Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 159 of 162
CVE-2009-3014P4MEDIUMCVSS 4.3≤ 3.0.13v3.0.1+14 more2009-08-31
CVE-2009-3014 [MEDIUM] CWE-79 CVE-2009-3014: Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Loca
nvd
CVE-2008-4723P4MEDIUMCVSS 4.3v3.0.1v3.0.2+1 more2008-10-23
CVE-2008-4723 [MEDIUM] CWE-79 CVE-2008-4723: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow rem
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2009-3012P4MEDIUMCVSS 4.3≤ 3.0.13v3.0+15 more2009-08-31
CVE-2009-3012 [MEDIUM] CWE-79 CVE-2009-3012: Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: UR
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data
nvd
CVE-2007-5415P4MEDIUMCVSS 4.3v2.02007-10-12
CVE-2007-5415 [MEDIUM] CVE-2007-5415: Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rend
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5414.
nvd
CVE-2012-1964P4MEDIUMCVSS 4.0v4.0v4.0.1+20 more2012-07-18
CVE-2012-1964 [MEDIUM] CVE-2012-1964: The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml i
The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.10 does not properly handle attempted clickjacking of the about:certerror page, which allows man-in-the-
nvd
CVE-2006-3812P4LOWCVSS 2.6v1.5v1.5.0.1+3 more2006-07-29
CVE-2006-3812 [LOW] CVE-2006-3812: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.
nvd
CVE-2025-13015P4LOWCVSS 3.4fixed in 115.30.0fixed in 145.0+1 more2025-11-11
CVE-2025-13015 [LOW] CWE-290 CVE-2025-13015: Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firef
Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.
nvd
CVE-2005-2114P4MEDIUMCVSS 5.0v1.0.42005-07-05
CVE-2005-2114 [MEDIUM] CVE-2005-2114: Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other pro
Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.
nvd
CVE-2010-0181P4MEDIUMCVSS 4.3v3.6≤ 3.5.7+92 more2010-04-05
CVE-2010-0181 [MEDIUM] CWE-20 CVE-2010-0181: Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail app
Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.
nvd
CVE-2008-0592P4MEDIUMCVSS 4.3≤ 2.0.0.112008-02-09
CVE-2008-0592 [MEDIUM] CVE-2008-0592: Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to
Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a "Content-Disposition: attachment" and an invalid "Content-Type: plain/text," which prevents Firefox from rendering future plain text files within the browser.
nvd
CVE-2006-6506P4MEDIUMCVSS 4.3v2.02006-12-20
CVE-2006-6506 [MEDIUM] CVE-2006-6506: The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requ
The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed viewing services to determine browsing habits.
nvd
CVE-2006-2783P4MEDIUMCVSS 4.3≤ 1.5.0.32006-06-02
CVE-2006-2783 [MEDIUM] CWE-79 CVE-2006-2783: Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8
Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.
nvd
CVE-2008-3444P4MEDIUMCVSS 4.3v3.0v3.0.12008-08-04
CVE-2008-3444 [MEDIUM] CWE-20 CVE-2008-3444: The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a den
The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."
nvd
CVE-2007-6589P4MEDIUMCVSS 4.3≤ 2.0.0.92007-12-28
CVE-2007-6589 [MEDIUM] CVE-2007-6589: The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not upda
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.
nvd
CVE-2025-1939P4LOWCVSS 3.9fixed in 136.02025-03-04
CVE-2025-1939 [LOW] CWE-359 CVE-2025-1939: Android apps can load web pages using the Custom Tabs feature. This feature supports a transition an
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.
nvd
CVE-2011-2372P4LOWCVSS 3.5≤ 3.6.22v3.6+23 more2011-09-29
CVE-2011-2372 [LOW] CWE-264 CVE-2011-2372: Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.
nvd
CVE-2005-0232P4LOWCVSS 2.6v1.02005-05-02
CVE-2005-0232 [LOW] CVE-2005-0232: Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config
Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."
nvd
CVE-2005-1937P4LOWCVSS 2.6v1.0.32005-06-14
CVE-2005-1937 [LOW] CVE-2005-1937: A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Ja
A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.
nvd
CVE-2015-4508P4LOWCVSS 2.6≤ 40.0.32015-09-24
CVE-2015-4508 [LOW] CWE-254 CVE-2015-4508: Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relat
Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.
nvdosv
CVE-2005-2602P4LOWCVSS 2.6v1.0.62005-08-17
CVE-2005-2602 [LOW] CVE-2005-2602: Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI,
Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.
nvd