Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 5 of 162
CVE-2005-2265P3MEDIUMCVSS 5.0PoCv0.8v0.9+10 more2005-07-13
CVE-2005-2265 [MEDIUM] CVE-2005-2265: Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to ca
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.
nvd
CVE-2024-29943P2CRITICALCVSS 9.8fixed in 124.0.1≥ unspecified, < 124.0.12024-03-22
CVE-2024-29943 [CRITICAL] CWE-125 CVE-2024-29943: An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling ran
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.
nvdosv
CVE-2007-3845P3CRITICALCVSS 9.3PoCv2.0.0.52007-08-08
CVE-2007-3845 [CRITICAL] CVE-2007-3845: Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey be
Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still po
nvd
CVE-2023-6856P2HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6856 [HIGH] CWE-787 CVE-2023-6856: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on syst
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2005-2968P3HIGHCVSS 7.5PoCv1.0.62005-09-20
CVE-2005-2968 [HIGH] CVE-2005-2968: Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharac
Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.
nvd
CVE-2017-5415P3MEDIUMCVSS 5.3PoCfixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5415 [MEDIUM] CWE-20 CVE-2017-5415: An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
nvdosv
CVE-2009-2479P3HIGHCVSS 7.8PoCv3.0.1v3.0.2+17 more2009-07-16
CVE-2009-2479 [HIGH] CWE-119 CVE-2009-2479: Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of servic
Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occur
nvd
CVE-2010-0168P3HIGHCVSS 7.6PoCv3.6v3.6.12010-03-25
CVE-2010-0168 [HIGH] CWE-264 CVE-2010-0168: The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloadin
The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of
nvd
CVE-2019-9816P3MEDIUMCVSS 5.9PoCfixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9816 [MEDIUM] CWE-843 CVE-2019-9816: A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbi
nvd
CVE-2022-2200P3HIGHCVSS 8.8fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-2200 [HIGH] CWE-1321 CVE-2022-2200: If an object prototype was corrupted by an attacker, they would have been able to set undesired attr
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvdosv
CVE-2007-0981P3HIGHCVSS 7.5PoC≤ 1.5.0.9v0.8+35 more2007-02-16
CVE-2007-0981 [HIGH] CWE-264 CVE-2007-0981: Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey befo
Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.
nvd
CVE-2007-0009P3MEDIUMCVSS 6.8≥ 1.5, < 1.5.0.10≥ 2.0, < 2.0.0.22007-02-26
CVE-2007-0009 [MEDIUM] CWE-119 CVE-2007-0009: Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Mas
nvd
CVE-2007-1562P3MEDIUMCVSS 6.8PoC≥ 1.5, < 1.5.0.11≥ 2.0, < 2.0.0.32007-03-21
CVE-2007-1562 [MEDIUM] CWE-200 CVE-2007-1562: The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows rem
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
nvd
CVE-2004-0648P3CRITICALCVSS 10.0PoC≤ 0.9.22004-08-06
CVE-2004-0648 [CRITICAL] CVE-2004-0648: Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attack
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
nvd
CVE-2006-4253P3HIGHCVSS 7.6PoCv0.8v0.9+21 more2006-08-21
CVE-2006-4253 [HIGH] CWE-264 CVE-2006-4253: Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be fr
nvd
CVE-2014-1512P3CRITICALCVSS 10.0fixed in 28.0≥ 24.0, < 24.42014-03-19
CVE-2014-1512 [CRITICAL] CWE-416 CVE-2014-1512: Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox bef
Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is occurring, as demonstrated by improper
nvd
CVE-2025-4918P3CRITICALCVSS 9.8fixed in 115.23.1fixed in 138.0.4+1 more2025-05-17
CVE-2025-4918 [CRITICAL] CWE-125 CVE-2025-4918: An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. Thi
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.
nvd
CVE-2026-16367P3CRITICALCVSS 10.0fixed in 153.0.02026-07-21
CVE-2026-16367 [CRITICAL] CWE-119 CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability wa
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2018-18505P3CRITICALCVSS 10.0fixed in 60.5.0fixed in 65.02019-02-05
CVE-2018-18505 [CRITICAL] CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authenti
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later chann
nvd
CVE-2005-1532P3HIGHCVSS 7.5PoCv0.8v0.9+9 more2005-05-12
CVE-2005-1532 [HIGH] CVE-2005-1532: Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript e
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
nvd