cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 4 of 162
CVE-2015-0802P3MEDIUMCVSS 5.0PoC≤ 36.0.42015-04-01
CVE-2015-0802 [MEDIUM] CWE-264 CVE-2015-0802: Mozilla Firefox before 37.0 relies on docshell type information instead of page principal informatio Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of ac
nvdosv
CVE-2019-9792P2CRITICALCVSS 9.8PoCfixed in 60.6.0fixed in 66.0+1 more2019-04-26
CVE-2019-9792 [CRITICAL] CWE-787 CVE-2019-9792: The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the r The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvd
CVE-2009-3373P3CRITICALCVSS 10.0PoCv3.0v3.0.1+16 more2009-10-29
CVE-2009-3373 [CRITICAL] CWE-119 CVE-2009-3373: Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2019-9813P3HIGHCVSS 8.8PoCfixed in 60.6.1fixed in 66.0.1+1 more2019-04-26
CVE-2019-9813 [HIGH] CWE-843 CVE-2019-9813: Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can b Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
nvd
CVE-2010-3131P3CRITICALCVSS 9.3PoCv3.6v3.6.2+86 more2010-08-26
CVE-2010-3131 [CRITICAL] CVE-2010-3131: Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunder Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder
nvd
CVE-2010-3179P3CRITICALCVSS 9.3PoCv3.6v3.6.2+90 more2010-10-21
CVE-2010-3179 [CRITICAL] CWE-119 CVE-2010-3179: Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a long argument to the docum
nvd
CVE-2010-1214P3CRITICALCVSS 9.3PoCv3.5.1v3.5.2+12 more2010-07-30
CVE-2010-1214 [CRITICAL] CWE-189 CVE-2010-1214: Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.
nvd
CVE-2010-1199P3CRITICALCVSS 9.3PoCv3.5v3.5.1+10 more2010-06-24
CVE-2010-1199 [CRITICAL] CWE-189 CVE-2010-1199: Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.
nvd
CVE-2010-2752P3CRITICALCVSS 9.3PoCv3.5.1v3.5.2+12 more2010-07-30
CVE-2010-2752 [CRITICAL] CWE-189 CVE-2010-2752: Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Th Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an
nvd
CVE-2009-0689P3MEDIUMCVSS 6.8PoCv3.0.1v3.0.2+16 more2009-07-01
CVE-2009-0689 [MEDIUM] CWE-119 CVE-2009-0689: Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and o
nvd
CVE-2009-2464P3CRITICALCVSS 10.0PoC≤ 3.0.11v0.1+81 more2009-07-22
CVE-2009-2464 [CRITICAL] CWE-399 CVE-2009-2464: The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaM The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.
nvd
CVE-2006-0295P3MEDIUMCVSS 5.1PoCv1.52006-02-02
CVE-2006-0295 [MEDIUM] CVE-2006-0295: Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 migh Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
nvd
CVE-2017-7783P3HIGHCVSS 7.5PoCfixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7783 [HIGH] CWE-20 CVE-2017-7783: If a long user name is used in a username/password combination in a site URL (such as " http://UserN If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.
nvdosv
CVE-2009-1313P3CRITICALCVSS 9.3PoCv3.0.92009-04-30
CVE-2009-1313 [CRITICAL] CVE-2009-1313: The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3. The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.
nvd
CVE-2005-2871P3HIGHCVSS 7.5PoCv1.0v1.0.1+6 more2005-09-09
CVE-2005-2871 [HIGH] CVE-2005-2871: Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::Build
nvd
CVE-2010-0167P3CRITICALCVSS 9.3PoCv3.0v3.0.1+17 more2010-03-25
CVE-2010-0167 [CRITICAL] CWE-119 CVE-2010-0167: The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6. The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (
nvd
CVE-2009-1169P3CRITICALCVSS 9.3PoC≤ 3.0.7v0.1+85 more2009-03-27
CVE-2009-1169 [CRITICAL] CWE-399 CVE-2009-1169: The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey be The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.
nvd
CVE-2009-3076P3CRITICALCVSS 9.3PoC≤ 3.0.13v0.1+91 more2009-09-10
CVE-2009-3076 [CRITICAL] CVE-2009-3076: Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pk Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.
nvd
CVE-2009-3382P3CRITICALCVSS 10.0PoCv3.0.1v3.0.2+12 more2009-10-29
CVE-2009-3382 [CRITICAL] CVE-2009-3382: layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 d layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2006-1993P3MEDIUMCVSS 5.1PoCv1.5.0.22006-04-25
CVE-2006-1993 [MEDIUM] CWE-399 CVE-2006-1993: Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of se Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buff
nvd
Mozilla Firefox vulnerabilities | cvebase