Mozilla Firefox vulnerabilities
3,029 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,029
CISA KEV
15
actively exploited
Public exploits
121
Exploited in wild
20
Severity breakdown
CRITICAL853HIGH879MEDIUM1228LOW69
Vulnerabilities
Page 26 of 152
CVE-2024-0748MEDIUMCVSS 4.3fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0748 [MEDIUM] CVE-2024-0748: A compromised content process could have updated the document URI. This could have allowed an attack
A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.
cvelistv5nvdosv
CVE-2023-6866HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6866 [HIGH] CWE-755 CVE-2023-6866: TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other
TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. This vulnerability affects Firefox < 121.
cvelistv5nvdosv
CVE-2023-6864HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6864 [HIGH] CWE-787 CVE-2023-6864: Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these b
Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
cvelistv5nvd
CVE-2023-6858HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6858 [HIGH] CWE-787 CVE-2023-6858: Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handli
Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
cvelistv5nvd
CVE-2023-6873HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6873 [HIGH] CWE-787 CVE-2023-6873: Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
cvelistv5nvd
CVE-2023-6863HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6863 [HIGH] CVE-2023-6863: The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
cvelistv5nvd
CVE-2023-6856HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6856 [HIGH] CWE-787 CVE-2023-6856: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on syst
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
cvelistv5nvd
CVE-2023-6861HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6861 [HIGH] CWE-787 CVE-2023-6861: The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in he
The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
cvelistv5nvd
CVE-2023-6859HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6859 [HIGH] CWE-416 CVE-2023-6859: A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerabili
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
cvelistv5nvd
CVE-2023-6870MEDIUMCVSS 4.3fixed in 121.0≥ unspecified, < 1302023-12-19
CVE-2023-6870 [MEDIUM] CVE-2023-6870: Applications which spawn a Toast notification in a background thread may have obscured fullscreen no
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox.
*This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.
cvelistv5nvd
CVE-2023-6857MEDIUMCVSS 5.3fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6857 [MEDIUM] CWE-362 CVE-2023-6857: When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be sma
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary.
*This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
cvelistv5nvd
CVE-2023-6867MEDIUMCVSS 6.1fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6867 [MEDIUM] CWE-1021 CVE-2023-6867: The timing of a button click causing a popup to disappear was approximately the same length as the a
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
cvelistv5nvd
CVE-2023-6869MEDIUMCVSS 6.5fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6869 [MEDIUM] CVE-2023-6869: A `<dialog>` element could have been manipulated to paint content outside of a sandboxed iframe.
A ` ` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.
cvelistv5nvdosv
CVE-2023-6872MEDIUMCVSS 6.5fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6872 [MEDIUM] CVE-2023-6872: Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the brow
Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the browsing habits of users running in a private tab. This vulnerability affects Firefox < 121.
cvelistv5nvdosv
CVE-2023-6868MEDIUMCVSS 4.3fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6868 [MEDIUM] CVE-2023-6868: In some instances, the user-agent would allow push requests which lacked a valid VAPID even though t
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties.
*This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.
cvelistv5nvd
CVE-2023-6865MEDIUMCVSS 6.5fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6865 [MEDIUM] CVE-2023-6865: `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be a
`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
cvelistv5nvdosv
CVE-2023-6860MEDIUMCVSS 6.5fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6860 [MEDIUM] CVE-2023-6860: The `VideoBridge` allowed any content process to use textures produced by remote decoders. This cou
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
cvelistv5nvd
CVE-2023-6135MEDIUMCVSS 4.3fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6135 [MEDIUM] CWE-203 CVE-2023-6135: Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack c
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
cvelistv5nvd
CVE-2023-6871MEDIUMCVSS 4.3fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6871 [MEDIUM] CVE-2023-6871: Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a n
Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121.
cvelistv5nvdosv
CVE-2023-49060CRITICALCVSS 9.8fixed in 120.02023-11-21
CVE-2023-49060 [CRITICAL] CVE-2023-49060: An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMo
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
nvd