Mozilla Firefox vulnerabilities
3,257 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,257
CISA KEV
17
actively exploited
Public exploits
123
Exploited in wild
22
Severity breakdown
CRITICAL875HIGH985MEDIUM1325LOW72
Vulnerabilities
Page 26 of 163
CVE-2024-6606HIGHCVSS 8.2fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6606 [HIGH] CWE-125 CVE-2024-6606: Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla
CVE-2024-6609HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6609 [HIGH] CVE-2024-6609: When almost out-of-memory an elliptic curve key which was never allocated could have been freed agai
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdmozilla
CVE-2024-6603HIGHCVSS 7.4fixed in 115.13fixed in 128.0+1 more2024-07-09
CVE-2024-6603 [HIGH] CWE-823 CVE-2024-6603: In an out-of-memory scenario an allocation could fail but free would have been called on the pointer
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdmozilla
CVE-2024-6615HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6615 [HIGH] CWE-787 CVE-2024-6615: Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla
CVE-2024-6607HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6607 [HIGH] CWE-763 CVE-2024-6607: It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay custo
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a ` ` element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla
CVE-2024-6604HIGHCVSS 7.5fixed in 115.13fixed in 126.0+1 more2024-07-09
CVE-2024-6604 [HIGH] CWE-120 CVE-2024-6604: Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdmozilla
CVE-2024-6605HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6605 [HIGH] CWE-277 CVE-2024-6605: Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjac
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
nvdmozilla
CVE-2024-6601MEDIUMCVSS 4.7fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6601 [MEDIUM] CWE-367 CVE-2024-6601: A race condition could lead to a cross-origin container obtaining permissions of the top-level origi
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdosvmozilla
CVE-2024-6610MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6610 [MEDIUM] CWE-451 CVE-2024-6610: Form validation popups could capture escape key presses. Therefore, spamming form validation message
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla
CVE-2024-6614MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6614 [MEDIUM] CWE-835 CVE-2024-6614: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla
CVE-2024-6600MEDIUMCVSS 6.3fixed in 115.13fixed in 128.0+1 more2024-07-09
CVE-2024-6600 [MEDIUM] CWE-770 CVE-2024-6600: Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access c
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvdmozilla
CVE-2024-6608MEDIUMCVSS 4.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6608 [MEDIUM] CVE-2024-6608: It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla
CVE-2024-6612MEDIUMCVSS 5.3fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6612 [MEDIUM] CWE-200 CVE-2024-6612: CSP violations generated links in the console tab of the developer tools, pointing to the violating
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla
CVE-2024-6613MEDIUMCVSS 5.5fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6613 [MEDIUM] CWE-209 CVE-2024-6613: The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorr
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosvmozilla
CVE-2024-38313MEDIUMCVSS 4.3fixed in 127.02024-06-13
CVE-2024-38313 [MEDIUM] CWE-451 CVE-2024-38313: In certain scenarios a malicious website could attempt to display a fake location URL bar which coul
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.
nvdmozilla
CVE-2024-38312MEDIUMCVSS 6.5fixed in 127.02024-06-13
CVE-2024-38312 [MEDIUM] CWE-922 CVE-2024-38312: When browsing private tabs, some data related to location history or webpage thumbnails could be per
When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.
nvdmozilla
CVE-2024-5695CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5695 [CRITICAL] CWE-787 CVE-2024-5695: If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
nvdosvmozilla
CVE-2024-5701CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5701 [CRITICAL] CWE-787 CVE-2024-5701: Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.
nvdosvmozilla
CVE-2024-5699CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5699 [CRITICAL] CWE-178 CVE-2024-5699: In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correct
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.
nvdosvmozilla
CVE-2024-5694HIGHCVSS 7.5fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5694 [HIGH] CWE-416 CVE-2024-5694: An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaSc
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.
nvdosvmozilla