cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 153 of 162
CVE-2016-1957P4MEDIUMCVSS 4.3≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1957 [MEDIUM] CWE-119 CVE-2016-1957: Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
nvd
CVE-2010-1197P4MEDIUMCVSS 4.3v3.5v3.5.1+10 more2010-06-24
CVE-2010-1197 [MEDIUM] CWE-79 CVE-2010-1197: Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not pro Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.
nvd
CVE-2008-0593P4MEDIUMCVSS 4.3≤ 2.0.0.11v0.2+8 more2008-02-09
CVE-2008-0593 [MEDIUM] CWE-200 CVE-2008-0593: Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify t Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.
nvd
CVE-2009-3010P4MEDIUMCVSS 4.3≤ 3.0.13v3.5+2 more2009-08-31
CVE-2009-3010 [MEDIUM] CWE-79 CVE-2009-3010: Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1 Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences i
nvd
CVE-2007-2869P4MEDIUMCVSS 4.3v1.5v1.5.0.1+14 more2007-06-01
CVE-2007-2869 [MEDIUM] CVE-2007-2869: The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and poss The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.
nvd
CVE-2008-0416P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-12
CVE-2008-0416 [MEDIUM] CWE-79 CVE-2008-0416: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-l
nvd
CVE-2013-1698P4MEDIUMCVSS 4.3≤ 21.0v19.0+4 more2013-06-26
CVE-2013-1698 [MEDIUM] CWE-264 CVE-2013-1698: The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a to The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.
nvd
CVE-2007-5960P4MEDIUMCVSS 4.3v0.8v0.9+46 more2007-11-26
CVE-2007-5960 [MEDIUM] CWE-22 CVE-2007-5960: Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal al
nvd
CVE-2015-7191P4MEDIUMCVSS 4.3≤ 41.0.22015-11-05
CVE-2015-7191 [MEDIUM] CWE-79 CVE-2015-7191: Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows att Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka "Universal XSS (UXSS)."
nvd
CVE-2012-4192P4MEDIUMCVSS 4.3v16.02012-10-12
CVE-2012-4192 [MEDIUM] CWE-264 CVE-2012-4192: Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.
nvd
CVE-2006-4340P4MEDIUMCVSS 4.0≤ 1.5.0.62006-09-15
CVE-2006-4340 [MEDIUM] CWE-20 CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5. Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulner
nvd
CVE-2016-5279P4MEDIUMCVSS 4.3≤ 48.0.22016-09-22
CVE-2016-5279 [MEDIUM] CWE-200 CVE-2016-5279: Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
nvdosv
CVE-2011-2369P4MEDIUMCVSS 4.3v4.0v4.0.12011-06-30
CVE-2011-2369 [MEDIUM] CWE-79 CVE-2011-2369: Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attacker Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.
nvd
CVE-2018-12358P4MEDIUMCVSS 4.3fixed in 61.0≥ unspecified, < 612018-10-18
CVE-2018-12358 [MEDIUM] CWE-200 CVE-2018-12358: Service workers can use redirection to avoid the tainting of cross-origin resources in some instance Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read responses which are supposed to be opaque. This vulnerability affects Firefox < 61.
nvdosv
CVE-2016-5268P4MEDIUMCVSS 4.3≤ 47.0.12016-08-05
CVE-2016-5268 [MEDIUM] CWE-254 CVE-2016-5268: Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT fl Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.
nvdosv
CVE-2017-5452P4MEDIUMCVSS 4.3fixed in 53.0≥ unspecified, < 532018-06-11
CVE-2017-5452 [MEDIUM] CWE-20 CVE-2017-5452: Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.
nvd
CVE-2021-23968P4MEDIUMCVSS 4.3fixed in 86.0fixed in 862021-02-26
CVE-2021-23968 [MEDIUM] CWE-209 CVE-2021-23968: If Content Security Policy blocked frame navigation, the full destination of a redirect served in th If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2014-1566P4MEDIUMCVSS 4.3≤ 31.0v30.02014-09-03
CVE-2014-1566 [MEDIUM] CVE-2014-1566: Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515.
nvd
CVE-2007-3074P4MEDIUMCVSS 4.3v2.0v2.0.0.1+3 more2007-06-06
CVE-2007-3074 [MEDIUM] CWE-200 CVE-2007-3074: Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox insta Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.
nvd
CVE-2010-1206P4MEDIUMCVSS 4.3v3.5.1v3.5.2+12 more2010-06-25
CVE-2010-1206 [MEDIUM] CWE-264 CVE-2010-1206: The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3. The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to con
nvd
Mozilla Firefox vulnerabilities | cvebase