Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 40 of 162
CVE-2013-1678P3CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1678 [CRITICAL] CWE-119 CVE-2013-1678: The _cairo_xlib_surface_add_glyph function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 1
The _cairo_xlib_surface_add_glyph function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via unspecified vectors.
nvd
CVE-2013-1736P3CRITICALCVSS 10.0v17.0v17.0.1+16 more2013-09-18
CVE-2013-1736 [CRITICAL] CWE-119 CVE-2013-1736: The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17
The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to improperly establishing parent-child
nvd
CVE-2016-5272P3HIGHCVSS 8.8≤ 48.0.2v45.1.0+3 more2016-09-22
CVE-2016-5272 [HIGH] CWE-20 CVE-2016-5272: The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thu
The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which allows remote attackers to execute arbitrary code via a crafted web site.
nvd
CVE-2013-5602P3CRITICALCVSS 10.0v17.0v17.0.1+21 more2013-10-30
CVE-2013-5602 [CRITICAL] CWE-119 CVE-2013-5602: The Worker::SetEventListener function in the Web workers implementation in Mozilla Firefox before 25
The Worker::SetEventListener function in the Web workers implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via ve
nvd
CVE-2016-1946P3CRITICALCVSS 9.8≤ 43.0.42016-01-31
CVE-2016-1946 [CRITICAL] CWE-119 CVE-2016-1946: The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox bef
The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.
nvdosv
CVE-2018-12391P3HIGHCVSS 8.8fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12391 [HIGH] CWE-863 CVE-2018-12391: During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins i
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of
nvd
CVE-2012-4187P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4187 [CRITICAL] CWE-119 CVE-2012-4187: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and assertion failure) via unspecified vecto
nvd
CVE-2006-1726P3CRITICALCVSS 9.3v1.0v1.0.1+9 more2006-04-14
CVE-2006-1726 [CRITICAL] CWE-264 CVE-2006-1726: Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1,
Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueToFunctionObject check and execute arbitrary code via unknown vectors involving setTimeout and Firefox' ForEach method.
nvd
CVE-2014-1550P3CRITICALCVSS 10.0≤ 30.02014-07-23
CVE-2014-1550 [CRITICAL] CVE-2014-1550: Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderb
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.
nvdosv
CVE-2016-9078P3HIGHCVSS 8.8v49.0v50.0+1 more2018-06-11
CVE-2016-9078 [HIGH] CWE-601 CVE-2016-9078: Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "dat
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Fir
nvdosv
CVE-2019-17008P3HIGHCVSS 8.8fixed in 71.0vbefore 712020-01-08
CVE-2019-17008 [HIGH] CWE-416 CVE-2019-17008: When using nested workers, a use-after-free could occur during worker destruction. This resulted in
When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2008-4058P3HIGHCVSS 7.5fixed in 2.0.0.17≥ 3.0, < 3.0.22008-09-24
CVE-2008-4058 [HIGH] CWE-264 CVE-2008-4058: The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before
The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.
nvd
CVE-2014-1576P3HIGHCVSS 7.5v31.0v31.1.0+2 more2014-10-15
CVE-2014-1576 [HIGH] CWE-119 CVE-2014-1576: Heap-based buffer overflow in the nsTransformedTextRun function in Mozilla Firefox before 33.0, Fire
Heap-based buffer overflow in the nsTransformedTextRun function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to execute arbitrary code via Cascading Style Sheets (CSS) token sequences that trigger changes to capitalization style.
nvdosv
CVE-2020-15667P3HIGHCVSS 8.8fixed in 80.0≥ unspecified, < 802020-10-01
CVE-2020-15667 [HIGH] CWE-787 CVE-2020-15667: When processing a MAR update file, after the signature has been validated, an invalid name length co
When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.
nvd
CVE-2021-23978P3HIGHCVSS 8.8fixed in 86.0fixed in 862021-02-26
CVE-2021-23978 [HIGH] CWE-787 CVE-2021-23978: Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of t
Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2020-15656P3HIGHCVSS 8.8fixed in 79.0≥ unspecified, < 792020-08-10
CVE-2020-15656 [HIGH] CWE-843 CVE-2020-15656: JIT optimizations involving the Javascript arguments object could confuse later optimizations. This
JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvdosv
CVE-2020-26968P3HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26968 [HIGH] CWE-787 CVE-2020-26968: Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of t
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-26974P3HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26974 [HIGH] CWE-787 CVE-2020-26974: When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrec
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2020-35113P3HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-35113 [HIGH] CWE-787 CVE-2020-35113: Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of t
Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2021-23999P3HIGHCVSS 8.8fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-23999 [HIGH] CWE-269 CVE-2021-23999: If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the Sys
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd