 [MEDIUM] CWE-20 CVE-2011-2366: Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block u
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
nvd
CVE-2021-43546P4MEDIUMCVSS 4.3fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43546 [MEDIUM] CWE-1021 CVE-2021-43546: It was possible to recreate previous cursor spoofing attacks against users with a zoomed native curs
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-12401P4MEDIUMCVSS 4.7fixed in 80.0≥ unspecified, < 802020-10-08
CVE-2020-12401 [MEDIUM] CWE-203 CVE-2020-12401: During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time sca
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvd
CVE-2015-2741P4MEDIUMCVSS 4.3≤ 38.1.0v31.0+7 more2015-07-06
CVE-2015-2741 [MEDIUM] CWE-310 CVE-2015-2741: Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforc
Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname f
nvdosv
CVE-2006-0299P4MEDIUMCVSS 6.4v1.52006-02-02
CVE-2006-0299 [MEDIUM] CVE-2006-0299: The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in m
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
nvd
CVE-2020-12400P4MEDIUMCVSS 4.7fixed in 80.0≥ unspecified, < 802020-10-08
CVE-2020-12400 [MEDIUM] CWE-203 CVE-2020-12400: When converting coordinates from projective to affine, the modular inversion was not performed in co
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvd
CVE-2021-23969P4MEDIUMCVSS 4.3fixed in 86.0fixed in 862021-02-26
CVE-2021-23969 [MEDIUM] CVE-2021-23969: As specified in the W3C Content Security Policy draft, when creating a violation report, "User agent
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the s
nvd
CVE-2018-5108P4MEDIUMCVSS 4.3≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5108 [MEDIUM] CWE-200 CVE-2018-5108: A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private brows
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blo
nvdosv
CVE-2010-3170P4MEDIUMCVSS 4.3v3.6v3.6.2+90 more2010-10-21
CVE-2010-3170 [MEDIUM] CWE-310 CVE-2010-3170: Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Cert
nvd