Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 162 of 162
CVE-2009-0358P4LOWCVSS 3.3v3.0v3.0.1+4 more2009-02-04
CVE-2009-0358 [LOW] CWE-200 CVE-2009-0358: Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.
nvd
CVE-2006-2332P4LOWCVSS 2.6v1.5.0.32006-05-12
CVE-2006-2332 [LOW] CVE-2006-2332: Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of service via a web page with a l
Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of service via a web page with a large number of IMG elements in which the SRC attribute is a mailto URI. NOTE: another researcher found that the web page caused a temporary browser slowdown instead of a crash.
nvd
CVE-2015-2714P4LOWCVSS 2.1≤ 37.0.22015-05-14
CVE-2015-2714 [LOW] CWE-264 CVE-2015-2714: Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android lo
Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.
nvd
CVE-2014-1515P4LOWCVSS 1.9≤ 28.02014-03-25
CVE-2014-1515 [LOW] CWE-200 CVE-2014-1515: Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD c
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.
nvd
CVE-2006-2538P4LOWCVSS 2.6v1.5.0.32006-05-22
CVE-2006-2538 [LOW] CVE-2006-2538: IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a den
IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a denial of service (application crash), possibly due to a null dereference, via certain Javascript, as demonstrated using a url parameter to the content/reloaded.html page in a chrome:// URI. Some third-party researchers claim that they are unable to reproduce this vu
nvd
CVE-2012-1945P4LOWCVSS 2.9v4.0v4.0.1+18 more2012-06-05
CVE-2012-1945 [LOW] CWE-200 CVE-2012-1945: Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thun
Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (
nvd
CVE-2005-0144P4LOWCVSS 2.6v0.8v0.9+3 more2005-05-02
CVE-2005-0144 [LOW] CVE-2005-0144: Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: UR
Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.
nvd
CVE-2006-3731P4LOWCVSS 2.6v1.5v1.5.0.1+3 more2006-07-21
CVE-2006-3731 [LOW] CVE-2006-3731: Mozilla Firefox 1.5.0.4 and earlier allows remote user-assisted attackers to cause a denial of servi
Mozilla Firefox 1.5.0.4 and earlier allows remote user-assisted attackers to cause a denial of service (crash) via a form with a multipart/form-data encoding and a user-uploaded file. NOTE: a third party has claimed that this issue might be related to the LiveHTTPHeaders extension.
nvd
CVE-2014-1595P4LOWCVSS 2.1v31.0v31.1.0+2 more2014-12-11
CVE-2014-1595 [LOW] CWE-199 CVE-2014-1595: Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
nvd
CVE-2012-0450P4LOWCVSS 2.1v4.0v4.0.1+9 more2012-02-01
CVE-2012-0450 [LOW] CWE-264 CVE-2012-0450: Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions
Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions for Firefox Recovery Key.html, which might allow local users to read a Firefox Sync key via standard filesystem operations.
nvd
CVE-2004-2657P4LOWCVSS 1.7v1.5.0.12004-12-31
CVE-2004-2657 [LOW] CVE-2004-2657: Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even a
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is
nvd
CVE-2005-0143P4LOWCVSS 2.6v0.8v0.9+6 more2005-03-23
CVE-2005-0143 [LOW] CVE-2005-0143: Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
nvd
CVE-2005-0142P4LOWCVSS 2.1v0.92005-05-02
CVE-2005-0142 [LOW] CVE-2005-0142: Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save tempor
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.
nvd
← Previous162 / 162