Mozilla Firefox vulnerabilities

3,148 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70

Vulnerabilities

Page 54 of 158
CVE-2020-12395CRITICALCVSS 9.8fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12395 [CRITICAL] CWE-787 CVE-2020-12395: Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird <
nvdmozilla
CVE-2020-12396CRITICALCVSS 9.8fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12396 [CRITICAL] CWE-787 CVE-2020-12396: Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 76.
nvdosvmozilla
CVE-2020-12393HIGHCVSS 7.8fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12393 [HIGH] CWE-78 CVE-2020-12393: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a req The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows
nvdmozilla
CVE-2020-12391HIGHCVSS 7.5fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12391 [HIGH] CWE-863 CVE-2020-12391: Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating con Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin. This vulnerability affects Firefox < 76.
nvdosvmozilla
CVE-2020-12387HIGHCVSS 8.1fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12387 [HIGH] CWE-362 CVE-2020-12387: A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. Th A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
nvdmozilla
CVE-2020-6830HIGHCVSS 7.5fixed in 25.02020-05-26
CVE-2020-6830 [HIGH] CWE-200 CVE-2020-6830: For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code ca For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.
nvdmozilla
CVE-2020-12392MEDIUMCVSS 5.5fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12392 [MEDIUM] CWE-22 CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and
nvdmozilla
CVE-2020-12394LOWCVSS 3.3fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12394 [LOW] CVE-2020-12394: A logic flaw in our location bar implementation could have allowed a local attacker to spoof the cur A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.
nvdosvmozilla
CVE-2020-6823CRITICALCVSS 9.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6823 [CRITICAL] CWE-862 CVE-2020-6823: A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling A malicious extension could have called browser.identity.launchWebAuthFlow, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.
nvdosvmozilla
CVE-2020-6825CRITICALCVSS 9.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6825 [CRITICAL] CWE-787 CVE-2020-6825: Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bug Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0
nvdmozilla
CVE-2020-6826CRITICALCVSS 9.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6826 [CRITICAL] CWE-787 CVE-2020-6826: Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 75.
nvdosvmozilla
CVE-2020-6819HIGHCVSS 8.1KEVfixed in 68.6.1fixed in 74.0.1+1 more2020-04-24
CVE-2020-6819 [HIGH] CWE-362 CVE-2020-6819: Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-a Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
nvdmozilla
CVE-2020-6821HIGHCVSS 7.5fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6821 [HIGH] CWE-908 CVE-2020-6821: When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSub When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvdosvmozilla
CVE-2020-6820HIGHCVSS 8.1KEVfixed in 68.6.1fixed in 74.0.1+1 more2020-04-24
CVE-2020-6820 [HIGH] CWE-362 CVE-2020-6820: Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-fre Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
nvdmozilla
CVE-2020-6822HIGHCVSS 8.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6822 [HIGH] CWE-787 CVE-2020-6822: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvdmozilla
CVE-2020-6824LOWCVSS 2.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6824 [LOW] CWE-384 CVE-2020-6824: Initially, a user opens a Private Browsing Window and generates a password for a site, then closes t Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This
nvdosvmozilla
CVE-2020-6814CRITICALCVSS 9.8fixed in 74.0≥ unspecified, < 74+1 more2020-03-25
CVE-2020-6814 [CRITICAL] CWE-787 CVE-2020-6814: Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of thes Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvdmozilla
CVE-2020-6815CRITICALCVSS 9.8fixed in 74.0≥ unspecified, < 742020-03-25
CVE-2020-6815 [CRITICAL] CWE-787 CVE-2020-6815: Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of thes Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or escalation of privilege and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 74.
nvdosvmozilla
CVE-2020-6805HIGHCVSS 8.8fixed in 74.0≥ unspecified, < 74+1 more2020-03-25
CVE-2020-6805 [HIGH] CWE-416 CVE-2020-6805: When removing data about an origin whose tab was recently closed, a use-after-free could occur in th When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvdmozilla
CVE-2020-6809HIGHCVSS 7.5fixed in 74.0≥ unspecified, < 742020-03-25
CVE-2020-6809 [HIGH] CVE-2020-6809: When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-o When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.
nvdosvmozilla