Mozilla Firefox vulnerabilities
3,148 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70
Vulnerabilities
Page 50 of 158
CVE-2020-26956MEDIUMCVSS 6.1fixed in 83.0fixed in 832020-12-09
CVE-2020-26956 [MEDIUM] CWE-79 CVE-2020-26956: In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvdmozilla
CVE-2020-26951MEDIUMCVSS 6.1fixed in 83.0fixed in 832020-12-09
CVE-2020-26951 [MEDIUM] CWE-79 CVE-2020-26951: A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, e
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbi
nvdmozilla
CVE-2020-26955MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26955 [MEDIUM] CWE-565 CVE-2020-26955: When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are
nvdmozilla
CVE-2020-26964MEDIUMCVSS 6.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26964 [MEDIUM] CVE-2020-26964: If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version pri
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however,
nvdmozilla
CVE-2020-26954MEDIUMCVSS 4.3fixed in 83.0fixed in 862020-12-09
CVE-2020-26954 [MEDIUM] CVE-2020-26954: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Andro
nvdmozilla
CVE-2020-26961MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26961 [MEDIUM] CVE-2020-26961: When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the respo
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR <
nvdmozilla
CVE-2020-26962MEDIUMCVSS 6.1fixed in 83.0fixed in 832020-12-09
CVE-2020-26962 [MEDIUM] CWE-1021 CVE-2020-26962: Cross-origin iframes that contained a login form could have been recognized by the login autofill se
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.
nvdosvmozilla
CVE-2020-26966MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26966 [MEDIUM] CVE-2020-26966: Searching for a single word from the address bar caused an mDNS request to be sent on the local netw
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thu
nvdmozilla
CVE-2020-26965MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26965 [MEDIUM] CWE-212 CVE-2020-26965: Some websites have a feature "Show Password" where clicking a button will change a password field in
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and t
nvdmozilla
CVE-2020-26957MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26957 [MEDIUM] CWE-665 CVE-2020-26957: OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. Th
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
nvdmozilla
CVE-2020-26953MEDIUMCVSS 4.3fixed in 83.0fixed in 832020-12-09
CVE-2020-26953 [MEDIUM] CWE-1021 CVE-2020-26953: It was possible to cause the browser to enter fullscreen mode without displaying the security UI; th
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvdmozilla
CVE-2020-26958MEDIUMCVSS 6.1fixed in 83.0fixed in 832020-12-09
CVE-2020-26958 [MEDIUM] CWE-79 CVE-2020-26958: Firefox did not block execution of scripts with incorrect MIME types when the response was intercept
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvdmozilla
CVE-2020-26967MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26967 [MEDIUM] CVE-2020-26967: When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox
When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other than those that it injected into the page. This would lead to internal errors and unexpected behavior in the Screenshots code. This vulnerability affects Firefox < 83.
nvdosvmozilla
CVE-2020-26963MEDIUMCVSS 4.3fixed in 83.0fixed in 832020-12-09
CVE-2020-26963 [MEDIUM] CVE-2020-26963: Repeated calls to the history and location interfaces could have been used to hang the browser. This
Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introducing rate-limiting to these API calls. This vulnerability affects Firefox < 83.
nvdosvmozilla
CVE-2020-6829MEDIUMCVSS 5.3fixed in 80.0≥ unspecified, < 802020-10-28
CVE-2020-6829 [MEDIUM] CVE-2020-6829: When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; wh
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
nvdmozilla
CVE-2020-15683CRITICALCVSS 9.8fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15683 [CRITICAL] CWE-416 CVE-2020-15683: Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird <
nvdmozilla
CVE-2020-15684CRITICALCVSS 9.8fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15684 [CRITICAL] CWE-416 CVE-2020-15684: Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.
nvdosvmozilla
CVE-2020-15254CRITICALCVSS 9.8≥ 0, < 82.0+build2-0ubuntu0.16.04.5≥ 0, < 82.0+build2-0ubuntu0.18.04.1+1 more2020-10-22
CVE-2020-15254 [CRITICAL] CVE-2020-15254: Crossbeam is a set of tools for concurrent programming
Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements. `Vec::from_iter` does not actually guarantee that and may allocate extra memory. The destructor of the `bounded` channel reconstructs `Vec` from the raw pointer based on the
osvmozilla
CVE-2020-15681HIGHCVSS 7.5fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15681 [HIGH] CVE-2020-15681: When multiple WASM threads had a reference to a module, and were looking up exported functions, one
When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entry in a shared stub table, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 82.
nvdosvmozilla
CVE-2020-15680MEDIUMCVSS 5.3fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15680 [MEDIUM] CVE-2020-15680: If a valid external protocol handler was referenced in an image tag, the resulting broken image size
If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered. This vulnerability affects Firefox < 82.
nvdosvmozilla