Mozilla Firefox vulnerabilities

3,148 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70

Vulnerabilities

Page 60 of 158
CVE-2019-11727MEDIUMCVSS 5.3fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11727 [MEDIUM] CWE-295 CVE-2019-11727: A vulnerability exists where it possible to force Network Security Services (NSS) to sign Certificat A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.
nvd
CVE-2019-11730MEDIUMCVSS 6.5fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11730 [MEDIUM] CVE-2019-11730: A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in comb
nvd
CVE-2019-11720MEDIUMCVSS 6.1fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11720 [MEDIUM] CWE-79 CVE-2019-11720: Some unicode characters are incorrectly treated as whitespace during the parsing of web content inst Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.
nvdosv
CVE-2019-11695MEDIUMCVSS 4.3fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11695 [MEDIUM] CVE-2019-11695: A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts, doorhanger notifications, or other buttons inadvertently if the location is spoofed
nvdosv
CVE-2019-11728MEDIUMCVSS 4.7fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11728 [MEDIUM] CWE-668 CVE-2019-11728: The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.
nvdosv
CVE-2019-11717MEDIUMCVSS 5.3fixed in 60.8.0fixed in 68.0+1 more2019-07-23
CVE-2019-11717 [MEDIUM] CWE-116 CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2019-11702MEDIUMCVSS 6.5fixed in 67.0.2≥ unspecified, < 67.0.22019-07-23
CVE-2019-11702 [MEDIUM] CWE-862 CVE-2019-11702: A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.
nvd
CVE-2019-11699MEDIUMCVSS 6.5fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11699 [MEDIUM] CVE-2019-11699: A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addres A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. This vulnerability affects Firefox < 67.
nvdosv
CVE-2019-11715MEDIUMCVSS 6.1fixed in 60.8.0fixed in 68.0+1 more2019-07-23
CVE-2019-11715 [MEDIUM] CWE-79 CVE-2019-11715: Due to an error while parsing page content, it is possible for properly sanitized user input to be m Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2019-11718MEDIUMCVSS 5.3fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11718 [MEDIUM] CWE-74 CVE-2019-11718: Activity Stream can display content from sent from the Snippet Service website. This content is writ Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Fire
nvdosv
CVE-2019-11724MEDIUMCVSS 6.1fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11724 [MEDIUM] CWE-863 CVE-2019-11724: Application permissions give additional remote troubleshooting permission to the site input.mozilla. Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability affects Firefox < 68.
nvdosv
CVE-2019-11697MEDIUMCVSS 6.5fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11697 [MEDIUM] CWE-20 CVE-2019-11697: If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extensi If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious exten
nvdosv
CVE-2019-9817MEDIUMCVSS 5.3fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9817 [MEDIUM] CWE-346 CVE-2019-9817: Images from a different domain can be read using a canvas object in some circumstances. This could b Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2019-11721MEDIUMCVSS 6.5fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11721 [MEDIUM] CVE-2019-11721: The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. T The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.
nvdosv
CVE-2019-11701MEDIUMCVSS 6.1fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11701 [MEDIUM] CWE-79 CVE-2019-11701: The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) a The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.
nvdosv
CVE-2019-11698MEDIUMCVSS 5.3fixed in 60.7.0fixed in 67.0+1 more2019-07-23
CVE-2019-11698 [MEDIUM] CWE-20 CVE-2019-11698: If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookm If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This
nvd
CVE-2019-11725MEDIUMCVSS 6.5fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11725 [MEDIUM] CVE-2019-11725: When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are display When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68.
nvdosv
CVE-2019-11700MEDIUMCVSS 6.5fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11700 [MEDIUM] CWE-862 CVE-2019-11700: A hyperlink using the res: protocol can be used to open local files at a known location in Internet A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.
nvd
CVE-2019-9816MEDIUMCVSS 5.9PoCfixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9816 [MEDIUM] CWE-843 CVE-2019-9816: A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbi
nvd
CVE-2018-6156HIGHCVSS 8.8≥ 0, < 70.0+build2-0ubuntu0.16.04.1≥ 0, < 70.0+build2-0ubuntu0.18.04.12019-06-27
CVE-2018-6156 [HIGH] CVE-2018-6156: Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68 Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
osv