Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 156 of 162
CVE-2006-2613P4MEDIUMCVSS 4.3v1.5.0.1v1.5.0.2+1 more2006-05-26
CVE-2006-2613 [MEDIUM] CWE-200 CVE-2006-2613: Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and N
Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by causing exceptions to be thrown and checking the message contents.
nvd
CVE-2007-2870P4MEDIUMCVSS 4.3v1.5v1.5.0.1+14 more2007-06-01
CVE-2007-2870 [MEDIUM] CVE-2007-2870: Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.
nvd
CVE-2010-0170P4MEDIUMCVSS 4.3v3.62010-03-25
CVE-2010-0170 [MEDIUM] CWE-79 CVE-2010-0170: Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mech
Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.
nvd
CVE-2011-3648P4MEDIUMCVSS 4.3≤ 3.6.23v0.1+131 more2011-11-09
CVE-2011-3648 [MEDIUM] CWE-79 CVE-2011-3648: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Th
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.
nvd
CVE-2014-1560P4MEDIUMCVSS 4.3≤ 30.02014-07-23
CVE-2014-1560 [MEDIUM] CVE-2014-1560: Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use ASCII character encoding in a required context.
nvdosv
CVE-2002-2436P4MEDIUMCVSS 4.3≤ 3.6.24v3.0+56 more2011-12-07
CVE-2002-2436 [MEDIUM] CWE-200 CVE-2002-2436: The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
nvd
CVE-2017-5453P4MEDIUMCVSS 4.3fixed in 53.0≥ unspecified, < 532018-06-11
CVE-2017-5453 [MEDIUM] CWE-20 CVE-2017-5453: A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape charac
A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element. This vulnerability allows for spoofing but no scripted content can be run. This vulnerability affects Firefox < 53.
nvdosv
CVE-2011-2999P4MEDIUMCVSS 4.3≤ 3.6.22v3.6+22 more2011-09-29
CVE-2011-2999 [MEDIUM] CVE-2011-2999: Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do
Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.
nvd
CVE-2011-1712P4MEDIUMCVSS 4.3≤ 3.5.18v1.0+102 more2011-04-15
CVE-2011-1712 [MEDIUM] CWE-200 CVE-2011-1712: The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWa
The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to t
nvd
CVE-2019-17002P4MEDIUMCVSS 4.3fixed in 70.0vbefore 702020-01-08
CVE-2019-17002 [MEDIUM] CVE-2019-17002: If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged an
If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.
nvdosv
CVE-2012-3987P4MEDIUMCVSS 4.0≤ 15.0.1v0.1+147 more2012-10-10
CVE-2012-3987 [MEDIUM] CWE-264 CVE-2012-3987: Mozilla Firefox before 16.0 on Android assigns chrome privileges to Reader Mode pages, which allows
Mozilla Firefox before 16.0 on Android assigns chrome privileges to Reader Mode pages, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.
nvd
CVE-2013-0776P4MEDIUMCVSS 4.0fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0776 [MEDIUM] CWE-295 CVE-2013-0776: Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird
Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operating a proxy server that provides a 407 HTTP status code accompanied by web script, as demonstrated by a phishing attack on an HTTPS site
nvd
CVE-2015-2720P4MEDIUMCVSS 4.4≤ 37.0.22015-05-14
CVE-2015-2720 [MEDIUM] CWE-17 CVE-2015-2720: The update implementation in Mozilla Firefox before 38.0 on Windows does not ensure that the pathnam
The update implementation in Mozilla Firefox before 38.0 on Windows does not ensure that the pathname for updater.exe corresponds to the application directory, which might allow local users to gain privileges via a Trojan horse file.
nvd
CVE-2006-0298P4MEDIUMCVSS 5.8v1.52006-02-02
CVE-2006-0298 [MEDIUM] CWE-20 CVE-2006-0298: The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
nvd
CVE-2008-2809P4MEDIUMCVSS 4.0v2.0.0.1v2.0.0.2+12 more2008-07-08
CVE-2008-2809 [MEDIUM] CWE-20 CVE-2008-2809: Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions be
Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regard the certificate as also accepted for all domain names in subjectAltName:dNSName fiel
nvd
CVE-2007-0775P4LOWCVSS 3.7v1.0v1.0.1+19 more2007-02-26
CVE-2007-0775 [LOW] CVE-2007-0775: Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x
Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially execute arbitrary code via certain vectors.
nvd
CVE-2024-3861P4MEDIUMCVSS 4.0fixed in 115.0fixed in 125.0+1 more2024-04-16
CVE-2024-3861 [MEDIUM] CWE-416 CVE-2024-3861: If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect r
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2005-0402P4LOWCVSS 2.6v0.8v0.9+8 more2005-05-02
CVE-2005-0402 [LOW] CVE-2005-0402: Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into savin
Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.
nvd
CVE-2006-6499P4MEDIUMCVSS 4.3≥ 1.5, < 1.5.0.9≥ 2.0, < 2.0.0.12006-12-20
CVE-2006-6499 [MEDIUM] CWE-835 CVE-2006-6499: The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.
nvd
CVE-2004-0761P4MEDIUMCVSS 5.0≤ 0.92004-08-18
CVE-2004-0761 [MEDIUM] CVE-2004-0761: Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use ce
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.
nvd