cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 43 of 162
CVE-2018-12395P3HIGHCVSS 7.5fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12395 [HIGH] CVE-2018-12395: By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain re By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
nvd
CVE-2006-1730P3CRITICALCVSS 9.3v1.0v1.0.1+8 more2006-04-14
CVE-2006-1730 [CRITICAL] CWE-189 CVE-2006-1730: Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozil Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.
nvd
CVE-2017-7800P3CRITICALCVSS 9.8fixed in 55.0fixed in 52.3.0+1 more2018-06-11
CVE-2017-7800 [CRITICAL] CWE-416 CVE-2017-7800: A use-after-free vulnerability can occur in WebSockets when the object holding the connection is fre A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2009-1827P4MEDIUMCVSS 5.0PoCv3.0.42009-05-29
CVE-2009-1827 [MEDIUM] CWE-399 CVE-2009-1827: The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (app The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."
nvd
CVE-2018-5115P3HIGHCVSS 7.5≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5115 [HIGH] CWE-200 CVE-2018-5115: If an HTTP authentication prompt is triggered by a background network request from a page or extensi If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly se
nvdosv
CVE-2017-7749P3CRITICALCVSS 9.8fixed in 54.0fixed in 52.2.0+1 more2018-06-11
CVE-2017-7749 [CRITICAL] CWE-416 CVE-2017-7749: A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2007-3738P3CRITICALCVSS 9.3v2.0v2.0.0.1+3 more2007-07-18
CVE-2007-3738 [CRITICAL] CVE-2007-3738: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to exe Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
nvd
CVE-2013-0796P3CRITICALCVSS 10.0fixed in 20.0≥ 17.0, < 17.0.52013-04-03
CVE-2013-0796 [CRITICAL] CVE-2013-0796: The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird befo The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 on Linux does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (free of unallocated memory) via unspecified v
nvd
CVE-2012-4210P3CRITICALCVSS 9.3≤ 16.0.2v0.1+160 more2012-11-21
CVE-2012-4210 [CRITICAL] CWE-264 CVE-2012-4210: The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not prop The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted stylesheet.
nvd
CVE-2020-12395P3CRITICALCVSS 9.8fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12395 [CRITICAL] CWE-787 CVE-2020-12395: Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird <
nvd
CVE-2017-5425P3HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5425 [HIGH] CWE-200 CVE-2017-5425: The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. O
nvd
CVE-2019-9788P3CRITICALCVSS 9.8fixed in 60.6.0fixed in 66.0+1 more2019-04-26
CVE-2019-9788 [CRITICAL] CWE-787 CVE-2019-9788: Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.
nvdosv
CVE-2026-0877P3HIGHCVSS 8.1fixed in 115.32.0fixed in 147.0+1 more2026-01-13
CVE-2026-0877 [HIGH] CWE-693 CVE-2026-0877: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firef Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvd
CVE-2026-12290P3HIGHCVSS 8.1fixed in 115.37.0fixed in 152.0.0+1 more2026-06-16
CVE-2026-12290 [HIGH] CWE-119 CVE-2026-12290: Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140 Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-8962P3HIGHCVSS 8.1fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8962 [HIGH] CWE-693 CVE-2026-8962: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firef Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2014-1493P3CRITICALCVSS 9.8fixed in 28.0≥ 24.0, < 24.42014-03-19
CVE-2014-1493 [CRITICAL] CWE-119 CVE-2014-1493: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-5609P3CRITICALCVSS 9.8fixed in 26.0≥ 24.0, < 24.22013-12-11
CVE-2013-5609 [CRITICAL] CVE-2013-5609: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2026-4718P3HIGHCVSS 8.1fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4718 [HIGH] CWE-758 CVE-2026-4718: Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2025-13018P3HIGHCVSS 8.1fixed in 140.5.0fixed in 145.02025-11-11
CVE-2025-13018 [HIGH] CWE-288 CVE-2025-13018: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firef Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
nvd
CVE-2019-9800P3CRITICALCVSS 9.8fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9800 [CRITICAL] CWE-787 CVE-2019-9800: Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and
nvd
Mozilla Firefox vulnerabilities | cvebase