cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 161 of 162
CVE-2023-4579P4LOWCVSS 3.1fixed in 117.0≥ unspecified, < 1172023-09-11
CVE-2023-4579 [LOW] CVE-2023-4579: Search queries in the default search engine could appear to have been the currently navigated URL if Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.
nvdosv
CVE-2004-1753P4LOWCVSS 2.6v0.9.32004-12-31
CVE-2004-1753 [LOW] CVE-2004-1753: The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.
nvd
CVE-2005-0141P4LOWCVSS 2.6v0.8v0.9+3 more2005-05-02
CVE-2005-0141 [LOW] CVE-2005-0141: Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "wi Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.
nvd
CVE-2011-3649P4LOWCVSS 2.6v7.02011-11-09
CVE-2011-3649 [LOW] CVE-2011-3649: Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conju Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.
nvd
CVE-2005-0578P4LOWCVSS 2.1v0.8v0.9+6 more2005-05-02
CVE-2005-0578 [LOW] CVE-2005-0578: Firefox before 1.0.1 and Mozilla Suite before 1.7.6 use a predictable filename for the plugin tempor Firefox before 1.0.1 and Mozilla Suite before 1.7.6 use a predictable filename for the plugin temporary directory, which allows local users to delete arbitrary files of other users via a symlink attack on the plugtmp directory.
nvd
CVE-2005-2268P4LOWCVSS 2.6v0.8v0.9+10 more2005-07-13
CVE-2005-2268 [LOW] CVE-2005-2268: Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box wit Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
nvd
CVE-2009-0354P4LOWCVSS 2.6v3.0v3.0.1+4 more2009-02-04
CVE-2009-0354 [LOW] CWE-79 CVE-2009-0354: Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote att Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.
nvd
CVE-2016-9062P4LOWCVSS 3.3fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9062 [LOW] CWE-200 CVE-2016-9062: Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" a Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the Firefox profile after the mode is exited. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
nvd
CVE-2020-12394P4LOWCVSS 3.3fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12394 [LOW] CVE-2020-12394: A logic flaw in our location bar implementation could have allowed a local attacker to spoof the cur A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.
nvdosv
CVE-2020-15671P4LOWCVSS 3.1fixed in 80.02020-10-01
CVE-2020-15671 [LOW] CWE-200 CVE-2020-15671: When typing in a password under certain conditions, a race may have occured where the InputContext w When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.
nvd
CVE-2005-3089P4LOWCVSS 2.6v1.0v1.0.1+5 more2005-09-28
CVE-2005-3089 [LOW] CVE-2005-3089: Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) sc Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.
nvd
CVE-2005-1576P4LOWCVSS 2.6v0.10.1v1.02005-05-12
CVE-2005-1576 [LOW] CVE-2005-1576: The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP he The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.
nvd
CVE-2005-0584P4LOWCVSS 2.6v0.8v0.9+6 more2005-05-02
CVE-2005-0584 [LOW] CVE-2005-0584: Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do no Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.
nvd
CVE-2024-2616P4LOWCVSS 2.7fixed in 115.9.02024-03-19
CVE-2024-2616 [LOW] CWE-787 CVE-2024-2616: To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash i To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 and Thunderbird < 115.9.
nvd
CVE-2007-5414P4LOWCVSS 2.6≤ 1.82007-10-12
CVE-2007-5414 [LOW] CWE-79 CVE-2007-5414: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.
nvd
CVE-2020-6824P4LOWCVSS 2.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6824 [LOW] CWE-384 CVE-2020-6824: Initially, a user opens a Private Browsing Window and generates a password for a site, then closes t Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This
nvdosv
CVE-2017-5387P4LOWCVSS 3.3fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5387 [LOW] CWE-538 CVE-2017-5387: The existence of a specifically requested local file can be found due to the double firing of the "o The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "" tag refers to a file that does not exist if the source page is loaded locally. This vulnerability affects Firefox < 51.
nvdosv
CVE-2006-4569P4LOWCVSS 2.6≤ 1.5.0.62006-09-15
CVE-2006-4569 [LOW] CVE-2006-4569: The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the contex The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2005-0585P4LOWCVSS 2.6v0.8v0.9+6 more2005-03-25
CVE-2005-0585 [LOW] CVE-2005-0585: Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
nvd
CVE-2005-0586P4LOWCVSS 2.6v0.8v0.9+6 more2005-05-02
CVE-2005-0586 [LOW] CVE-2005-0586: Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensi Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.
nvd
Mozilla Firefox vulnerabilities | cvebase