cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 151 of 162
CVE-2020-15668P4MEDIUMCVSS 4.3fixed in 80.0≥ unspecified, < 802020-10-01
CVE-2020-15668 [MEDIUM] CWE-667 CVE-2020-15668: A lock was missing when accessing a data structure and importing certificate information into the tr A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvdosv
CVE-2023-6871P4MEDIUMCVSS 4.3fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6871 [MEDIUM] CVE-2023-6871: Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a n Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121.
nvdosv
CVE-2023-25750P4MEDIUMCVSS 4.3fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-25750 [MEDIUM] CWE-668 CVE-2023-25750: Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.
nvdosv
CVE-2024-5697P4MEDIUMCVSS 4.3fixed in 127≥ unspecified, < 1272024-06-11
CVE-2024-5697 [MEDIUM] CWE-203 CVE-2024-5697: A website was able to detect when a user took a screenshot of a page using the built-in Screenshot f A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.
nvdosv
CVE-2023-25749P4MEDIUMCVSS 4.3fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-25749 [MEDIUM] CWE-863 CVE-2023-25749: Android applications with unpatched vulnerabilities can be launched from a browser using Intents, ex Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. Firefox will now confirm with users that they want to launch an external application before doing so. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability aff
nvd
CVE-2023-6870P4MEDIUMCVSS 4.3fixed in 121.0≥ unspecified, < 1302023-12-19
CVE-2023-6870 [MEDIUM] CVE-2023-6870: Applications which spawn a Toast notification in a background thread may have obscured fullscreen no Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
nvd
CVE-2024-6608P4MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6608 [MEDIUM] CVE-2024-6608: It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosv
CVE-2024-6614P4MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6614 [MEDIUM] CWE-835 CVE-2024-6614: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosv
CVE-2022-22762P4MEDIUMCVSS 4.3fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22762 [MEDIUM] CWE-451 CVE-2022-22762: Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another webs Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.
nvd
CVE-2025-1019P4MEDIUMCVSS 4.3fixed in 135.02025-02-04
CVE-2025-1019 [MEDIUM] CWE-1021 CVE-2025-1019: The z-order of the browser windows could be manipulated to hide the fullscreen notification. This co The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2023-28159P4MEDIUMCVSS 4.3fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28159 [MEDIUM] CWE-1021 CVE-2023-28159: The fullscreen notification could have been hidden on Firefox for Android by using download popups, The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.
nvd
CVE-2024-6610P4MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6610 [MEDIUM] CWE-451 CVE-2024-6610: Form validation popups could capture escape key presses. Therefore, spamming form validation message Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosv
CVE-2024-0749P4MEDIUMCVSS 4.3fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0749 [MEDIUM] CWE-346 CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
nvd
CVE-2021-29963P4MEDIUMCVSS 4.3fixed in 89.0≥ unspecified, < 892021-06-24
CVE-2021-29963 [MEDIUM] CWE-345 CVE-2021-29963: Address bar search suggestions in private browsing mode were re-using session data from normal mode. Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.
nvd
CVE-2025-1935P4MEDIUMCVSS 4.3fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1935 [MEDIUM] CWE-79 CVE-2025-1935: A web page could trick a user into setting that site as the default handler for a custom URL protoco A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvd
CVE-2025-5266P4MEDIUMCVSS 4.3fixed in 128.11.0fixed in 139.02025-05-27
CVE-2025-5266 [MEDIUM] CWE-200 CVE-2025-5266: Script elements loading cross-origin resources generated load and error events which leaked informat Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
nvd
CVE-2025-27424P4MEDIUMCVSS 4.3fixed in 136.02025-03-04
CVE-2025-27424 [MEDIUM] CWE-601 CVE-2025-27424: Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a mali Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.
nvd
CVE-2025-23108P4MEDIUMCVSS 4.3fixed in 134.02025-01-11
CVE-2025-23108 [MEDIUM] CWE-79 CVE-2025-23108: Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a mal Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability was fixed in Firefox for iOS 134.
nvd
CVE-2025-27425P4MEDIUMCVSS 4.3fixed in 136.02025-03-04
CVE-2025-27425 [MEDIUM] CWE-287 CVE-2025-27425: Scanning certain QR codes that included text with a website URL could allow the URL to be opened wit Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.
nvd
CVE-2025-5263P4MEDIUMCVSS 4.3fixed in 115.24.0fixed in 139.0+1 more2025-05-27
CVE-2025-5263 [MEDIUM] CWE-346 CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content, which could have allo Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.
nvd
Mozilla Firefox vulnerabilities | cvebase