Mozilla Firefox vulnerabilities
3,148 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70
Vulnerabilities
Page 37 of 158
CVE-2022-38473HIGHCVSS 8.8fixed in 104.0≥ 102.0, < 102.2+1 more2022-12-22
CVE-2022-38473 [HIGH] CWE-281 CVE-2022-38473: A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (su
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
nvdmozilla
CVE-2022-46874HIGHCVSS 8.8fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46874 [HIGH] CWE-94 CVE-2022-46874: A file with a long filename could have had its filename truncated to remove the valid extension, lea
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitte
nvdmozilla
CVE-2022-22751HIGHCVSS 8.8fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22751 [HIGH] CWE-787 CVE-2022-22751: Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto,
Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memory safety bugs present in Firefox 95 and Firefox ESR 91.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t
nvdmozilla
CVE-2022-22744HIGHCVSS 8.8fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22744 [HIGH] CWE-116 CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped fo
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunder
nvdmozilla
CVE-2022-46872HIGHCVSS 8.6fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46872 [HIGH] CWE-125 CVE-2022-46872: An attacker who compromised a content process could have partially escaped the sandbox to read arbit
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvdmozilla
CVE-2022-26381HIGHCVSS 8.8fixed in 98.0≥ unspecified, < 982022-12-22
CVE-2022-26381 [HIGH] CWE-416 CVE-2022-26381: An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to
An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvdmozilla
CVE-2022-45421HIGHCVSS 8.8fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45421 [HIGH] CWE-787 CVE-2022-45421: Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thund
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox
nvdmozilla
CVE-2022-22741HIGHCVSS 7.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22741 [HIGH] CVE-2022-22741: When resizing a popup while requesting fullscreen access, the popup would have become unable to leav
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvdmozilla
CVE-2022-22761HIGHCVSS 8.8fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22761 [HIGH] CWE-693 CVE-2022-22761: Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing t
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvdmozilla
CVE-2022-22753HIGHCVSS 7.1fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22753 [HIGH] CWE-367 CVE-2022-22753: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6,
nvdmozilla
CVE-2022-22752HIGHCVSS 8.8fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22752 [HIGH] CWE-787 CVE-2022-22752: Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox
Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 96.
nvdosvmozilla
CVE-2022-42927HIGHCVSS 8.1fixed in 106.0≥ unspecified, < 1062022-12-22
CVE-2022-42927 [HIGH] CWE-346 CVE-2022-42927: A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvdosvmozilla
CVE-2022-31741HIGHCVSS 8.8fixed in 101≥ unspecified, < 1012022-12-22
CVE-2022-31741 [HIGH] CWE-908 CVE-2022-31741: A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvdmozilla
CVE-2022-45407HIGHCVSS 7.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45407 [HIGH] CWE-416 CVE-2022-45407: If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free
If an attacker loaded a font using FontFace() on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107.
nvdmozilla
CVE-2022-26485HIGHCVSS 8.8KEVfixed in 91.6.1fixed in 97.0.2+2 more2022-12-22
CVE-2022-26485 [HIGH] CWE-416 CVE-2022-26485: Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We ha
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
nvdosvmozilla
CVE-2022-28289HIGHCVSS 8.8fixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28289 [HIGH] CWE-787 CVE-2022-28289: Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mo
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability
nvdmozilla
CVE-2022-26387HIGHCVSS 7.5fixed in 98.0≥ unspecified, < 982022-12-22
CVE-2022-26387 [HIGH] CWE-367 CVE-2022-26387: When installing an add-on, Firefox verified the signature before prompting the user; but while the u
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvdmozilla
CVE-2022-46878HIGHCVSS 8.8fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46878 [HIGH] CWE-787 CVE-2022-46878: Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firef
nvdmozilla
CVE-2022-46873HIGHCVSS 8.8fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46873 [HIGH] CWE-74 CVE-2022-46873: Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was
Because Firefox did not implement the unsafe-hashes CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.
nvdosvmozilla
CVE-2022-46881HIGHCVSS 8.8fixed in 106.0≥ unspecified, < 1062022-12-22
CVE-2022-46881 [HIGH] CWE-787 CVE-2022-46881: An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash.
*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR <
nvdmozilla