Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 3 of 162
CVE-2013-0753P2CRITICALCVSS 9.3PoCfixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0753 [CRITICAL] CWE-416 CVE-2013-0753: Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code v
nvd
CVE-2013-0757P2CRITICALCVSS 9.3PoCfixed in 17.0.2fixed in 18.02013-01-13
CVE-2013-0757 [CRITICAL] CWE-20 CVE-2013-0757: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x befo
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not prevent modifications to the prototype of an object, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges
nvd
CVE-2020-26950P2HIGHCVSS 8.8PoCfixed in 82.0.32020-12-09
CVE-2020-26950 [HIGH] CWE-416 CVE-2020-26950: In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resultin
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.
nvd
CVE-2017-5715P2MEDIUMCVSS 5.6PoC≥ 0, < 57.0.4+build1-0ubuntu0.14.04.1≥ 0, < 57.0.4+build1-0ubuntu0.16.04.12018-01-05
CVE-2017-5715 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5715,
CVE-2017-5753, C
osv
CVE-2013-2566P2MEDIUMCVSS 5.9PoCfixed in 17.0.11fixed in 25.0.1+1 more2013-03-15
CVE-2013-2566 [MEDIUM] CWE-326 CVE-2013-2566: The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
nvd
CVE-2011-3659P2CRITICALCVSS 9.3PoCfixed in 3.6.26≥ 4.0, < 10.02012-02-01
CVE-2011-3659 [CRITICAL] CWE-416 CVE-2011-3659: Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird befor
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
nvd
CVE-2008-0016P2CRITICALCVSS 10.0PoC≤ 2.0.0.16v0.8+46 more2008-09-24
CVE-2008-0016 [CRITICAL] CWE-119 CVE-2008-0016: Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and
Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.
nvd
CVE-2012-3993P2CRITICALCVSS 9.3PoCv10.0v10.0.1+138 more2012-10-10
CVE-2012-3993 [CRITICAL] CWE-269 CVE-2012-3993: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x befo
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary JavaScript code with chrome privil
nvd
CVE-2017-5375P2CRITICALCVSS 9.8PoCfixed in 45.7.0fixed in 51.0.1+1 more2018-06-11
CVE-2017-5375 [CRITICAL] CWE-119 CVE-2017-5375: JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory c
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2019-9791P2CRITICALCVSS 9.8PoCfixed in 60.6.0fixed in 66.0+1 more2019-04-26
CVE-2019-9791 [CRITICAL] CWE-843 CVE-2019-9791: The type inference system allows the compilation of functions that can cause type confusions between
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable
nvd
CVE-2011-3658P3HIGHCVSS 7.5PoCv8.02011-12-21
CVE-2011-3658 [HIGH] CWE-399 CVE-2011-3658: The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
nvd
CVE-2016-2819P2HIGHCVSS 8.8PoCv45.1.0v45.1.1+1 more2016-06-13
CVE-2016-2819 [HIGH] CWE-119 CVE-2016-2819: Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows re
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.
nvd
CVE-2016-9899P2CRITICALCVSS 9.8PoC≥ 52.0, < 52.1.0fixed in 53.0+2 more2018-06-11
CVE-2016-9899 [CRITICAL] CWE-416 CVE-2016-9899: Use-after-free while manipulating DOM events and removing audio elements due to errors in the handli
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2018-5159P2CRITICALCVSS 9.8PoCfixed in 52.8.0fixed in 60.0+1 more2018-06-11
CVE-2018-5159 [CRITICAL] CWE-190 CVE-2018-5159: An integer overflow can occur in the Skia library due to 32-bit integer use in an array without inte
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8
nvd
CVE-2015-4000P3LOWCVSS 3.7PoCv38.1.0v39.02015-05-21
CVE-2015-4000 [LOW] CWE-310 CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, a
nvd
CVE-2016-1960P2HIGHCVSS 8.8PoC≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1960 [HIGH] CVE-2016-1960: Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox befo
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
nvd
CVE-2017-5447P2CRITICALCVSS 9.1PoCfixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5447 [CRITICAL] CWE-416 CVE-2017-5447: An out-of-bounds read during the processing of glyph widths during text layout. This results in a po
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2015-0816P3MEDIUMCVSS 5.0PoC≤ 31.5.3≤ 36.0.42015-04-01
CVE-2015-0816 [MEDIUM] CWE-264 CVE-2015-0816: Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not proper
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
nvdosv
CVE-2017-5404P2CRITICALCVSS 9.8PoCfixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5404 [CRITICAL] CWE-416 CVE-2017-5404: A use-after-free error can occur when manipulating ranges in selections with one node inside a nativ
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5465P2CRITICALCVSS 9.1PoCfixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5465 [CRITICAL] CWE-125 CVE-2017-5465: An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and a
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd