Mozilla Firefox vulnerabilities

3,148 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70

Vulnerabilities

Page 34 of 158
CVE-2023-25741MEDIUMCVSS 6.5fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25741 [MEDIUM] CWE-203 CVE-2023-25741: When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.
nvdosvmozilla
CVE-2023-29533MEDIUMCVSS 4.3fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29533 [MEDIUM] CVE-2023-29533: A website could have obscured the fullscreen notification by using a combination of <code>window.ope A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thun
nvdmozilla
CVE-2023-25730MEDIUMCVSS 5.4fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25730 [MEDIUM] CWE-1021 CVE-2023-25730: A background script invoking <code>requestFullscreen</code> and then blocking the main thread could A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdmozilla
CVE-2023-29547MEDIUMCVSS 6.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29547 [MEDIUM] CVE-2023-29547: When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosvmozilla
CVE-2023-23601MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23601 [MEDIUM] CWE-346 CVE-2023-23601: Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab whic Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvdmozilla
CVE-2023-25750MEDIUMCVSS 4.3fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-25750 [MEDIUM] CWE-668 CVE-2023-25750: Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.
nvdosvmozilla
CVE-2023-23603MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23603 [MEDIUM] CWE-770 CVE-2023-23603: Regular expressions used to filter out forbidden properties and values from style directives in call Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvdmozilla
CVE-2023-28164MEDIUMCVSS 6.5fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28164 [MEDIUM] CWE-346 CVE-2023-28164: Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user co Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvdmozilla
CVE-2023-23598MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23598 [MEDIUM] CVE-2023-23598: Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plai Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvdmozilla
CVE-2023-23600MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23600 [MEDIUM] CVE-2023-23600: Per origin notification permissions were being stored in a way that didn't take into account what br Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Fir
nvdmozilla
CVE-2023-23597MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23597 [MEDIUM] CWE-326 CVE-2023-23597: A compromised web child process could disable web security opening restrictions, leading to a new ch A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This vulnerability affects Firefox < 109.
nvdosvmozilla
CVE-2023-32206MEDIUMCVSS 6.5fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32206 [MEDIUM] CWE-125 CVE-2023-32206: An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvdmozilla
CVE-2023-25748MEDIUMCVSS 4.3fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-25748 [MEDIUM] CWE-1021 CVE-2023-25748: By displaying a prompt with a long description, the fullscreen notification could have been hidden, By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.
nvdmozilla
CVE-2023-23602MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23602 [MEDIUM] CWE-754 CVE-2023-23602: A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Pol A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvdmozilla
CVE-2023-29544MEDIUMCVSS 6.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29544 [MEDIUM] CWE-400 CVE-2023-29544: If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector c If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosvmozilla
CVE-2023-28159MEDIUMCVSS 4.3fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28159 [MEDIUM] CWE-1021 CVE-2023-28159: The fullscreen notification could have been hidden on Firefox for Android by using download popups, The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.
nvdmozilla
CVE-2023-32211MEDIUMCVSS 6.5fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32211 [MEDIUM] CVE-2023-32211: A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefo A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvdmozilla
CVE-2023-29538MEDIUMCVSS 4.3fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29538 [MEDIUM] CWE-668 CVE-2023-29538: Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instea Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosvmozilla
CVE-2023-25752MEDIUMCVSS 6.5fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-25752 [MEDIUM] CVE-2023-25752: When accessing throttled streams, the count of available bytes needed to be checked in the calling f When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvdmozilla
CVE-2023-29540MEDIUMCVSS 6.1fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29540 [MEDIUM] CWE-601 CVE-2023-29540: Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosvmozilla