Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 44 of 162
CVE-2006-1735P3CRITICALCVSS 9.3≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1735 [CRITICAL] CWE-264 CVE-2006-1735: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13,
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges.
nvd
CVE-2017-5403P3CRITICALCVSS 9.8fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5403 [CRITICAL] CWE-416 CVE-2017-5403: When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2019-11691P3CRITICALCVSS 9.8fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11691 [CRITICAL] CWE-416 CVE-2019-11691: A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, ca
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvdosv
CVE-2015-4473P3CRITICALCVSS 10.0≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4473 [CRITICAL] CWE-119 CVE-2015-4473: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2006-6504P3CRITICALCVSS 9.3≥ 1.5, < 1.5.0.9≥ 2.0, < 2.0.0.12006-12-20
CVE-2006-6504 [CRITICAL] CWE-94 CVE-2006-6504: Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote a
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
nvd
CVE-2019-11733P3CRITICALCVSS 9.8fixed in 68.0.2≥ unspecified, < 68.0.22019-09-27
CVE-2019-11733 [CRITICAL] CWE-287 CVE-2019-11733: When a master password is set, it is required to be entered again before stored passwords can be acc
When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered i
nvdosv
CVE-2016-2796P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2796 [HIGH] CWE-119 CVE-2016-2796: Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
nvd
CVE-2017-5444P3HIGHCVSS 7.5fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5444 [HIGH] CWE-119 CVE-2017-5444: A buffer overflow vulnerability while parsing "application/http-index-format" format content when th
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2012-3965P3CRITICALCVSS 9.3≤ 14.0v1.0+129 more2012-08-29
CVE-2012-3965 [CRITICAL] CWE-264 CVE-2012-3965: Mozilla Firefox before 15.0 does not properly restrict navigation to the about:newtab page, which al
Mozilla Firefox before 15.0 does not properly restrict navigation to the about:newtab page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers creation of a new tab and then a new window.
nvd
CVE-2015-7183P3HIGHCVSS 7.5≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-7183 [HIGH] CWE-119 CVE-2015-7183: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozi
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup
nvd
CVE-2021-4129P3CRITICALCVSS 9.8fixed in 95.0≥ unspecified, < 952022-12-22
CVE-2021-4129 [CRITICAL] CWE-787 CVE-2021-4129: Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith,
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. Thi
nvd
CVE-2013-5610P3CRITICALCVSS 10.0fixed in 26.02013-12-11
CVE-2013-5610 [CRITICAL] CWE-787 CVE-2013-5610: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMon
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2022-29917P3CRITICALCVSS 9.8fixed in 100.0≥ unspecified, < 1002022-12-22
CVE-2022-29917 [CRITICAL] CWE-787 CVE-2022-29917: Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team report
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affect
nvd
CVE-2024-11704P3CRITICALCVSS 9.8fixed in 128.7.0fixed in 133.0+1 more2024-11-26
CVE-2024-11704 [CRITICAL] CWE-415 CVE-2024-11704: A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an erro
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.
nvd
CVE-2024-6604P3HIGHCVSS 7.5fixed in 115.13fixed in 126.0+1 more2024-07-09
CVE-2024-6604 [HIGH] CWE-120 CVE-2024-6604: Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2025-1937P3HIGHCVSS 7.5fixed in 115.21.0fixed in 128.8.0+1 more2025-03-04
CVE-2025-1937 [HIGH] CWE-1260 CVE-2025-1937: Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, a
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox E
nvd
CVE-2022-34485P3CRITICALCVSS 9.8v101.0v101.0.1+1 more2022-12-22
CVE-2022-34485 [CRITICAL] CWE-787 CVE-2022-34485: Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilit
Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102.
nvdosv
CVE-2022-34476P3CRITICALCVSS 9.8fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34476 [CRITICAL] CWE-20 CVE-2022-34476: ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.
nvdosv
CVE-2023-25736P3CRITICALCVSS 9.8fixed in 110.0≥ unspecified, < 1102023-06-19
CVE-2023-25736 [CRITICAL] CVE-2023-25736: An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. Thi
An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.
nvdosv
CVE-2024-8900P3HIGHCVSS 7.5fixed in 129.0≥ unspecified, < 1292024-09-17
CVE-2024-8900 [HIGH] CWE-732 CVE-2024-8900: An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain se
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
nvd