cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 30 of 162
CVE-2014-1529P3HIGHCVSS 8.8fixed in 29.0≥ 24.0, < 24.52014-04-30
CVE-2014-1529 [HIGH] CWE-269 CVE-2014-1529: The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird b The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.
nvdosv
CVE-2023-5176P3CRITICALCVSS 9.8fixed in 118≥ unspecified, < 1182023-09-27
CVE-2023-5176 [CRITICAL] CWE-787 CVE-2023-5176: Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these b Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2021-29971P3CRITICALCVSS 9.8fixed in 90.0≥ unspecified, < 902021-08-05
CVE-2021-29971 [CRITICAL] CWE-281 CVE-2021-29971: If a user had granted a permission to a webpage and saved that grant, any webpage running on the sam If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 90.
nvd
CVE-2009-1571P3CRITICALCVSS 10.0v3.0v3.0.1+23 more2010-02-22
CVE-2009-1571 [CRITICAL] CWE-94 CVE-2009-1571: Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x bef Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.
nvd
CVE-2022-31737P3CRITICALCVSS 9.8fixed in 101≥ unspecified, < 1012022-12-22
CVE-2022-31737 [CRITICAL] CWE-787 CVE-2022-31737: A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2023-5172P3CRITICALCVSS 9.8fixed in 118≥ unspecified, < 1182023-09-27
CVE-2023-5172 [CRITICAL] CWE-416 CVE-2023-5172: A hashtable in the Ion Engine could have been mutated while there was a live interior reference, le A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.
nvdosv
CVE-2016-5259P3HIGHCVSS 8.8≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-5259 [HIGH] CWE-416 CVE-2016-5259: Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop.
nvd
CVE-2016-5252P3HIGHCVSS 8.8≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-5252 [HIGH] CWE-119 CVE-2016-5252: Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48. Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via crafted two-dimensional graphics data that is mishandled during clipping-region calculations.
nvd
CVE-2025-1020P3CRITICALCVSS 9.8fixed in 135.02025-02-04
CVE-2025-1020 [CRITICAL] CWE-787 CVE-2025-1020: Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2016-1973P3HIGHCVSS 8.8≤ 44.0.22016-03-13
CVE-2016-1973 [HIGH] CVE-2016-1973: Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox bef Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox before 45.0 might allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via unspecified vectors.
nvd
CVE-2014-1536P3CRITICALCVSS 10.0≤ 29.0.12014-06-11
CVE-2014-1536 [CRITICAL] CVE-2014-1536: The PropertyProvider::FindJustificationRange function in Mozilla Firefox before 30.0 allows remote a The PropertyProvider::FindJustificationRange function in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvdosv
CVE-2006-2894P4MEDIUMCVSS 4.0PoC≤ 2.0.0.8v1.5.0.42006-06-07
CVE-2006-2894 [MEDIUM] CWE-20 CVE-2006-2894: Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and oth Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javasc
nvd
CVE-2013-0767P3CRITICALCVSS 10.0fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0767 [CRITICAL] CWE-125 CVE-2013-0767: The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x b The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read)
nvd
CVE-2026-12327P3HIGHCVSS 7.3fixed in Firefox 152
CVE-2026-12327 [HIGH] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12327 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12327 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2007-4041P3MEDIUMCVSS 6.8v2.0.0.5v3.02007-07-27
CVE-2007-4041 [MEDIUM] CVE-2007-4041: Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote att Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.
nvd
CVE-2014-1528P3CRITICALCVSS 10.0v28.02014-04-30
CVE-2014-1528 [CRITICAL] CWE-119 CVE-2014-1528: The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and Se The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.
nvdosv
CVE-2019-11730P3MEDIUMCVSS 6.5fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11730 [MEDIUM] CVE-2019-11730: A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in comb
nvd
CVE-2019-17017P3HIGHCVSS 8.8fixed in 72.02020-01-08
CVE-2019-17017 [HIGH] CWE-843 CVE-2019-17017: Due to a missing case handling object types, a type confusion vulnerability could occur, resulting i Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2017-7798P3HIGHCVSS 8.8fixed in 55.0fixed in 52.3.0+1 more2018-06-11
CVE-2017-7798 [HIGH] CWE-94 CVE-2017-7798: The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.
nvd
CVE-2013-0755P3CRITICALCVSS 9.3fixed in 17.0.2fixed in 18.02013-01-13
CVE-2013-0755 [CRITICAL] CWE-416 CVE-2013-0755: Use-after-free vulnerability in the mozVibrate implementation in the Vibrate library in Mozilla Fire Use-after-free vulnerability in the mozVibrate implementation in the Vibrate library in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors related to the domDoc pointer.
nvd
Mozilla Firefox vulnerabilities | cvebase