Mozilla Firefox vulnerabilities

3,029 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,029
CISA KEV
15
actively exploited
Public exploits
121
Exploited in wild
20
Severity breakdown
CRITICAL853HIGH879MEDIUM1228LOW69

Vulnerabilities

Page 20 of 152
CVE-2024-7525HIGHCVSS 8.1fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7525 [HIGH] CWE-276 CVE-2024-7525: It was possible for a web extension with minimal permissions to create a `StreamFilter` which could It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-43112MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43112 [MEDIUM] CWE-79 CVE-2024-43112: Long pressing on a download link could potentially provide a means for cross-site scripting This vul Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2024-7531MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7531 [MEDIUM] CWE-367 CVE-2024-7531: Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can resu Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection per
cvelistv5nvd
CVE-2024-7518MEDIUMCVSS 6.5fixed in 129≥ unspecified, < 1292024-08-06
CVE-2024-7518 [MEDIUM] CWE-1021 CVE-2024-7518: Select options could obscure the fullscreen notification dialog. This could be used by a malicious s Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
cvelistv5nvdosv
CVE-2024-7526MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7526 [MEDIUM] CWE-908 CVE-2024-7526: ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7529MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7529 [MEDIUM] CWE-451 CVE-2024-7529: The date picker could partially obscure security prompts. This could be used by a malicious site to The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7524MEDIUMCVSS 6.1fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7524 [MEDIUM] CWE-79 CVE-2024-7524: Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. Thi
cvelistv5nvd
CVE-2024-43111MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43111 [MEDIUM] CWE-79 CVE-2024-43111: Long pressing on a download link could potentially allow Javascript commands to be executed within t Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2024-43113MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43113 [MEDIUM] CWE-79 CVE-2024-43113: The contextual menu for links could provide an opportunity for cross-site scripting attacks This vul The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
nvd
CVE-2024-6602CRITICALCVSS 9.8fixed in 115.13fixed in 128.0+1 more2024-07-09
CVE-2024-6602 [CRITICAL] CWE-94 CVE-2024-6602: A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6611CRITICALCVSS 9.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6611 [CRITICAL] CWE-1275 CVE-2024-6611: A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6606HIGHCVSS 8.2fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6606 [HIGH] CWE-125 CVE-2024-6606: Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6609HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6609 [HIGH] CVE-2024-6609: When almost out-of-memory an elliptic curve key which was never allocated could have been freed agai When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6615HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6615 [HIGH] CWE-787 CVE-2024-6615: Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6605HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6605 [HIGH] CWE-277 CVE-2024-6605: Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjac Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
cvelistv5nvd
CVE-2024-6607HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6607 [HIGH] CWE-763 CVE-2024-6607: It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay custo It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a ` ` element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6603HIGHCVSS 7.4fixed in 115.13fixed in 128.0+1 more2024-07-09
CVE-2024-6603 [HIGH] CWE-823 CVE-2024-6603: In an out-of-memory scenario an allocation could fail but free would have been called on the pointer In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6604HIGHCVSS 7.5fixed in 115.13fixed in 126.0+1 more2024-07-09
CVE-2024-6604 [HIGH] CWE-120 CVE-2024-6604: Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6601MEDIUMCVSS 4.7fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6601 [MEDIUM] CWE-367 CVE-2024-6601: A race condition could lead to a cross-origin container obtaining permissions of the top-level origi A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6610MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6610 [MEDIUM] CWE-451 CVE-2024-6610: Form validation popups could capture escape key presses. Therefore, spamming form validation message Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv