Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 56 of 162
CVE-2016-1944P3CRITICALCVSS 9.8v43.0.42016-01-31
CVE-2016-1944 [CRITICAL] CWE-119 CVE-2016-1944: The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might a
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvdosv
CVE-2009-1838P3CRITICALCVSS 9.3≤ 3.0.10v0.1+89 more2009-06-12
CVE-2009-1838 [CRITICAL] CWE-94 CVE-2009-1838: The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22,
The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for th
nvd
CVE-2018-5155P3CRITICALCVSS 9.8fixed in 52.8.0fixed in 60.0+1 more2018-06-11
CVE-2018-5155 [CRITICAL] CWE-416 CVE-2018-5155: A use-after-free vulnerability can occur while adjusting layout during SVG animations with text path
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvd
CVE-2013-5613P3CRITICALCVSS 9.8fixed in 26.0≥ 24.0, < 24.22013-12-11
CVE-2013-5613 [CRITICAL] CWE-416 CVE-2013-5613: Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox be
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related
nvd
CVE-2011-0061P3CRITICALCVSS 9.3v3.6v3.6.2+10 more2011-03-02
CVE-2011-0061 [CRITICAL] CWE-119 CVE-2011-0061: Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey befo
Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.
nvd
CVE-2010-2767P3CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2767 [CRITICAL] CWE-399 CVE-2010-2767: The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunde
The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via craft
nvd
CVE-2017-7819P3CRITICALCVSS 9.8fixed in 52.4.0fixed in 56.0+1 more2018-06-11
CVE-2017-7819 [CRITICAL] CWE-416 CVE-2017-7819: A use-after-free vulnerability can occur in design mode when image objects are resized if objects re
A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2015-0818P3HIGHCVSS 7.5≤ 36.0.3v31.0+5 more2015-03-24
CVE-2015-0818 [HIGH] CWE-264 CVE-2015-0818: Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow rem
Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving SVG hash navigation.
nvdosv
CVE-2017-7826P3CRITICALCVSS 9.8fixed in 57.0fixed in 52.5.0+1 more2018-06-11
CVE-2017-7826 [CRITICAL] CWE-119 CVE-2017-7826: Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvdosv
CVE-2018-5089P3CRITICALCVSS 9.8fixed in 52.6.0≤ 58.0+1 more2018-06-11
CVE-2018-5089 [CRITICAL] CWE-119 CVE-2018-5089: Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2006-4310P4MEDIUMCVSS 4.3PoCv1.5.0.62006-08-23
CVE-2006-4310 [MEDIUM] CWE-20 CVE-2006-4310: Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted F
Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI.
nvd
CVE-2017-7843P3HIGHCVSS 7.5fixed in 57.0.1fixed in 52.5.2+1 more2018-06-11
CVE-2017-7843 [HIGH] CWE-200 CVE-2017-7843: When Private Browsing mode is used, it is possible for a web worker to write persistent data to Inde
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox E
nvd
CVE-2020-12387P3HIGHCVSS 8.1fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12387 [HIGH] CWE-362 CVE-2020-12387: A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. Th
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
nvd
CVE-2018-12376P3CRITICALCVSS 9.8fixed in 60.2.0fixed in 62.0+1 more2018-10-18
CVE-2018-12376 [CRITICAL] CWE-119 CVE-2018-12376: Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2017-5401P3CRITICALCVSS 9.8fixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5401 [CRITICAL] CWE-388 CVE-2017-5401: A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a l
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2021-29986P3HIGHCVSS 8.1fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29986 [HIGH] CWE-362 CVE-2021-29986: A suspected race condition when calling getaddrinfo led to memory corruption and a potentially explo
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2018-5187P3CRITICALCVSS 9.8fixed in 60.1.0fixed in 61.0+1 more2018-10-18
CVE-2018-5187 [CRITICAL] CWE-119 CVE-2018-5187: Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of m
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd
CVE-2017-7751P3CRITICALCVSS 9.8fixed in 54.0fixed in 52.2.0+1 more2018-06-11
CVE-2017-7751 [CRITICAL] CWE-416 CVE-2017-7751: A use-after-free vulnerability with content viewer listeners that results in a potentially exploitab
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2009-1312P4MEDIUMCVSS 4.3PoC≤ 3.0.8v0.1+79 more2009-04-22
CVE-2009-1312 [MEDIUM] CWE-16 CVE-2009-1312: Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers i
Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and
nvd
CVE-2013-0778P3CRITICALCVSS 9.3fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0778 [CRITICAL] CWE-125 CVE-2013-0778: The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3,
The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd