Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 148 of 162
CVE-2024-5689P4MEDIUMCVSS 4.3fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5689 [MEDIUM] CVE-2024-5689: In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay th
In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.
nvdosv
CVE-2023-29538P4MEDIUMCVSS 4.3fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29538 [MEDIUM] CWE-668 CVE-2023-29538: Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instea
Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosv
CVE-2024-4766P4MEDIUMCVSS 4.3fixed in 126.0≥ unspecified, < 1262024-05-14
CVE-2024-4766 [MEDIUM] CVE-2024-4766: Different techniques existed to obscure the fullscreen notification in Firefox for Android. These c
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
nvd
CVE-2023-25748P4MEDIUMCVSS 4.3fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-25748 [MEDIUM] CWE-1021 CVE-2023-25748: By displaying a prompt with a long description, the fullscreen notification could have been hidden,
By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.
nvd
CVE-2024-31393P4MEDIUMCVSS 4.3fixed in 124.02024-04-03
CVE-2024-31393 [MEDIUM] CVE-2024-31393: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions an
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
nvd
CVE-2022-29915P4MEDIUMCVSS 4.3fixed in 100.0≥ unspecified, < 1002022-12-22
CVE-2022-29915 [MEDIUM] CWE-346 CVE-2022-29915: The Performance API did not properly hide the fact whether a request cross-origin resource has obser
The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.
nvdosv
CVE-2026-0887P4MEDIUMCVSS 4.3fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0887 [MEDIUM] CWE-497 CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvd
CVE-2025-8364P4MEDIUMCVSS 4.3fixed in 141.02025-08-19
CVE-2025-8364 [MEDIUM] CWE-451 CVE-2025-8364: A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potent
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack.
*Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 141.
nvd
CVE-2026-12303P4MEDIUMCVSS 4.3fixed in 152.02026-06-16
CVE-2026-12303 [MEDIUM] CWE-125 CVE-2026-12303: Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This
Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2022-36315P4MEDIUMCVSS 4.3fixed in 103.0≥ unspecified, < 1032022-12-22
CVE-2022-36315 [MEDIUM] CWE-345 CVE-2022-36315: When loading a script with Subresource Integrity, attackers with an injection capability could trigg
When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.
nvdosv
CVE-2025-6428P4MEDIUMCVSS 4.3fixed in 140.02025-06-24
CVE-2025-6428 [MEDIUM] CWE-601 CVE-2025-6428: When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL i
When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140.
nvd
CVE-2026-12320P4MEDIUMCVSS 4.3fixed in 152.0.02026-06-16
CVE-2026-12320 [MEDIUM] CWE-200 CVE-2026-12320: Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 15
Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2006-3802P4MEDIUMCVSS 5.8v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3802 [MEDIUM] CVE-2006-3802: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object.
nvd
CVE-2008-5016P4MEDIUMCVSS 5.0≤ 3.0.3v3.0+2 more2008-11-13
CVE-2008-5016 [MEDIUM] CWE-399 CVE-2008-5016: The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonke
The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.
nvd
CVE-2008-5502P4MEDIUMCVSS 5.0≥ 2.0, < 2.0.0.19≥ 3.0, < 3.0.52008-12-17
CVE-2008-5502 [MEDIUM] CWE-399 CVE-2008-5502: The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonke
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
nvd
CVE-2004-2227P4MEDIUMCVSS 5.0v0.8v0.9+5 more2004-12-31
CVE-2004-2227 [MEDIUM] CVE-2004-2227: Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
nvd
CVE-2005-2707P4MEDIUMCVSS 5.0≤ 1.0.6v1.0+5 more2005-09-23
CVE-2005-2707 [MEDIUM] CVE-2005-2707: Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows withou
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.
nvd
CVE-2010-1987P4MEDIUMCVSS 5.0v3.6.32010-05-20
CVE-2010-1987 [MEDIUM] CVE-2010-1987: Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory
Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application crash) via JavaScript code that appends long strings to the content of a P element, and performs certain other string concatenation and substring operations, related to the DoubleWideCharMappedString class in US
nvd
CVE-2007-4879P4MEDIUMCVSS 5.0≤ 2.0.0.12v0.1+59 more2007-09-13
CVE-2007-4879 [MEDIUM] CVE-2007-4879: Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS c
Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.
nvd
CVE-2012-4194P4MEDIUMCVSS 4.3fixed in 16.0.2≥ 10.0, < 10.0.102012-10-29
CVE-2012-4194 [MEDIUM] CWE-79 CVE-2012-4194: Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbi
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors inv
nvd