Mozilla Firefox vulnerabilities
3,148 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70
Vulnerabilities
Page 49 of 158
CVE-2020-26972CRITICALCVSS 9.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26972 [CRITICAL] CWE-416 CVE-2020-26972: The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former mu
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 84.
nvdosvmozilla
CVE-2020-35113HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-35113 [HIGH] CWE-787 CVE-2020-35113: Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of t
Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvdmozilla
CVE-2020-35114HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-35114 [HIGH] CWE-787 CVE-2020-35114: Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.
nvdosvmozilla
CVE-2020-35112HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-35112 [HIGH] CVE-2020-35112: If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the download
If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other ope
nvdmozilla
CVE-2020-26971HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26971 [HIGH] CWE-787 CVE-2020-26971: Certain blit values provided by the user were not properly constrained leading to a heap buffer over
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvdmozilla
CVE-2020-26973HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26973 [HIGH] CVE-2020-26973: Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. Thi
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvdmozilla
CVE-2020-26974HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26974 [HIGH] CWE-787 CVE-2020-26974: When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrec
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvdmozilla
CVE-2020-35111MEDIUMCVSS 4.3fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-35111 [MEDIUM] CVE-2020-35111: When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest ca
When an extension with the proxy permission registered to receive , the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvdmozilla
CVE-2020-26979MEDIUMCVSS 6.1fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26979 [MEDIUM] CWE-601 CVE-2020-26979: When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a websit
When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it. This v
nvdosvmozilla
CVE-2020-26978MEDIUMCVSS 6.1fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26978 [MEDIUM] CVE-2020-26978: Using techniques that built on the slipstream research, a malicious webpage could have exposed both
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvdmozilla
CVE-2020-26976MEDIUMCVSS 6.5fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26976 [MEDIUM] CVE-2020-26976: When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the fo
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
nvdmozilla
CVE-2020-26977MEDIUMCVSS 6.5fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26977 [MEDIUM] CVE-2020-26977: By attempting to connect a website using an unresponsive port, an attacker could have controlled the
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
nvdmozilla
CVE-2020-26975MEDIUMCVSS 6.5fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26975 [MEDIUM] CVE-2020-26975: When a malicious application installed on the user's device broadcast an Intent to Firefox for Andro
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating sys
nvdmozilla
CVE-2020-16042MEDIUMCVSS 6.52020-12-15
CVE-2020-16042 [MEDIUM] Mozilla Foundation Security Advisory 2020-55: CVE-2020-16042
Mozilla Foundation Security Advisory 2020-55
CVE: CVE-2020-16042
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.6
osvmozilla
CVE-2020-26952HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26952 [HIGH] CWE-787 CVE-2020-26952: Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruptio
Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash when handling out-of-memory errors. This vulnerability affects Firefox < 83.
nvdosvmozilla
CVE-2020-26968HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26968 [HIGH] CWE-787 CVE-2020-26968: Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of t
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvdmozilla
CVE-2020-26969HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26969 [HIGH] CWE-787 CVE-2020-26969: Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.
nvdosvmozilla
CVE-2020-26960HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26960 [HIGH] CWE-416 CVE-2020-26960: If the Compact() method was called on an nsTArray, the array could have been reallocated without upd
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvdmozilla
CVE-2020-26950HIGHCVSS 8.8PoCfixed in 82.0.32020-12-09
CVE-2020-26950 [HIGH] CWE-416 CVE-2020-26950: In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resultin
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.
nvdmozilla
CVE-2020-26959HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26959 [HIGH] CWE-416 CVE-2020-26959: During browser shutdown, reference decrementing could have occured on a previously freed object, res
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvdmozilla