cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 48 of 162
CVE-2018-12393P3HIGHCVSS 7.5fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12393 [HIGH] CWE-190 CVE-2018-12393: A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox
nvd
CVE-2022-46883P3HIGHCVSS 8.8fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-46883 [HIGH] CWE-787 CVE-2022-46883: Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team re Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.*Note*: This advisory was added on December 13
nvdosv
CVE-2022-22763P3HIGHCVSS 8.8fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22763 [HIGH] CWE-362 CVE-2022-22763: When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2022-28284P3HIGHCVSS 8.8fixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28284 [HIGH] CWE-116 CVE-2022-28284: SVG's <code>&lt;use&gt;</code> element could have been used to load unexpected content that could ha SVG's element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99.
nvdosv
CVE-2023-29551P3HIGHCVSS 8.8fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29551 [HIGH] CWE-787 CVE-2023-29551: Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosv
CVE-2024-6615P3HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6615 [HIGH] CWE-787 CVE-2024-6615: Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosv
CVE-2016-5256P3CRITICALCVSS 9.8≤ 48.0.22016-09-22
CVE-2016-5256 [CRITICAL] CWE-119 CVE-2016-5256: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2009-0723P3CRITICALCVSS 9.3v3.12009-03-23
CVE-2009-0723 [CRITICAL] CWE-190 CVE-2009-0723: Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3 Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
nvd
CVE-2013-0779P3CRITICALCVSS 9.3fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0779 [CRITICAL] CWE-125 CVE-2013-0779: The nsCodingStateMachine::NextState function in Mozilla Firefox before 19.0, Thunderbird before 17.0 The nsCodingStateMachine::NextState function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2017-5400P3CRITICALCVSS 9.8fixed in 45.8.0fixed in 52.0+1 more2018-06-11
CVE-2017-5400 [CRITICAL] CWE-119 CVE-2017-5400: JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protection JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2019-11716P3HIGHCVSS 8.3fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11716 [HIGH] CWE-20 CVE-2019-11716: Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not vi Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.
nvdosv
CVE-2010-3168P3CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-3168 [CRITICAL] CWE-119 CVE-2010-3168: Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1. Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to cause a denial of service (deleted memory access and application crash) or possibly execute arbitrary
nvd
CVE-2018-18501P3CRITICALCVSS 9.8fixed in 65.0≥ unspecified, < 652019-02-05
CVE-2018-18501 [CRITICAL] CWE-119 CVE-2018-18501: Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox <
nvd
CVE-2018-5154P3CRITICALCVSS 9.8fixed in 52.8.0fixed in 60.0+1 more2018-06-11
CVE-2018-5154 [CRITICAL] CWE-416 CVE-2018-5154: A use-after-free vulnerability can occur while enumerating attributes during SVG animations with cli A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvd
CVE-2017-5376P3CRITICALCVSS 9.8fixed in 51.0fixed in 45.7.0+1 more2018-06-11
CVE-2017-5376 [CRITICAL] CWE-416 CVE-2017-5376: Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45 Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2018-12390P3CRITICALCVSS 9.8fixed in 60.3.0fixed in 63.0+1 more2019-02-28
CVE-2018-12390 [CRITICAL] CWE-119 CVE-2018-12390: Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 6
nvd
CVE-2018-12405P3CRITICALCVSS 9.8fixed in 60.4.0fixed in 64.0+1 more2019-02-28
CVE-2018-12405 [CRITICAL] CWE-119 CVE-2018-12405: Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox <
nvdosv
CVE-2018-5150P3CRITICALCVSS 9.8fixed in 52.8.0fixed in 60.0+1 more2018-06-11
CVE-2018-5150 [CRITICAL] CWE-119 CVE-2018-5150: Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of thes Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8
nvdosv
CVE-2017-5432P3CRITICALCVSS 9.8fixed in 53.0v52.0+2 more2018-06-11
CVE-2017-5432 [CRITICAL] CWE-416 CVE-2017-5432: A use-after-free vulnerability occurs during certain text input selection resulting in a potentially A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5435P3CRITICALCVSS 9.8fixed in 53.0v52.0+2 more2018-06-11
CVE-2017-5435 [CRITICAL] CWE-416 CVE-2017-5435: A use-after-free vulnerability occurs during transaction processing in the editor during design mode A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
Mozilla Firefox vulnerabilities | cvebase