cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 152 of 162
CVE-2026-2802P4MEDIUMCVSS 4.2fixed in 148.02026-02-24
CVE-2026-2802 [MEDIUM] CWE-362 CVE-2026-2802: Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thun Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2006-1942P4MEDIUMCVSS 5.1v1.5.0.22006-04-20
CVE-2006-1942 [MEDIUM] CVE-2006-1942: Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, an Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using
nvd
CVE-2008-2933P4LOWCVSS 2.6≤ 2.0.0.15v0.8+61 more2008-07-17
CVE-2008-2933 [LOW] CWE-20 CVE-2008-2933: Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction
nvd
CVE-2009-1304P4MEDIUMCVSS 5.0v3.0v3.0.1+7 more2009-04-22
CVE-2009-1304 [MEDIUM] CWE-399 CVE-2009-1304: The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonke The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.
nvd
CVE-2010-1990P4MEDIUMCVSS 5.0v3.6.1v3.6.2+27 more2010-05-20
CVE-2010-1990 [MEDIUM] CWE-399 CVE-2010-1990: Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in sit Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
nvd
CVE-2009-1303P4MEDIUMCVSS 5.0≤ 3.0.8v0.1+77 more2009-04-22
CVE-2009-1303 [MEDIUM] CWE-16 CVE-2009-1303: The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey befor The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.
nvd
CVE-2005-0588P4MEDIUMCVSS 5.0v0.8v0.9+6 more2005-05-02
CVE-2005-0588 [MEDIUM] CVE-2005-0588: Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in X Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.
nvd
CVE-2010-1986P4MEDIUMCVSS 5.0v3.6.32010-05-20
CVE-2010-1986 [MEDIUM] CVE-2010-1986: Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption and application crash) via JavaScript code that creates multiple arrays containing elements with long string values, and then appends long strings to the content of a P element, related to the gfxWindowsFontGroup::MakeTextRun function in xul.dll, a
nvd
CVE-2010-0220P4MEDIUMCVSS 5.0≤ 3.5.6v0.1+66 more2010-01-07
CVE-2010-0220 [MEDIUM] CWE-399 CVE-2010-0220: The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox bef The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty obse
nvd
CVE-2013-1708P4MEDIUMCVSS 4.3≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1708 [MEDIUM] CVE-2013-1708: Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of se Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function.
nvd
CVE-2005-1158P4MEDIUMCVSS 5.0v0.8v0.9+8 more2005-05-02
CVE-2005-1158 [MEDIUM] CVE-2005-1158: Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrar Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.
nvd
CVE-2005-1575P4MEDIUMCVSS 5.0v0.10.1v1.02005-05-14
CVE-2005-1575 [MEDIUM] CVE-2005-1575: The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hi The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.
nvd
CVE-2008-1234P4MEDIUMCVSS 4.3≤ 2.0.0.122008-03-27
CVE-2008-1234 [MEDIUM] CWE-79 CVE-2008-1234: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0. Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."
nvd
CVE-2008-5913P4MEDIUMCVSS 4.9v3.5v3.5.1+12 more2009-01-20
CVE-2008-5913 [MEDIUM] CVE-2008-5913: The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating t
nvd
CVE-2009-1835P4MEDIUMCVSS 4.3≤ 3.0.10v0.1+88 more2009-06-12
CVE-2009-1835 [MEDIUM] CWE-200 CVE-2009-1835: Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external do Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.
nvd
CVE-2009-2472P4MEDIUMCVSS 4.3fixed in 3.0.122009-07-22
CVE-2009-2472 [MEDIUM] CWE-79 CVE-2009-2472: Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
nvd
CVE-2016-5250P4MEDIUMCVSS 4.3≤ 47.0.12016-08-05
CVE-2016-5250 [MEDIUM] CWE-200 CVE-2016-5250: Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obt Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.
nvd
CVE-2008-0415P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-08
CVE-2008-0415 [MEDIUM] CWE-79 CVE-2008-0415: Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remo Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
nvd
CVE-2012-1966P4MEDIUMCVSS 4.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1966 [MEDIUM] CWE-264 CVE-2012-1966: Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-men Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
nvd
CVE-2007-5896P4HIGHCVSS 7.1v2.0.0.92007-11-08
CVE-2007-5896 [HIGH] CWE-399 CVE-2007-5896: Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and cr Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) file:/// URI.
nvd