cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 46 of 162
CVE-2025-14332P3HIGHCVSS 7.3fixed in 146.02025-12-09
CVE-2025-14332 [HIGH] CWE-787 CVE-2025-14332: Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146 and Thunderbird 146.
nvd
CVE-2013-1677P3CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1677 [CRITICAL] CWE-399 CVE-2013-1677: The gfxSkipCharsIterator::SetOffsets function in Mozilla Firefox before 21.0, Firefox ESR 17.x befor The gfxSkipCharsIterator::SetOffsets function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2016-1930P3CRITICALCVSS 9.8≤ 43.0.4v38.0+5 more2016-01-31
CVE-2016-1930 [CRITICAL] CWE-119 CVE-2016-1930: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2012-3960P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3960 [CRITICAL] CWE-416 CVE-2012-3960: Use-after-free vulnerability in the mozSpellChecker::SetCurrentDictionary function in Mozilla Firefo Use-after-free vulnerability in the mozSpellChecker::SetCurrentDictionary function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecifi
nvd
CVE-2012-3956P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3956 [CRITICAL] CWE-416 CVE-2012-3956: Use-after-free vulnerability in the MediaStreamGraphThreadRunnable::Run function in Mozilla Firefox Use-after-free vulnerability in the MediaStreamGraphThreadRunnable::Run function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified
nvd
CVE-2020-6800P3HIGHCVSS 8.8fixed in 73.0≥ unspecified, < 73+1 more2020-03-02
CVE-2020-6800 [HIGH] CWE-787 CVE-2020-6800: Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product
nvd
CVE-2012-3958P3CRITICALCVSS 10.0v10.0v10.0.1+133 more2012-08-29
CVE-2012-3958 [CRITICAL] CWE-399 CVE-2012-3958: Use-after-free vulnerability in the nsHTMLEditRules::DeleteNonTableElements function in Mozilla Fire Use-after-free vulnerability in the nsHTMLEditRules::DeleteNonTableElements function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2007-0776P3CRITICALCVSS 9.3≤ 2.0.0.12007-02-26
CVE-2007-0776 [CRITICAL] CWE-119 CVE-2007-0776: Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Th Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.
nvd
CVE-2020-12422P3HIGHCVSS 8.8fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12422 [HIGH] CWE-787 CVE-2020-12422: In non-standard configurations, a JPEG image created by JavaScript could have caused an internal var In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
nvdosv
CVE-2013-0752P3CRITICALCVSS 9.3fixed in 17.0.2fixed in 18.02013-01-13
CVE-2013-0752 [CRITICAL] CWE-119 CVE-2013-0752: Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XBL file with multiple bindings that have SVG content.
nvd
CVE-2014-1537P3CRITICALCVSS 10.0≤ 29.0.12014-06-11
CVE-2014-1537 [CRITICAL] CVE-2014-1537: Use-after-free vulnerability in the mozilla::dom::workers::WorkerPrivateParent function in Mozilla F Use-after-free vulnerability in the mozilla::dom::workers::WorkerPrivateParent function in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvdosv
CVE-2015-4492P3HIGHCVSS 7.5≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4492 [HIGH] CVE-2015-4492: Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40 Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.
nvdosv
CVE-2013-5598P3HIGHCVSS 8.3v24.0v24.0.1+11 more2013-10-30
CVE-2013-5598 [HIGH] CWE-264 CVE-2013-5598: PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
nvd
CVE-2019-11740P3HIGHCVSS 8.8fixed in 60.9.0fixed in 69.0+1 more2019-09-27
CVE-2019-11740 [HIGH] CWE-787 CVE-2019-11740: Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird
nvd
CVE-2021-38496P3HIGHCVSS 8.8fixed in 93.0≥ 91.0, < 91.2+1 more2021-11-03
CVE-2021-38496 [HIGH] CWE-416 CVE-2021-38496: During operations on MessageTasks, a task may have been removed while it was still scheduled, result During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
nvd
CVE-2020-12410P3HIGHCVSS 8.8fixed in 76.0≥ unspecified, < 772020-07-09
CVE-2020-12410 [HIGH] CWE-787 CVE-2020-12410: Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of t Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2015-2743P3HIGHCVSS 7.5v31.0v31.1.0+7 more2015-07-06
CVE-2015-2743 [HIGH] CWE-17 CVE-2015-2743: PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.
nvdosv
CVE-2021-29985P3HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29985 [HIGH] CWE-416 CVE-2021-29985: A use-after-free vulnerability in media channels could have led to memory corruption and a potential A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2013-0789P3CRITICALCVSS 10.0≤ 19.0.2v19.0+1 more2013-04-03
CVE-2013-0789 [CRITICAL] CVE-2013-0789: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMon Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other vectors.
nvd
CVE-2021-29984P3HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29984 [HIGH] CWE-787 CVE-2021-29984: Instruction reordering resulted in a sequence of instructions that would cause an object to be incor Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd