cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 2 of 162
CVE-2022-1802P1HIGHCVSS 8.8ExploitedPoCfixed in 100.0.2fixed in 100.3.0+1 more2022-12-22
CVE-2022-1802 [HIGH] CWE-1321 CVE-2022-1802: If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollut If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
nvd
CVE-2013-1710P2CRITICALCVSS 10.0ExploitedPoC≤ 22.0v19.0+13 more2013-08-07
CVE-2013-1710 [CRITICAL] CWE-20 CVE-2013-1710: The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0 The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message F
nvd
CVE-2022-28281P2HIGHCVSS 8.8ExploitedPoCfixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28281 [HIGH] CWE-787 CVE-2022-28281: If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register comm If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvd
CVE-2009-2477P2CRITICALCVSS 9.3ExploitedPoCv3.52009-07-15
CVE-2009-2477 [CRITICAL] CWE-94 CVE-2009-2477: js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firef js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.
nvd
CVE-2013-1670P2MEDIUMCVSS 4.3ExploitedPoC≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1670 [MEDIUM] CWE-79 CVE-2013-1670: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x befo The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct
nvd
CVE-2025-2857P1CRITICALCVSS 10.0Exploitedfixed in 136.0.4fixed in 115.21.1+1 more2025-03-27
CVE-2025-2857 [CRITICAL] CVE-2025-2857: Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Win
nvd
CVE-2022-1529P2HIGHCVSS 8.8Exploitedfixed in 100.0.2fixed in 100.3.0+1 more2022-12-22
CVE-2022-1529 [HIGH] CWE-1321 CVE-2022-1529: An attacker could have sent a message to the parent process where the contents were used to double-i An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and
nvd
CVE-2020-15654P2MEDIUMCVSS 6.5Exploitedfixed in 79.0≥ unspecified, < 792020-08-10
CVE-2020-15654 [MEDIUM] CWE-835 CVE-2020-15654: When in an endless loop, a website specifying a custom cursor using CSS could make it look like the When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived broken state, especially when interactions with existing browser dialogs and warnings do not work. This vulnerability affects Firefox ESR < 78.1, Firefox < 7
nvdosv
CVE-2022-34478P2MEDIUMCVSS 6.5Exploitedfixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34478 [MEDIUM] CWE-601 CVE-2022-34478: The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the us
nvd
CVE-2019-11695P2MEDIUMCVSS 4.3Exploitedfixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11695 [MEDIUM] CVE-2019-11695: A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts, doorhanger notifications, or other buttons inadvertently if the location is spoofed
nvdosv
CVE-2022-1097P2MEDIUMCVSS 6.5Exploitedfixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-1097 [MEDIUM] CWE-416 CVE-2022-1097: <code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an NSSToken objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvdosv
CVE-2019-9806P2HIGHCVSS 7.5Exploitedfixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9806 [HIGH] CWE-399 CVE-2019-9806: A vulnerability exists during authorization prompting for FTP transaction where successive modal pro A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) attack. This vulnerability affects Firefox < 66.
nvdosv
CVE-2021-23957P2HIGHCVSS 7.4Exploitedfixed in 85.0fixed in 852021-02-26
CVE-2021-23957 [HIGH] CVE-2021-23957: Navigations through the Android-specific `intent` URL scheme could have been misused to escape ifram Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
nvd
CVE-2009-1308P2MEDIUMCVSS 4.3Exploited≤ 3.0.8v0.1+86 more2009-04-22
CVE-2009-1308 [MEDIUM] CWE-79 CVE-2009-1308: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.
nvd
CVE-2024-4367P2HIGHCVSS 8.8PoCfixed in 115.11.0fixed in 126.02024-05-14
CVE-2024-4367 [HIGH] CWE-754 CVE-2024-4367: A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execu A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2013-0758P2CRITICALCVSS 9.3PoCfixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0758 [CRITICAL] CWE-94 CVE-2013-0758: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging improper interaction between plugin objects and SVG eleme
nvd
CVE-2011-2371P2CRITICALCVSS 10.0PoC≤ 3.6.17v1.0+105 more2011-06-30
CVE-2011-2371 [CRITICAL] CWE-189 CVE-2011-2371: Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4. Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.
nvd
CVE-2011-0065P2CRITICALCVSS 10.0PoCv3.6v3.6.2+101 more2011-05-07
CVE-2011-0065 [CRITICAL] CWE-399 CVE-2011-0065: Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.
nvd
CVE-2010-1205P2CRITICALCVSS 9.8PoCfixed in 3.5.11≥ 3.5.12, < 3.6.72010-06-30
CVE-2010-1205 [CRITICAL] CWE-120 CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
nvd
CVE-2011-0073P2CRITICALCVSS 10.0PoCv3.6v3.6.2+101 more2011-05-07
CVE-2011-0073 [CRITICAL] CWE-20 CVE-2011-0073: Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properl Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
nvd
Mozilla Firefox vulnerabilities | cvebase