Mozilla Firefox vulnerabilities

3,148 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70

Vulnerabilities

Page 32 of 158
CVE-2023-28177HIGHCVSS 8.8fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28177 [HIGH] CWE-787 CVE-2023-28177: Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111.
nvdosvmozilla
CVE-2023-23606HIGHCVSS 8.8fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23606 [HIGH] CWE-787 CVE-2023-23606: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109.
nvdosvmozilla
CVE-2023-29537HIGHCVSS 7.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29537 [HIGH] CWE-362 CVE-2023-29537: Multiple race conditions in the font initialization could have led to memory corruption and executio Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosvmozilla
CVE-2023-32207HIGHCVSS 8.8fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32207 [HIGH] CWE-290 CVE-2023-32207: A missing delay in popup notifications could have made it possible for an attacker to trick a user i A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvdmozilla
CVE-2023-29539HIGHCVSS 8.8fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29539 [HIGH] CWE-476 CVE-2023-29539: When handling the filename directive in the Content-Disposition header, the filename would be trunca When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for An
nvdmozilla
CVE-2023-25735HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25735 [HIGH] CWE-416 CVE-2023-25735: Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartmen Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdmozilla
CVE-2023-25729HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25729 [HIGH] CWE-863 CVE-2023-25729: Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> r Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox <
nvdmozilla
CVE-2023-25740HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25740 [HIGH] CWE-522 CVE-2023-25740: After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could su After downloading a Windows .scf script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability
nvdmozilla
CVE-2023-0767HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-0767 [HIGH] CVE-2023-0767: An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memor An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdosvmozilla
CVE-2023-25744HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25744 [HIGH] CWE-787 CVE-2023-25744: Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
nvdmozilla
CVE-2023-23605HIGHCVSS 8.8fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23605 [HIGH] CWE-787 CVE-2023-23605: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 a Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunde
nvdmozilla
CVE-2023-28176HIGHCVSS 8.8fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28176 [HIGH] CWE-787 CVE-2023-28176: Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvdmozilla
CVE-2023-25745HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25745 [HIGH] CWE-787 CVE-2023-25745: Memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110.
nvdosvmozilla
CVE-2023-29541HIGHCVSS 8.8fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29541 [HIGH] CWE-116 CVE-2023-29541: Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be int Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112,
nvdmozilla
CVE-2023-25734HIGHCVSS 8.1fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25734 [HIGH] CWE-601 CVE-2023-25734: After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability
nvdmozilla
CVE-2023-29551HIGHCVSS 8.8fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29551 [HIGH] CWE-787 CVE-2023-29551: Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosvmozilla
CVE-2023-29536HIGHCVSS 8.8fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29536 [HIGH] CWE-416 CVE-2023-29536: An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-con An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvdmozilla
CVE-2023-32215HIGHCVSS 8.8fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32215 [HIGH] CWE-787 CVE-2023-32215: Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112 and Firefox ESR 102.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been
nvdmozilla
CVE-2023-25739HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25739 [HIGH] CWE-416 CVE-2023-25739: Module load requests that failed were not being checked as to whether or not they were cancelled cau Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in ScriptLoadContext. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdmozilla
CVE-2023-25737HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25737 [HIGH] CWE-704 CVE-2023-25737: An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undef An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdmozilla