cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 26 of 162
CVE-2024-6611P3CRITICALCVSS 9.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6611 [CRITICAL] CWE-1275 CVE-2024-6611: A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosv
CVE-2024-9393P3HIGHCVSS 7.5fixed in 131.0≥ unspecified, < 1312024-10-01
CVE-2024-9393 [HIGH] CWE-346 CVE-2024-9393: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under th An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vu
nvd
CVE-2023-49060P3CRITICALCVSS 9.8fixed in 120.02023-11-21
CVE-2023-49060 [CRITICAL] CVE-2023-49060: An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMo An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
nvd
CVE-2016-5275P3HIGHCVSS 8.8≤ 48.0.22016-09-22
CVE-2016-5275 [HIGH] CWE-119 CVE-2016-5275: Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla F Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering.
nvdosv
CVE-2024-9402P3CRITICALCVSS 9.8fixed in 128.3.0fixed in 131.0+1 more2024-10-01
CVE-2024-9402 [CRITICAL] CWE-119 CVE-2024-9402: Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these b Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2024-8387P3CRITICALCVSS 9.8v129.0≥ unspecified, < 1302024-09-03
CVE-2024-8387 [CRITICAL] CWE-787 CVE-2024-8387: Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these b Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvd
CVE-2018-12368P3HIGHCVSS 8.1fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-12368 [HIGH] CVE-2018-12368: Windows 10 does not warn users before opening executable files with the SettingContent-ms extension Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable. This also allows a WebExtension with the limited downloads.open per
nvd
CVE-2024-5695P3CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5695 [CRITICAL] CWE-787 CVE-2024-5695: If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
nvdosv
CVE-2025-8044P3CRITICALCVSS 9.8fixed in 141.02025-07-22
CVE-2025-8044 [CRITICAL] CWE-119 CVE-2025-8044: Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141 and Thunderbird 141.
nvd
CVE-2026-2805P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2805 [CRITICAL] CWE-824 CVE-2026-2805: Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and T Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2026-2800P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2800 [CRITICAL] CWE-290 CVE-2026-2800: Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Fir Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2015-2731P3CRITICALCVSS 10.0≤ 38.1.0v31.0+7 more2015-07-06
CVE-2015-2731 [CRITICAL] CVE-2015-2731: Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.
nvdosv
CVE-2010-1121P3CRITICALCVSS 10.0v3.6v3.6.1+1 more2010-03-25
CVE-2010-1121 [CRITICAL] CWE-94 CVE-2010-1121: Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved f Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition
nvd
CVE-2025-6433P3CRITICALCVSS 9.8fixed in 140.02025-06-24
CVE-2025-6433 [CRITICAL] CWE-295 CVE-2025-6433: If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage w If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird
nvd
CVE-2025-8038P3CRITICALCVSS 9.8fixed in 140.1.0fixed in 141.02025-07-22
CVE-2025-8038 [CRITICAL] CWE-345 CVE-2025-8038: Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability w Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvd
CVE-2026-8959P3CRITICALCVSS 9.6fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8959 [CRITICAL] CWE-20 CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerabili Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2009-2654P4MEDIUMCVSS 5.8PoC≤ 3.5.1v0.1+94 more2009-08-03
CVE-2009-2654 [MEDIUM] CWE-20 CVE-2009-2654: Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.
nvd
CVE-2016-9063P3CRITICALCVSS 9.8fixed in 50≥ unspecified, < 502018-06-11
CVE-2016-9063 [CRITICAL] CWE-190 CVE-2016-9063: An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Fi An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
nvd
CVE-2012-3966P3CRITICALCVSS 10.0v10.0v10.0.1+133 more2012-08-29
CVE-2012-3966 [CRITICAL] CWE-119 CVE-2012-3966: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ES Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a negative height value in a BMP image within a .ICO file, related to (1) improper handling of the tr
nvd
CVE-2019-11759P3HIGHCVSS 8.8fixed in 70.0vbefore 702020-01-08
CVE-2019-11759 [HIGH] CWE-120 CVE-2019-11759: An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored o An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
Mozilla Firefox vulnerabilities | cvebase