Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 41 of 162
CVE-2021-23964P3HIGHCVSS 8.8fixed in 85.0fixed in 852021-02-26
CVE-2021-23964 [HIGH] CWE-787 CVE-2021-23964: Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of t
Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2021-38500P3HIGHCVSS 8.8fixed in 93.0≥ 91.0, < 91.2+1 more2021-11-03
CVE-2021-38500 [HIGH] CVE-2021-38500: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and
nvd
CVE-2021-43534P3HIGHCVSS 8.8fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-43534 [HIGH] CWE-787 CVE-2021-43534: Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.
nvd
CVE-2021-23960P3HIGHCVSS 8.8fixed in 85.0fixed in 852021-02-26
CVE-2021-23960 [HIGH] CVE-2021-23960: Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, a
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2023-6859P3HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6859 [HIGH] CWE-416 CVE-2023-6859: A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerabili
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2020-12406P3HIGHCVSS 8.8fixed in 77.0≥ unspecified, < 772020-07-09
CVE-2020-12406 [HIGH] CWE-345 CVE-2020-12406: Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resul
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2022-38477P3HIGHCVSS 8.8fixed in 104.0≥ unspecified, < 1042022-12-22
CVE-2022-38477 [HIGH] CWE-787 CVE-2022-38477: Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird <
nvd
CVE-2009-0821P4MEDIUMCVSS 5.0PoC≤ 2.0.0.20v0.1+75 more2009-03-05
CVE-2009-0821 [MEDIUM] CWE-399 CVE-2009-0821: Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (applicati
Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element.
nvd
CVE-2023-37202P3HIGHCVSS 8.8fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37202 [HIGH] CWE-416 CVE-2023-37202: Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartmen
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2022-22761P3HIGHCVSS 8.8fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22761 [HIGH] CWE-693 CVE-2022-22761: Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing t
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2022-42932P3HIGHCVSS 8.8fixed in 106.0≥ unspecified, < 1062022-12-22
CVE-2022-42932 [HIGH] CWE-787 CVE-2022-42932: Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106, Firefox ESR < 102.4
nvd
CVE-2022-22764P3HIGHCVSS 8.8fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22764 [HIGH] CWE-787 CVE-2022-22764: Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, an
nvd
CVE-2017-7786P3CRITICALCVSS 9.8≥ 52.0, < 52.1.0fixed in 55.0+1 more2018-06-11
CVE-2017-7786 [CRITICAL] CWE-119 CVE-2017-7786: A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements.
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2022-38473P3HIGHCVSS 8.8fixed in 104.0≥ 102.0, < 102.2+1 more2022-12-22
CVE-2022-38473 [HIGH] CWE-281 CVE-2022-38473: A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (su
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
nvd
CVE-2023-25744P3HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25744 [HIGH] CWE-787 CVE-2023-25744: Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
nvd
CVE-2024-7522P3HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7522 [HIGH] CWE-125 CVE-2024-7522: Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This v
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2023-4047P3HIGHCVSS 8.8fixed in 116.0≥ 102.0, < 102.14+2 more2023-08-01
CVE-2023-4047 [HIGH] CWE-352 CVE-2023-4047: A bug in popup notifications delay calculation could have made it possible for an attacker to trick
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvdosv
CVE-2023-28161P3HIGHCVSS 8.8fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28161 [HIGH] CWE-281 CVE-2023-28161: If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a docume
If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. This is potentially dangerous if the local files came from different sources, such as in a download directory. This vulnerability affects
nvdosv
CVE-2024-4770P3HIGHCVSS 8.8fixed in 115.11.0fixed in 126.0+1 more2024-05-14
CVE-2024-4770 [HIGH] CWE-416 CVE-2024-4770: When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. T
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2024-9400P3HIGHCVSS 8.8fixed in 128.3.0fixed in 131.0+1 more2024-10-01
CVE-2024-9400 [HIGH] CWE-119 CVE-2024-9400: A potential memory corruption vulnerability could be triggered if an attacker had the ability to tri
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd