Mozilla Firefox vulnerabilities

3,029 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,029
CISA KEV
15
actively exploited
Public exploits
121
Exploited in wild
20
Severity breakdown
CRITICAL853HIGH879MEDIUM1228LOW69

Vulnerabilities

Page 17 of 152
CVE-2024-11699HIGHCVSS 8.8fixed in 128.5.0fixed in 133.0+1 more2024-11-26
CVE-2024-11699 [HIGH] CWE-94 CVE-2024-11699: Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these b Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
cvelistv5nvd
CVE-2024-11702HIGHCVSS 7.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11702 [HIGH] CWE-838 CVE-2024-11702: Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have ina Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.
cvelistv5nvd
CVE-2024-11696MEDIUMCVSS 5.4fixed in 128.5.0fixed in 133.0+1 more2024-11-26
CVE-2024-11696 [MEDIUM] CWE-347 CVE-2024-11696: The application failed to account for exceptions thrown by the `loadManifestFromFile` method during The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated ad
cvelistv5nvd
CVE-2024-11695MEDIUMCVSS 5.4fixed in 128.5.0fixed in 133.0+1 more2024-11-26
CVE-2024-11695 [MEDIUM] CWE-1021 CVE-2024-11695: A crafted URL containing Arabic script and whitespace characters could have hidden the true origin o A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
cvelistv5nvd
CVE-2024-11703MEDIUMCVSS 5.7fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11703 [MEDIUM] CWE-522 CVE-2024-11703: On Android, Firefox may have inadvertently allowed viewing saved passwords without the required devi On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.
cvelistv5nvd
CVE-2024-53976MEDIUMCVSS 5.4fixed in 133.02024-11-26
CVE-2024-53976 [MEDIUM] CWE-1021 CVE-2024-53976: Under certain circumstances, navigating to a webpage would result in the address missing from the lo Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
nvd
CVE-2024-11708MEDIUMCVSS 6.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11708 [MEDIUM] CWE-362 CVE-2024-11708: Missing thread synchronization primitives could have led to a data race on members of the PlaybackPa Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
cvelistv5nvdosv
CVE-2024-11692MEDIUMCVSS 4.3fixed in 128.5.0fixed in 133.0+1 more2024-11-26
CVE-2024-11692 [MEDIUM] CWE-290 CVE-2024-11692: An attacker could cause a select dropdown to be shown over another tab; this could have led to user An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
cvelistv5nvdosv
CVE-2024-53975MEDIUMCVSS 5.4fixed in 133.02024-11-26
CVE-2024-53975 [MEDIUM] CVE-2024-53975: Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.
nvd
CVE-2024-11694MEDIUMCVSS 6.1fixed in 115.8.0fixed in 133.0+2 more2024-11-26
CVE-2024-11694 [MEDIUM] CWE-79 CVE-2024-11694: Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass a Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ES
cvelistv5nvd
CVE-2024-11701MEDIUMCVSS 4.3fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11701 [MEDIUM] CWE-290 CVE-2024-11701: The incorrect domain may have been displayed in the address bar during an interrupted navigation att The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
cvelistv5nvdosv
CVE-2024-11706MEDIUMCVSS 6.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11706 [MEDIUM] CWE-476 CVE-2024-11706: A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `S A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.
cvelistv5nvdosv
CVE-2024-10941MEDIUMCVSS 6.5fixed in 126.0≥ unspecified, < 1262024-11-06
CVE-2024-10941 [MEDIUM] CWE-86 CVE-2024-10941: A malicious website could have included an iframe with an malformed URI resulting in a non-exploitab A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.
cvelistv5nvdosv
CVE-2024-10459HIGHCVSS 7.5fixed in 115.17fixed in 132.0+2 more2024-10-29
CVE-2024-10459 [HIGH] CWE-416 CVE-2024-10459: An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentia An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
cvelistv5nvd
CVE-2024-10458HIGHCVSS 7.5fixed in 115.17fixed in 132.0+2 more2024-10-29
CVE-2024-10458 [HIGH] CWE-281 CVE-2024-10458: A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `objec A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
cvelistv5nvdosv
CVE-2024-10467HIGHCVSS 8.8fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10467 [HIGH] CWE-787 CVE-2024-10467: Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these b Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
cvelistv5nvd
CVE-2024-10466HIGHCVSS 7.5fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10466 [HIGH] CWE-400 CVE-2024-10466: By sending a specially crafted push message, a remote server could have hung the parent process, cau By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
cvelistv5nvd
CVE-2024-10462MEDIUMCVSS 6.5fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10462 [MEDIUM] CWE-290 CVE-2024-10462: Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerabili Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
cvelistv5nvd
CVE-2024-10465MEDIUMCVSS 6.5fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10465 [MEDIUM] CWE-290 CVE-2024-10465: A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerabi A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
cvelistv5nvd
CVE-2024-10461MEDIUMCVSS 6.1fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10461 [MEDIUM] CWE-79 CVE-2024-10461: In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
cvelistv5nvd
Mozilla Firefox vulnerabilities | cvebase