cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 149 of 162
CVE-2012-4209P4MEDIUMCVSS 4.3fixed in 17.0≥ 10.0, < 10.0.112012-11-21
CVE-2012-4209 [MEDIUM] CWE-79 CVE-2012-4209: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a b
nvd
CVE-2012-3994P4MEDIUMCVSS 4.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-3994 [MEDIUM] CWE-79 CVE-2012-3994: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the
nvd
CVE-2010-2769P4MEDIUMCVSS 4.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2769 [MEDIUM] CWE-79 CVE-2010-2769: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Th Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.
nvd
CVE-2012-0471P4MEDIUMCVSS 4.3v4.0v4.0.1+16 more2012-04-25
CVE-2012-0471 [MEDIUM] CWE-79 CVE-2012-0471: Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x befor Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via a multibyte character set.
nvd
CVE-2012-0477P4MEDIUMCVSS 4.3v4.0v4.0.1+16 more2012-04-25
CVE-2012-0477 [MEDIUM] CWE-79 CVE-2012-0477: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 11.0, Firefox ESR Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) ISO-2022-KR or (2) ISO-2022-CN character set.
nvd
CVE-2016-1955P4MEDIUMCVSS 4.3≤ 44.0.22016-03-13
CVE-2016-1955 [MEDIUM] CWE-200 CVE-2016-1955: Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sens Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
nvd
CVE-2011-3000P4MEDIUMCVSS 4.3≤ 3.6.22v3.6+23 more2011-09-29
CVE-2011-3000 [MEDIUM] CWE-94 CVE-2011-3000: Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
nvd
CVE-2012-1956P4MEDIUMCVSS 4.3≤ 14.0v1.0+129 more2012-08-29
CVE-2012-1956 [MEDIUM] CWE-79 CVE-2012-1956: Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use o Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
nvd
CVE-2009-5017P4MEDIUMCVSS 4.3≤ 3.6v3.62010-11-12
CVE-2009-5017 [MEDIUM] CWE-79 CVE-2009-5017: Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it e Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
nvd
CVE-2012-0455P4MEDIUMCVSS 4.3≤ 3.6.27v4.0+13 more2012-03-14
CVE-2012-0455 [MEDIUM] CWE-79 CVE-2012-0455: Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird befo Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2008-4066P4MEDIUMCVSS 4.3v2.0.0.14v2.0.0.15+1 more2008-09-24
CVE-2008-4066 [MEDIUM] CWE-79 CVE-2008-4066: Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cros Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav�ascript" sequence, aka "HTML escaped low surrogates bug."
nvd
CVE-2018-18511P4MEDIUMCVSS 4.3v65.0≥ unspecified, < 65.0.12019-04-26
CVE-2018-18511 [MEDIUM] CWE-200 CVE-2018-18511: Cross-origin images can be read from a canvas element in violation of the same-origin policy using t Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
nvd
CVE-2012-0446P4MEDIUMCVSS 4.3v4.0v4.0.1+9 more2012-02-01
CVE-2012-0446 [MEDIUM] CWE-79 CVE-2012-0446: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted o
nvd
CVE-2011-2983P4MEDIUMCVSS 4.3≤ 3.6.19v1.0+105 more2011-08-18
CVE-2011-2983 [MEDIUM] CWE-200 CVE-2011-2983: Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and pos Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.
nvd
CVE-2017-5451P4MEDIUMCVSS 4.3fixed in 53.0fixed in 52.1.0+1 more2018-06-11
CVE-2017-5451 [MEDIUM] CWE-20 CVE-2017-5451: A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2011-0082P4MEDIUMCVSS 4.3v4.0v4.0.12011-06-06
CVE-2011-0082 [MEDIUM] CWE-20 CVE-2011-0082: The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not prope The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.
nvd
CVE-2011-3001P4MEDIUMCVSS 4.3v4.0v4.0.1+2 more2011-09-29
CVE-2011-3001 [MEDIUM] CWE-264 CVE-2011-3001: Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manua Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.
nvd
CVE-2016-2830P4MEDIUMCVSS 4.3≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-2830 [MEDIUM] CWE-200 CVE-2016-2830: Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used fo Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used for favicon resource retrieval after the associated browser window is closed, which makes it easier for remote web servers to track users by observing network traffic from multiple IP addresses.
nvd
CVE-2018-5167P4MEDIUMCVSS 4.3fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5167 [MEDIUM] CWE-20 CVE-2018-5167: The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both wil The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked into c
nvdosv
CVE-2008-0417P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-08
CVE-2008-0417 [MEDIUM] CWE-94 CVE-2008-0417: CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web site CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.
nvd