Mozilla Firefox vulnerabilities

3,029 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,029
CISA KEV
15
actively exploited
Public exploits
121
Exploited in wild
20
Severity breakdown
CRITICAL853HIGH879MEDIUM1228LOW69

Vulnerabilities

Page 21 of 152
CVE-2024-6613MEDIUMCVSS 5.5fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6613 [MEDIUM] CWE-209 CVE-2024-6613: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6608MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6608 [MEDIUM] CVE-2024-6608: It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6614MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6614 [MEDIUM] CWE-835 CVE-2024-6614: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-6600MEDIUMCVSS 6.3fixed in 115.13fixed in 128.0+1 more2024-07-09
CVE-2024-6600 [MEDIUM] CWE-770 CVE-2024-6600: Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access c Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6612MEDIUMCVSS 5.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6612 [MEDIUM] CWE-200 CVE-2024-6612: CSP violations generated links in the console tab of the developer tools, pointing to the violating CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.
cvelistv5nvdosv
CVE-2024-38313MEDIUMCVSS 4.3fixed in 127.02024-06-13
CVE-2024-38313 [MEDIUM] CWE-451 CVE-2024-38313: In certain scenarios a malicious website could attempt to display a fake location URL bar which coul In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.
nvd
CVE-2024-38312MEDIUMCVSS 6.5fixed in 127.02024-06-13
CVE-2024-38312 [MEDIUM] CWE-922 CVE-2024-38312: When browsing private tabs, some data related to location history or webpage thumbnails could be per When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.
nvd
CVE-2024-5701CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5701 [CRITICAL] CWE-787 CVE-2024-5701: Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.
cvelistv5nvdosv
CVE-2024-5695CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5695 [CRITICAL] CWE-787 CVE-2024-5695: If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
cvelistv5nvdosv
CVE-2024-5699CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5699 [CRITICAL] CWE-178 CVE-2024-5699: In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correct In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.
cvelistv5nvdosv
CVE-2024-5696HIGHCVSS 8.6fixed in 115.12fixed in 127.0+1 more2024-06-11
CVE-2024-5696 [HIGH] CWE-787 CVE-2024-5696: By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory lea By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd
CVE-2024-5702HIGHCVSS 7.5fixed in 115.12fixed in 125.0+1 more2024-06-11
CVE-2024-5702 [HIGH] CWE-416 CVE-2024-5702: Memory corruption in the networking stack could have led to a potentially exploitable crash. This vu Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd
CVE-2024-5694HIGHCVSS 7.5fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5694 [HIGH] CWE-416 CVE-2024-5694: An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaSc An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.
cvelistv5nvdosv
CVE-2024-5688HIGHCVSS 8.1fixed in 115.12fixed in 127.0+1 more2024-06-11
CVE-2024-5688 [HIGH] CWE-416 CVE-2024-5688: If a garbage collection was triggered at the right time, a use-after-free could have occurred during If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd
CVE-2024-5700HIGHCVSS 7.0fixed in 115.12fixed in 127.0+1 more2024-06-11
CVE-2024-5700 [HIGH] CWE-786 CVE-2024-5700: Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd
CVE-2024-5687MEDIUMCVSS 5.3fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5687 [MEDIUM] CWE-284 CVE-2024-5687: If a specific sequence of actions is performed when opening a new tab, the triggering principal asso If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incor
cvelistv5nvd
CVE-2024-5693MEDIUMCVSS 6.1fixed in 115.12fixed in 127.0+1 more2024-06-11
CVE-2024-5693 [MEDIUM] CWE-829 CVE-2024-5693: Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image d Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd
CVE-2024-5698MEDIUMCVSS 6.1fixed in 127≥ unspecified, < 1272024-06-11
CVE-2024-5698 [MEDIUM] CWE-1021 CVE-2024-5698: By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.
cvelistv5nvdosv
CVE-2024-5690MEDIUMCVSS 4.3fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5690 [MEDIUM] CWE-203 CVE-2024-5690: By monitoring the time certain operations take, an attacker could have guessed which external protoc By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd
CVE-2024-5689MEDIUMCVSS 4.3fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5689 [MEDIUM] CVE-2024-5689: In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay th In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.
cvelistv5nvdosv