cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 147 of 162
CVE-2021-23953P4MEDIUMCVSS 4.3fixed in 85.0fixed in 852021-02-26
CVE-2021-23953 [MEDIUM] CVE-2021-23953: If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cro If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2014-1520P4MEDIUMCVSS 6.9fixed in 29.0≥ 24.0, < 24.52014-04-30
CVE-2014-1520 [MEDIUM] CWE-269 CVE-2014-1520: maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.
nvd
CVE-2013-0797P4MEDIUMCVSS 6.9≤ 19.0.2v19.0+6 more2013-04-03
CVE-2013-0797 [MEDIUM] CVE-2013-0797: Untrusted search path vulnerability in the Mozilla Updater in Mozilla Firefox before 20.0, Firefox E Untrusted search path vulnerability in the Mozilla Updater in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allows local users to gain privileges via a Trojan horse DLL file in an unspecified directory.
nvd
CVE-2021-29959P4MEDIUMCVSS 4.3≥ 78.11.0, < 89.0≥ unspecified, < 892021-06-24
CVE-2021-29959 [MEDIUM] CWE-863 CVE-2021-29959: When a user has already allowed a website to access microphone and camera, disabling camera sharing When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microphone until re-enabling the camera. This vulnerability affects Firefox < 89.
nvdosv
CVE-2021-29974P4MEDIUMCVSS 4.3fixed in 90.0≥ unspecified, < 902021-08-05
CVE-2021-29974 [MEDIUM] CVE-2021-29974: When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgra
nvdosv
CVE-2015-0833P4MEDIUMCVSS 6.9≤ 35.0.1v0.1+214 more2015-02-25
CVE-2015-0833 [MEDIUM] CVE-2015-0833: Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefo Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dl
nvd
CVE-2019-9807P4MEDIUMCVSS 4.3fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9807 [MEDIUM] CWE-20 CVE-2019-9807: When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66.
nvdosv
CVE-2020-12412P4MEDIUMCVSS 4.3fixed in 70.0≥ unspecified, < 702020-07-09
CVE-2020-12412 [MEDIUM] CVE-2020-12412: By navigating a tab using the history API, an attacker could cause the address bar to display the in By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock icon) while controlling the page contents. This vulnerability affects Firefox < 70.
nvdosv
CVE-2023-6135P4MEDIUMCVSS 4.3fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6135 [MEDIUM] CWE-203 CVE-2023-6135: Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack c Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
nvd
CVE-2021-23963P4MEDIUMCVSS 4.3fixed in 85.0fixed in 852021-02-26
CVE-2021-23963 [MEDIUM] CWE-281 CVE-2021-23963: When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.
nvdosv
CVE-2022-26383P4MEDIUMCVSS 4.3fixed in 98.0≥ unspecified, < 982022-12-22
CVE-2022-26383 [MEDIUM] CWE-451 CVE-2022-26383: When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd
CVE-2023-32212P4MEDIUMCVSS 4.3fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32212 [MEDIUM] CVE-2023-32212: An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerabilit An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-32205P4MEDIUMCVSS 4.3fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32205 [MEDIUM] CVE-2023-32205: In multiple cases browser prompts could have been obscured by popups controlled by content. These co In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvdosv
CVE-2023-5726P4MEDIUMCVSS 4.3fixed in 119.0≥ unspecified, < 1192023-10-25
CVE-2023-5726 [MEDIUM] CVE-2023-5726: A website could have obscured the full screen notification by using the file open dialog. This could A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. *Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2024-0742P4MEDIUMCVSS 4.3fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0742 [MEDIUM] CVE-2024-0742: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2023-5729P4MEDIUMCVSS 4.3fixed in 119.0≥ unspecified, < 1192023-10-25
CVE-2023-5729 [MEDIUM] CVE-2023-5729: A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. Th A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack. This vulnerability affects Firefox < 119.
nvdosv
CVE-2023-29533P4MEDIUMCVSS 4.3fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29533 [MEDIUM] CVE-2023-29533: A website could have obscured the fullscreen notification by using a combination of <code>window.ope A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thun
nvd
CVE-2022-26382P4MEDIUMCVSS 4.3fixed in 98.0≥ unspecified, < 982022-12-22
CVE-2022-26382 [MEDIUM] CWE-203 CVE-2022-26382: While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was re While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.
nvdosv
CVE-2024-4767P4MEDIUMCVSS 4.3fixed in 115.11.0fixed in 126.0+1 more2024-05-14
CVE-2024-4767 [MEDIUM] CWE-459 CVE-2024-4767: If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvdosv
CVE-2024-11701P4MEDIUMCVSS 4.3fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11701 [MEDIUM] CWE-290 CVE-2024-11701: The incorrect domain may have been displayed in the address bar during an interrupted navigation att The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
nvdosv
Mozilla Firefox vulnerabilities | cvebase