cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 157 of 162
CVE-2008-2014P4MEDIUMCVSS 5.0v3.02008-04-30
CVE-2008-2014 [MEDIUM] CWE-399 CVE-2008-2014: Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
nvd
CVE-2010-2754P4MEDIUMCVSS 5.0v3.5.1v3.5.2+12 more2010-07-30
CVE-2010-2754 [MEDIUM] CWE-200 CVE-2010-2754: dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderb dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about s
nvd
CVE-2007-5947P4MEDIUMCVSS 4.3≤ 2.0.0.9v2.0.0.1+7 more2007-11-14
CVE-2007-5947 [MEDIUM] CWE-79 CVE-2007-5947: The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
nvd
CVE-2009-0581P4MEDIUMCVSS 4.3v3.12009-03-23
CVE-2009-0581 [MEDIUM] CWE-401 CVE-2009-0581: Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.
nvd
CVE-2007-2871P4MEDIUMCVSS 4.3v1.5v1.5.0.1+14 more2007-06-01
CVE-2007-2871 [MEDIUM] CVE-2007-2871: Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.
nvd
CVE-2006-4568P4MEDIUMCVSS 4.3≤ 1.5.0.62006-09-15
CVE-2006-4568 [MEDIUM] CWE-79 CVE-2006-4568: Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the secu Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.
nvd
CVE-2011-3663P4MEDIUMCVSS 4.3v4.0v4.0.1+7 more2011-12-21
CVE-2011-3663 [MEDIUM] CWE-200 CVE-2011-3663: Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within that web page.
nvd
CVE-2008-2800P4MEDIUMCVSS 4.3≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2800 [MEDIUM] CWE-79 CVE-2008-2800: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Sam Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpReque
nvd
CVE-2009-3978P4MEDIUMCVSS 4.3≤ 3.5.4v0.1+64 more2009-11-19
CVE-2009-3978 [MEDIUM] CVE-2009-3978: The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
nvd
CVE-2010-2117P4MEDIUMCVSS 4.3v3.0.19v3.5+9 more2010-06-01
CVE-2010-2117 [MEDIUM] CWE-399 CVE-2010-2117: Mozilla Firefox 3.0.19, 3.5.x, and 3.6.x allows remote attackers to cause a denial of service (resou Mozilla Firefox 3.0.19, 3.5.x, and 3.6.x allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.
nvd
CVE-2014-1590P4MEDIUMCVSS 4.3≤ 31.2≤ 33.02014-12-11
CVE-2014-1590 [MEDIUM] CWE-20 CVE-2014-1590: The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31. The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to cause a denial of service (application crash) via a crafted JavaScript object.
nvdosv
CVE-2009-1310P4MEDIUMCVSS 4.3≤ 3.0.8v0.1+78 more2009-04-22
CVE-2009-1310 [MEDIUM] CWE-79 CVE-2009-1310: Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox b Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.
nvd
CVE-2004-1156P4MEDIUMCVSS 4.3v0.8v0.9+6 more2004-12-31
CVE-2004-1156 [MEDIUM] CVE-2004-1156: Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
nvd
CVE-2010-1207P4MEDIUMCVSS 4.3≤ 3.6.6v3.6+3 more2010-07-30
CVE-2010-1207 [MEDIUM] CWE-264 CVE-2010-1207: Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restriction Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.
nvd
CVE-2009-1309P4MEDIUMCVSS 4.3≤ 3.0.8v0.1+86 more2009-04-22
CVE-2009-1309 [MEDIUM] CWE-16 CVE-2009-1309: Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin P Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attac
nvd
CVE-2008-2808P4MEDIUMCVSS 4.3v2.0v2.0.0.2+12 more2008-07-07
CVE-2008-2808 [MEDIUM] CWE-79 CVE-2008-2808: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// U Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.
nvd
CVE-2007-3736P4MEDIUMCVSS 4.3v2.0v2.0.0.1+3 more2007-07-18
CVE-2007-3736 [MEDIUM] CVE-2007-3736: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers t Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.
nvd
CVE-2010-1210P4MEDIUMCVSS 4.3≤ 3.6.6v0.1+103 more2010-07-30
CVE-2010-1210 [MEDIUM] CWE-20 CVE-2010-1210: intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1 intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.
nvd
CVE-2013-0774P4MEDIUMCVSS 4.3fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0774 [MEDIUM] CVE-2013-0774: Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent JavaScript workers from reading the browser-profile directory name, which has unspecified impact and remote attack vectors.
nvd
CVE-2010-0648P4MEDIUMCVSS 4.3≤ 3.5.7v1.0+73 more2010-02-18
CVE-2010-0648 [MEDIUM] CWE-200 CVE-2010-0648: Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, f Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.
nvd