Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 55 of 162
CVE-2015-7210P3HIGHCVSS 7.5≤ 42.0v38.0+8 more2015-12-16
CVE-2015-7210 [HIGH] CVE-2015-7210: Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows
Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering attempted use of a data channel that has been closed by a WebRTC function.
nvdosv
CVE-2013-0769P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0769 [CRITICAL] CVE-2013-0769: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or po
nvd
CVE-2021-29981P3HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29981 [HIGH] CVE-2021-29981: An issue present in lowering/register allocation could have led to obscure but deterministic registe
An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a potentially exploitable crash. This vulnerability affects Firefox < 91 and Thunderbird < 91.
nvdosv
CVE-2018-6156P3HIGHCVSS 8.8≥ 0, < 70.0+build2-0ubuntu0.16.04.1≥ 0, < 70.0+build2-0ubuntu0.18.04.12019-06-27
CVE-2018-6156 [HIGH] CVE-2018-6156: Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68
Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
osv
CVE-2018-5095P3CRITICALCVSS 9.8fixed in 58.0fixed in 52.6.0+1 more2018-06-11
CVE-2018-5095 [CRITICAL] CWE-190 CVE-2018-5095: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2012-0464P3HIGHCVSS 7.5≤ 3.6.27≥ 4.0, ≤ 10.0+3 more2012-03-14
CVE-2012-0464 [HIGH] CWE-399 CVE-2012-0464: Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through
Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join f
nvd
CVE-2023-29539P3HIGHCVSS 8.8fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29539 [HIGH] CWE-476 CVE-2023-29539: When handling the filename directive in the Content-Disposition header, the filename would be trunca
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for An
nvd
CVE-2023-25745P3HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25745 [HIGH] CWE-787 CVE-2023-25745: Memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110.
nvdosv
CVE-2023-6213P3HIGHCVSS 8.8fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6213 [HIGH] CWE-787 CVE-2023-6213: Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120.
nvdosv
CVE-2022-31740P3HIGHCVSS 8.8fixed in 101.0≥ unspecified, < 1012022-12-22
CVE-2022-31740 [HIGH] CWE-119 CVE-2022-31740: On arm64, WASM code could have resulted in incorrect assembly generation leading to a register alloc
On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2023-37212P3HIGHCVSS 8.8fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37212 [HIGH] CWE-787 CVE-2023-37212: Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115.
nvdosv
CVE-2017-5396P3CRITICALCVSS 9.8fixed in 51.0fixed in 45.7.0+1 more2018-06-11
CVE-2017-5396 [CRITICAL] CWE-416 CVE-2017-5396: A use-after-free vulnerability in the Media Decoder when working with media files when some events a
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2024-6609P3HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6609 [HIGH] CVE-2024-6609: When almost out-of-memory an elliptic curve key which was never allocated could have been freed agai
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvd
CVE-2023-28177P3HIGHCVSS 8.8fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28177 [HIGH] CWE-787 CVE-2023-28177: Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111.
nvdosv
CVE-2016-5276P3CRITICALCVSS 9.8≤ 48.0.2v45.1.0+3 more2016-09-22
CVE-2016-5276 [CRITICAL] CWE-416 CVE-2016-5276: Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function i
Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute.
nvd
CVE-2013-0795P3CRITICALCVSS 10.0≤ 19.0.2v19.0+6 more2013-04-03
CVE-2013-0795 [CRITICAL] CWE-264 CVE-2013-0795: The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before
The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 does not prevent use of the cloneNode method for cloning a protected node, which allows remote attackers to bypass the Same Origin Policy or possibly exe
nvd
CVE-2015-0804P3HIGHCVSS 7.5≤ 36.0.42015-04-01
CVE-2015-0804 [HIGH] CWE-264 CVE-2015-0804: The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrai
The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element.
nvdosv
CVE-2025-1014P3HIGHCVSS 8.8fixed in 128.7.0fixed in 135.02025-02-04
CVE-2025-1014 [HIGH] CWE-295 CVE-2025-1014: Certificate length was not properly checked when added to a certificate store. In practice only trus
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2024-6605P3HIGHCVSS 8.8fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6605 [HIGH] CWE-277 CVE-2024-6605: Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjac
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
nvd
CVE-2017-5398P3CRITICALCVSS 9.8fixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5398 [CRITICAL] CWE-119 CVE-2017-5398: Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory c
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvdosv