cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 160 of 162
CVE-2007-5335P4MEDIUMCVSS 4.3≤ 2.0.0.72007-10-24
CVE-2007-5335 [MEDIUM] CWE-200 CVE-2007-5335: Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to access file: URIs.
nvd
CVE-2007-3657P4MEDIUMCVSS 4.3v2.0.0.42007-07-10
CVE-2007-3657 [MEDIUM] CVE-2007-3657: Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tab Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tabs in a popup window. NOTE: this issue has been disputed by third party researchers, stating that "this does not crash on me, and I can't see a likely mechanism of action that would lead to a DoS condition.
nvd
CVE-2006-1736P4LOWCVSS 2.6≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1736 [LOW] CVE-2006-1736: Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey be Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as.
nvd
CVE-2004-1200P4MEDIUMCVSS 5.0v0.8v0.9+6 more2004-12-31
CVE-2004-1200 [MEDIUM] CVE-2004-1200: Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memo Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
nvd
CVE-2025-0245P4LOWCVSS 3.3fixed in 134.02025-01-07
CVE-2025-0245 [LOW] CVE-2025-0245: Under certain circumstances, a user opt-in setting that Focus should require authentication before u Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability was fixed in Firefox 134.
nvd
CVE-2005-0591P4LOWCVSS 2.6v0.8v0.9+6 more2005-05-02
CVE-2005-0591 [LOW] CVE-2005-0591: Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."
nvd
CVE-2022-42931P4LOWCVSS 3.3fixed in 106.0≥ unspecified, < 1062022-12-22
CVE-2022-42931 [LOW] CWE-312 CVE-2022-42931: Logins saved by Firefox should be managed by the Password Manager component which uses encryption to Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.
nvdosv
CVE-2012-0475P4LOWCVSS 2.6v4.0v4.0.1+15 more2012-04-25
CVE-2012-0475 [LOW] CWE-264 CVE-2012-0475: Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not prop Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that co
nvd
CVE-2010-2751P4LOWCVSS 2.6v3.5.1v3.5.2+12 more2010-07-30
CVE-2010-2751 [LOW] CWE-264 CVE-2010-2751: The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3. The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and history.forward JavaScript functions.
nvd
CVE-2013-1729P4LOWCVSS 2.6≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1729 [LOW] CWE-200 CVE-2013-1729: The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Ma The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element.
nvd
CVE-2006-1740P4LOWCVSS 2.6≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1740 [LOW] CVE-2006-1740: Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey be Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.
nvd
CVE-2014-1504P4LOWCVSS 2.6fixed in 28.02014-03-19
CVE-2014-1504 [LOW] CWE-264 CVE-2014-1504: The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consid The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.
nvd
CVE-2021-24000P4LOWCVSS 3.1fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-24000 [LOW] CWE-362 CVE-2021-24000: A race condition with requestPointerLock() and setTimeout() could have resulted in a user interactin A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as ) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not i
nvdosv
CVE-2006-4567P4LOWCVSS 2.6≤ 1.5.0.62006-09-15
CVE-2006-4567 [LOW] CVE-2006-4567: Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to inst
nvd
CVE-2006-2786P4LOWCVSS 2.6≤ 1.5.0.32006-06-02
CVE-2006-2786 [LOW] CVE-2006-2786: HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used w HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignore
nvd
CVE-2008-5503P4LOWCVSS 2.6≤ 2.0.0.18v2.0+17 more2008-12-17
CVE-2008-5503 [LOW] CVE-2008-5503: The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0. The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.
nvd
CVE-2005-0145P4LOWCVSS 2.6v0.8v0.9+6 more2005-01-24
CVE-2005-0145 [LOW] CVE-2005-0145: Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
nvd
CVE-2007-5691P4MEDIUMCVSS 4.3v2.0.0.72007-10-29
CVE-2007-5691 [MEDIUM] CWE-20 CVE-2007-5691: ParseFTPList.cpp in Mozilla Firefox 2.0.0.7 allows remote FTP servers to cause a denial of service ( ParseFTPList.cpp in Mozilla Firefox 2.0.0.7 allows remote FTP servers to cause a denial of service (application crash) via a crafted reply to an unspecified listing command, related to "reading from invalid pointer."
nvd
CVE-2023-34414P4LOWCVSS 3.1fixed in 114.0≥ unspecified, < 1142023-06-19
CVE-2023-34414 [LOW] CWE-295 CVE-2023-34414: The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If a malicious page elicited user clicks in precise locations immediately before navigating to a site with a certificate error and made the renderer extremel
nvdosv
CVE-2005-0593P4LOWCVSS 2.6v0.8v0.9+6 more2005-03-04
CVE-2005-0593 [LOW] CVE-2005-0593: Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, wh
nvd
Mozilla Firefox vulnerabilities | cvebase