Mozilla Firefox vulnerabilities
3,148 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70
Vulnerabilities
Page 44 of 158
CVE-2021-43545MEDIUMCVSS 6.5fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43545 [MEDIUM] CWE-834 CVE-2021-43545: Using the Location API in a loop could have caused severe application hangs and crashes. This vulner
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvdmozilla
CVE-2021-43533MEDIUMCVSS 4.3fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-43533 [MEDIUM] CVE-2021-43533: When parsing internationalized domain names, high bits of the characters in the URLs were sometimes
When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94.
nvdosvmozilla
CVE-2021-38508MEDIUMCVSS 4.3fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-38508 [MEDIUM] CWE-1021 CVE-2021-38508: By displaying a form validity message in the correct location at the same time as a permission promp
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvdmozilla
CVE-2021-43540MEDIUMCVSS 6.5fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43540 [MEDIUM] CVE-2021-43540: WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-
WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension. This vulnerability affects Firefox < 95.
nvdosvmozilla
CVE-2021-43530MEDIUMCVSS 6.1fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-43530 [MEDIUM] CWE-79 CVE-2021-43530: A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitizatio
A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.
nvdmozilla
CVE-2021-38494HIGHCVSS 8.8fixed in 92.0≥ unspecified, < 922021-11-03
CVE-2021-38494 [HIGH] CWE-787 CVE-2021-38494: Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 92.
nvdosvmozilla
CVE-2021-38500HIGHCVSS 8.8fixed in 93.0≥ 91.0, < 91.2+1 more2021-11-03
CVE-2021-38500 [HIGH] CVE-2021-38500: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and
nvdmozilla
CVE-2021-38501HIGHCVSS 8.8fixed in 93.0≥ unspecified, < 932021-11-03
CVE-2021-38501 [HIGH] CVE-2021-38501: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosvmozilla
CVE-2021-29993HIGHCVSS 8.1fixed in 92.0≥ unspecified, < 922021-11-03
CVE-2021-29993 [HIGH] CVE-2021-29993: Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cau
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.
nvdmozilla
CVE-2021-38498HIGHCVSS 7.5fixed in 93.0≥ unspecified, < 932021-11-03
CVE-2021-38498 [HIGH] CWE-416 CVE-2021-38498: During process shutdown, a document could have caused a use-after-free of a languages service object
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosvmozilla
CVE-2021-29991HIGHCVSS 8.1fixed in 91.0.1≥ unspecified, < 91.0.12021-11-03
CVE-2021-29991 [HIGH] CWE-444 CVE-2021-29991: Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers.
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.
nvdosvmozilla
CVE-2021-38499HIGHCVSS 8.8fixed in 93.0≥ unspecified, < 932021-11-03
CVE-2021-38499 [HIGH] CWE-787 CVE-2021-38499: Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93.
nvdosvmozilla
CVE-2021-38496HIGHCVSS 8.8fixed in 93.0≥ 91.0, < 91.2+1 more2021-11-03
CVE-2021-38496 [HIGH] CWE-416 CVE-2021-38496: During operations on MessageTasks, a task may have been removed while it was still scheduled, result
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
nvdmozilla
CVE-2021-38493HIGHCVSS 8.8fixed in 92.0≥ unspecified, < 922021-11-03
CVE-2021-38493 [HIGH] CWE-787 CVE-2021-38493: Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of
Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.
nvdmozilla
CVE-2021-38497MEDIUMCVSS 6.5fixed in 93.0≥ unspecified, < 932021-11-03
CVE-2021-38497 [MEDIUM] CWE-346 CVE-2021-38497: Through use of reportValidity() and window.open(), a plain-text validation message could have been o
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosvmozilla
CVE-2021-38492MEDIUMCVSS 6.5fixed in 92.0≥ 91.0, < 91.1+1 more2021-11-03
CVE-2021-38492 [MEDIUM] CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which migh
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 7
nvdmozilla
CVE-2021-38491MEDIUMCVSS 6.5fixed in 92.0≥ unspecified, < 922021-11-03
CVE-2021-38491 [MEDIUM] CVE-2021-38491: Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loa
Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox < 92.
nvdosvmozilla
CVE-2021-29988HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29988 [HIGH] CWE-125 CVE-2021-29988: Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of b
Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdmozilla
CVE-2021-29986HIGHCVSS 8.1fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29986 [HIGH] CWE-362 CVE-2021-29986: A suspected race condition when calling getaddrinfo led to memory corruption and a potentially explo
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdmozilla
CVE-2021-29980HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29980 [HIGH] CWE-909 CVE-2021-29980: Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corr
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvdmozilla