cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 155 of 162
CVE-2006-5464P4MEDIUMCVSS 5.0v1.5v1.5.0.1+6 more2006-11-08
CVE-2006-5464 [MEDIUM] CVE-2006-5464: Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunder Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.
nvd
CVE-2025-0240P4MEDIUMCVSS 4.0fixed in 128.6.0fixed in 134.02025-01-07
CVE-2025-0240 [MEDIUM] CWE-416 CVE-2025-0240: Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvd
CVE-2024-2606P4LOWCVSS 3.7fixed in 124.0≥ unspecified, < 1242024-03-19
CVE-2024-2606 [LOW] CWE-704 CVE-2024-2606: Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.
nvdosv
CVE-2009-1305P4MEDIUMCVSS 5.0v3.0v3.0.1+7 more2009-04-22
CVE-2009-1305 [MEDIUM] CWE-399 CVE-2009-1305: The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey be The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving JSOP_DEFVAR and properties that lack the JSPROP_PERMANENT attribute.
nvd
CVE-2008-5019P4MEDIUMCVSS 4.3≥ 2.0, < 2.0.0.18≥ 3.0, < 3.0.42008-11-13
CVE-2008-5019 [MEDIUM] CWE-79 CVE-2008-5019: The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remot The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
nvd
CVE-2005-0146P4MEDIUMCVSS 5.0v0.8v0.9+3 more2005-05-02
CVE-2005-0146 [MEDIUM] CVE-2005-0146: Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.
nvd
CVE-2007-5334P4MEDIUMCVSS 4.3≤ 2.0.0.72007-10-21
CVE-2007-5334 [MEDIUM] CWE-16 CVE-2007-5334: Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displa Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.
nvd
CVE-2005-0589P4MEDIUMCVSS 5.0v0.8v0.9+6 more2005-05-02
CVE-2005-0589 [MEDIUM] CVE-2005-0589: The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.
nvd
CVE-2006-1650P4MEDIUMCVSS 5.0v1.5.0.12006-04-06
CVE-2006-1650 [MEDIUM] CVE-2006-1650: Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attac Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading. NOTE: a followup was unable to replicate this issue.
nvd
CVE-2007-1116P4MEDIUMCVSS 5.0v1.82007-02-26
CVE-2007-1116 [MEDIUM] CWE-200 CVE-2007-1116: The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.
nvd
CVE-2009-1311P4MEDIUMCVSS 4.3≤ 3.0.8v0.1+81 more2009-04-22
CVE-2009-1311 [MEDIUM] CWE-200 CVE-2009-1311: Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obt Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.
nvd
CVE-2012-1965P4MEDIUMCVSS 4.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1965 [MEDIUM] CWE-79 CVE-2012-1965: Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the se Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.
nvd
CVE-2007-0995P4MEDIUMCVSS 4.3v1.5.0.10v2.0+1 more2007-02-26
CVE-2007-0995 [MEDIUM] CWE-79 CVE-2007-0995: Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.
nvd
CVE-2014-1489P4MEDIUMCVSS 4.3≤ 26.0v0.1+196 more2014-02-06
CVE-2014-1489 [MEDIUM] CWE-264 CVE-2014-1489: Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on oth Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
nvd
CVE-2008-5511P4MEDIUMCVSS 4.3≥ 2.0, < 2.0.0.19≥ 3.0, < 3.0.52008-12-17
CVE-2008-5511 [MEDIUM] CWE-79 CVE-2008-5511: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."
nvd
CVE-2013-1723P4MEDIUMCVSS 4.3≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1723 [MEDIUM] CWE-119 CVE-2013-1723: The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2 The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 processes key messages after destruction by a dispatched event listener, which allows remote attackers to cause a denial of service (application crash) by leveraging incorrect event usage after widget-memory reallocation.
nvd
CVE-2008-1241P4MEDIUMCVSS 4.3≤ 2.0.0.122008-03-27
CVE-2008-1241 [MEDIUM] CWE-59 CVE-2008-1241: GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remot GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XUL pop-up window from a background tab.
nvd
CVE-2008-5513P4MEDIUMCVSS 4.3≥ 2.0, < 2.0.0.19≥ 3.0, < 3.0.52008-12-17
CVE-2008-5513 [MEDIUM] CWE-79 CVE-2008-5513: Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.
nvd
CVE-2010-0171P4MEDIUMCVSS 4.3v3.0v3.0.1+17 more2010-03-25
CVE-2010-0171 [MEDIUM] CVE-2010-0171: Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this v
nvd
CVE-2007-0800P4MEDIUMCVSS 4.3v1.5.0.92007-02-07
CVE-2007-0800 [MEDIUM] CVE-2007-0800: Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zon Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary file:// URIs by convincing a user to show a blocked popup.
nvd