cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 27 of 162
CVE-2011-0066P3CRITICALCVSS 10.0v3.6v3.6.2+101 more2011-05-07
CVE-2011-0066 [CRITICAL] CWE-399 CVE-2011-0066: Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.
nvd
CVE-2010-3167P3CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-3167 [CRITICAL] CWE-119 CVE-2010-3167: The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer v
nvd
CVE-2013-5604P3CRITICALCVSS 9.3v17.0v17.0.1+21 more2013-10-30
CVE-2013-5604 [CRITICAL] CWE-119 CVE-2013-5604: The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Fire The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of s
nvd
CVE-2011-0057P3CRITICALCVSS 10.0v3.6v3.6.2+96 more2011-03-02
CVE-2011-0057 [CRITICAL] CWE-399 CVE-2011-0057: Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to execute arbitrary code via vectors related to a JavaScript Worker and garbage collection.
nvd
CVE-2017-5448P3HIGHCVSS 8.6fixed in 45.9.0≥ 52.0, < 52.1.0+2 more2018-06-11
CVE-2017-5448 [HIGH] CWE-787 CVE-2017-5448: An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash.
nvd
CVE-2011-0054P3CRITICALCVSS 10.0v3.6v3.6.2+96 more2011-03-02
CVE-2011-0054 [CRITICAL] CWE-119 CVE-2011-0054: Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, a Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving non-local JavaScript variables, aka an "upvarMap" issue.
nvd
CVE-2011-0056P3CRITICALCVSS 10.0v3.6v3.6.2+96 more2011-03-02
CVE-2011-0056 [CRITICAL] CWE-119 CVE-2011-0056: Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, a Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving exception timing and a large number of string values, aka an "atom map" issue.
nvd
CVE-2018-18493P3CRITICALCVSS 9.8fixed in 60.4.0fixed in 64.0+1 more2019-02-28
CVE-2018-18493 [CRITICAL] CWE-119 CVE-2018-18493: A buffer overflow can occur in the Skia library during buffer offset calculations with hardware acce A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2023-6861P3HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6861 [HIGH] CWE-787 CVE-2023-6861: The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in he The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2022-1919P3HIGHCVSS 8.8≥ 0, < 101.0.1+build1-0ubuntu0.18.04.1≥ 0, < 101.0.1+build1-0ubuntu0.20.04.12022-06-01
CVE-2022-1919 [HIGH] CVE-2022-1919: Use after free in Codecs in Google Chrome prior to 101 Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
osv
CVE-2025-0242P3MEDIUMCVSS 6.5≤ 115.19.0fixed in 134.0+1 more2025-01-07
CVE-2025-0242 [MEDIUM] CWE-787 CVE-2025-0242: Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, T Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134, Firefox
nvd
CVE-2008-1235P3CRITICALCVSS 9.3≤ 2.0.0.12v0.1+46 more2008-03-27
CVE-2008-1235 [CRITICAL] CVE-2008-1235: Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMo Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via unknown vectors that cause JavaScript to execute with the wrong principal, aka "Privilege escalation via incorrect principals."
nvd
CVE-2020-6822P3HIGHCVSS 8.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6822 [HIGH] CWE-787 CVE-2020-6822: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvd
CVE-2024-10004P3CRITICALCVSS 9.1fixed in 131.2.02024-10-15
CVE-2024-10004 [CRITICAL] CWE-1021 CVE-2024-10004: Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
nvd
CVE-2024-0750P3HIGHCVSS 8.8fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0750 [HIGH] CWE-451 CVE-2024-0750: A bug in popup notifications delay calculation could have made it possible for an attacker to trick A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2014-1568P3HIGHCVSS 7.5≤ 32.0v31.0+3 more2014-09-25
CVE-2014-1568 [HIGH] CWE-310 CVE-2014-1568: Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.1 Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X
nvd
CVE-2023-4584P3HIGHCVSS 8.8fixed in 117.0≥ 115.0, < 115.2+1 more2023-09-11
CVE-2023-4584 [HIGH] CWE-787 CVE-2023-4584: Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14 Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox
nvd
CVE-2023-6207P3HIGHCVSS 8.8fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6207 [HIGH] CWE-416 CVE-2023-6207: Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Fi Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2023-6208P3HIGHCVSS 8.8fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6208 [HIGH] CVE-2023-6208: When using X11, text selected by the page using the Selection API was erroneously copied into the pr When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2023-4582P3HIGHCVSS 8.8fixed in 117.0≥ unspecified, < 1172023-09-11
CVE-2023-4582 [HIGH] CWE-120 CVE-2023-4582: Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could h Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd