Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 150 of 162
CVE-2013-0792P4MEDIUMCVSS 4.3≤ 19.0.2v19.0+1 more2013-04-03
CVE-2013-0792 [MEDIUM] CWE-200 CVE-2013-0792: Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, d
Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a grayscale PNG image.
nvd
CVE-2013-1709P4MEDIUMCVSS 4.3v17.0v17.0.1+13 more2013-08-07
CVE-2013-1709 [MEDIUM] CWE-79 CVE-2013-1709: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in
nvd
CVE-2017-7796P4MEDIUMCVSS 4.7fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7796 [MEDIUM] CWE-20 CVE-2017-7796: On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it ru
On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that name. The path to this file is supplied at the command line to the updater and could be used in concert with another local exploit to delete a different file named "update.log" instead of the one intended. Note: Thi
nvd
CVE-2015-0834P4MEDIUMCVSS 4.3≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0834 [MEDIUM] CWE-200 CVE-2015-0834: The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses t
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.
nvdosv
CVE-2017-5395P4MEDIUMCVSS 4.3fixed in 51.02018-06-11
CVE-2017-5395 [MEDIUM] CWE-20 CVE-2017-5395: Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing l
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.
nvd
CVE-2010-0182P4MEDIUMCVSS 4.3v3.6≤ 3.5.7+92 more2010-04-05
CVE-2010-0182 [MEDIUM] CWE-20 CVE-2010-0182: The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird b
The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.
nvd
CVE-2014-1558P4MEDIUMCVSS 4.3≤ 30.02014-07-23
CVE-2014-1558 [MEDIUM] CVE-2014-1558: Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1559.
nvdosv
CVE-2011-2605P4MEDIUMCVSS 4.3≤ 3.6.17v1.0+105 more2011-06-30
CVE-2011-2605 [MEDIUM] CVE-2011-2605: CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/coo
CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a Ja
nvd
CVE-2013-1715P4MEDIUMCVSS 6.9≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1715 [MEDIUM] CVE-2013-1715: Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in M
Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.
nvd
CVE-2020-12399P4MEDIUMCVSS 4.4fixed in 77.0≥ unspecified, < 772020-07-09
CVE-2020-12399 [MEDIUM] CWE-203 CVE-2020-12399: NSS has shown timing differences when performing DSA signatures, which was exploitable and could eve
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2021-29960P4MEDIUMCVSS 4.3≥ 78.11.0, < 89.0≥ unspecified, < 892021-06-24
CVE-2021-29960 [MEDIUM] CWE-669 CVE-2021-29960: Firefox used to cache the last filename used for printing a file. When generating a filename for pri
Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined may have lead to the title of a website visited during private browsing mode being stored on disk. This vulnerability affects Firefox < 89.
nvdosv
CVE-2012-1943P4MEDIUMCVSS 6.9v12.02012-06-05
CVE-2012-1943 [MEDIUM] CVE-2012-1943: Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox
Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory.
nvd
CVE-2010-3181P4MEDIUMCVSS 6.9v3.6v3.6.2+90 more2010-10-21
CVE-2010-3181 [MEDIUM] CVE-2010-3181: Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunde
Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd
CVE-2021-29961P4MEDIUMCVSS 4.3≥ 78.11.0, < 89.0≥ unspecified, < 892021-06-24
CVE-2021-29961 [MEDIUM] CWE-863 CVE-2021-29961: When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping w
When styling and rendering an oversized `` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89.
nvdosv
CVE-2022-46877P4MEDIUMCVSS 4.3fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46877 [MEDIUM] CWE-79 CVE-2022-46877: By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulti
By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.
nvd
CVE-2009-3007P4MEDIUMCVSS 4.3v3.5.12009-08-28
CVE-2009-3007 [MEDIUM] CVE-2009-3007: Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to sp
Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
nvd
CVE-2019-11754P4MEDIUMCVSS 4.3fixed in 69.0.1≥ unspecified, < 69.0.12019-09-27
CVE-2019-11754 [MEDIUM] CVE-2019-11754: When the pointer lock is enabled by a website though requestPointerLock(), no user notification is g
When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1.
nvdosv
CVE-2020-12402P4MEDIUMCVSS 4.4fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12402 [MEDIUM] CWE-203 CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does n
nvd
CVE-2020-15651P4MEDIUMCVSS 4.3fixed in 28.02020-08-10
CVE-2020-15651 [MEDIUM] CVE-2020-15651: A unicode RTL order character in the downloaded file name can be used to change the file's name duri
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.
nvd
CVE-2021-43533P4MEDIUMCVSS 4.3fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-43533 [MEDIUM] CVE-2021-43533: When parsing internationalized domain names, high bits of the characters in the URLs were sometimes
When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94.
nvdosv