Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 54 of 162
CVE-2019-17012P3HIGHCVSS 8.8fixed in 71.0vbefore 712020-01-08
CVE-2019-17012 [HIGH] CWE-787 CVE-2019-17012: Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of t
Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2011-2373P3HIGHCVSS 7.6≤ 3.6.17v1.0+105 more2011-06-30
CVE-2011-2373 [HIGH] CWE-399 CVE-2011-2373: Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when JavaScript is disabled, allows remote attackers to execute arbitrary code via a crafted XUL document.
nvd
CVE-2020-12420P3HIGHCVSS 8.8fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12420 [HIGH] CWE-362 CVE-2020-12420: When trying to connect to a STUN server, a race condition could have caused a use-after-free of a po
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2008-4059P3HIGHCVSS 7.5≤ 2.0.0.17v0.8+55 more2008-09-24
CVE-2008-4059 [HIGH] CWE-264 CVE-2008-4059: The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNa
The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.
nvd
CVE-2019-11746P3HIGHCVSS 8.8fixed in 60.9.0fixed in 69.0+1 more2019-09-27
CVE-2019-11746 [HIGH] CWE-416 CVE-2019-11746: A use-after-free vulnerability can occur while manipulating video elements if the body is freed whil
A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
nvd
CVE-2012-3959P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3959 [CRITICAL] CWE-416 CVE-2012-3959: Use-after-free vulnerability in the nsRangeUpdater::SelAdjDeleteNode function in Mozilla Firefox bef
Use-after-free vulnerability in the nsRangeUpdater::SelAdjDeleteNode function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified ve
nvd
CVE-2019-11711P3HIGHCVSS 8.8fixed in 60.8.0fixed in 68.0+1 more2019-07-23
CVE-2019-11711 [HIGH] CVE-2019-11711: When an inner window is reused, it does not consider the use of document.domain for cross-origin pro
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vul
nvd
CVE-2007-1362P4MEDIUMCVSS 4.3PoCv1.5.0.1v1.5.0.2+21 more2007-06-01
CVE-2007-1362 [MEDIUM] CWE-20 CVE-2007-1362: Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a misinterpretation of cookie data, aka "Path Abuse
nvd
CVE-2008-4060P3HIGHCVSS 7.5≤ 2.0.0.16v0.8+48 more2008-09-24
CVE-2008-4060 [HIGH] CWE-264 CVE-2008-4060: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey bef
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.
nvd
CVE-2019-11764P3HIGHCVSS 8.8fixed in 70.0vbefore 702020-01-08
CVE-2019-11764 [HIGH] CWE-787 CVE-2019-11764: Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2021-29970P3HIGHCVSS 8.8fixed in 90.0≥ unspecified, < 902021-08-05
CVE-2021-29970 [HIGH] CWE-416 CVE-2021-29970: A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially expl
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
nvd
CVE-2012-5838P3CRITICALCVSS 9.3fixed in 10.0.11fixed in 17.02012-11-21
CVE-2012-5838 [CRITICAL] CWE-119 CVE-2012-5838: The copyTexImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Thunderbird
The copyTexImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via large image dimensions.
nvd
CVE-2021-29988P3HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29988 [HIGH] CWE-125 CVE-2021-29988: Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of b
Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2019-11757P3HIGHCVSS 8.8fixed in 70.0vbefore 702020-01-08
CVE-2019-11757 [HIGH] CWE-416 CVE-2019-11757: When following the value's prototype chain, it was possible to retain a reference to a locale, delet
When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2011-2368P3CRITICALCVSS 10.0v4.0v4.0.12011-06-30
CVE-2011-2368 [CRITICAL] CWE-264 CVE-2011-2368: The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write opera
The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2019-11758P3HIGHCVSS 8.8fixed in 69.0vbefore 692020-01-08
CVE-2019-11758 [HIGH] CWE-787 CVE-2019-11758: Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total S
Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Fi
nvd
CVE-2020-26959P3HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26959 [HIGH] CWE-416 CVE-2020-26959: During browser shutdown, reference decrementing could have occured on a previously freed object, res
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2018-18496P3HIGHCVSS 8.8fixed in 64.0≥ unspecified, < 642019-02-28
CVE-2018-18496 [HIGH] CWE-1021 CVE-2018-18496: When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This
nvd
CVE-2020-15670P3HIGHCVSS 8.8fixed in 80.0≥ unspecified, < 802020-10-01
CVE-2020-15670 [HIGH] CWE-362 CVE-2020-15670: Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.
nvdosv
CVE-2019-11751P3HIGHCVSS 8.8fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11751 [HIGH] CWE-88 CVE-2019-11751: Logging-related command line parameters are not properly sanitized when Firefox is launched by anoth
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. *Note: this issue only affects Firefox on Windows operating systems.*. Th
nvd