cbcvebase.

Mozilla Firefox vulnerabilities

3,257 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,257
CISA KEV
17
actively exploited
Public exploits
123
Exploited in wild
22
Severity breakdown
CRITICAL875HIGH985MEDIUM1325LOW72

Vulnerabilities

Page 25 of 163
CVE-2024-8388MEDIUMCVSS 5.3fixed in 130.02024-09-03
CVE-2024-8388 [MEDIUM] CVE-2024-8388: Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notifi Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser UI if the sudden appearance of the prompt distracted the user from noticing the visual transition happening behind the pr
nvdmozilla
CVE-2024-7519CRITICALCVSS 9.6fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7519 [CRITICAL] CWE-787 CVE-2024-7519: Insufficient checks when processing graphics shared memory could have led to memory corruption. This Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdmozilla
CVE-2024-7527HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7527 [HIGH] CWE-416 CVE-2024-7527: Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerabil Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdmozilla
CVE-2024-7522HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7522 [HIGH] CWE-125 CVE-2024-7522: Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This v Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdmozilla
CVE-2024-7521HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7521 [HIGH] CWE-755 CVE-2024-7521: Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affe Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdmozilla
CVE-2024-7525HIGHCVSS 8.1fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7525 [HIGH] CWE-276 CVE-2024-7525: It was possible for a web extension with minimal permissions to create a `StreamFilter` which could It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdmozilla
CVE-2024-7523HIGHCVSS 8.1fixed in 129≥ unspecified, < 1292024-08-06
CVE-2024-7523 [HIGH] CWE-1021 CVE-2024-7523: A select option could partially obscure security prompts. This could be used by a malicious site to A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.
nvdosvmozilla
CVE-2024-7520HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7520 [HIGH] CWE-843 CVE-2024-7520: A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code ex A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvdosvmozilla
CVE-2024-7528HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7528 [HIGH] CWE-416 CVE-2024-7528: Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulne Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvdosvmozilla
CVE-2024-7530HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7530 [HIGH] CWE-416 CVE-2024-7530: Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affe Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
nvdosvmozilla
CVE-2024-43112MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43112 [MEDIUM] CWE-79 CVE-2024-43112: Long pressing on a download link could potentially provide a means for cross-site scripting This vul Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.
nvdmozilla
CVE-2024-7524MEDIUMCVSS 6.1fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7524 [MEDIUM] CWE-79 CVE-2024-7524: Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. Thi
nvdmozilla
CVE-2024-7529MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7529 [MEDIUM] CWE-451 CVE-2024-7529: The date picker could partially obscure security prompts. This could be used by a malicious site to The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdmozilla
CVE-2024-7526MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7526 [MEDIUM] CWE-908 CVE-2024-7526: ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvdmozilla
CVE-2024-43111MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43111 [MEDIUM] CWE-79 CVE-2024-43111: Long pressing on a download link could potentially allow Javascript commands to be executed within t Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
nvdmozilla
CVE-2024-7531MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7531 [MEDIUM] CWE-367 CVE-2024-7531: Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can resu Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection per
nvdmozilla
CVE-2024-7518MEDIUMCVSS 6.5fixed in 129≥ unspecified, < 1292024-08-06
CVE-2024-7518 [MEDIUM] CWE-1021 CVE-2024-7518: Select options could obscure the fullscreen notification dialog. This could be used by a malicious s Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvdosvmozilla
CVE-2024-43113MEDIUMCVSS 6.1fixed in 1292024-08-06
CVE-2024-43113 [MEDIUM] CWE-79 CVE-2024-43113: The contextual menu for links could provide an opportunity for cross-site scripting attacks This vul The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.
nvdmozilla
CVE-2024-6602CRITICALCVSS 9.8fixed in 115.13fixed in 128.0+1 more2024-07-09
CVE-2024-6602 [CRITICAL] CWE-94 CVE-2024-6602: A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdmozilla
CVE-2024-6611CRITICALCVSS 9.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6611 [CRITICAL] CWE-1275 CVE-2024-6611: A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla