Mozilla Firefox vulnerabilities
3,148 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70
Vulnerabilities
Page 62 of 158
CVE-2018-5124MEDIUMCVSS 6.1fixed in 58.0.1vAll versions prior to Firefox 58.0.12019-04-26
CVE-2018-5124 [MEDIUM] CWE-79 CVE-2018-5124: Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code exec
Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.
nvdosv
CVE-2019-9807MEDIUMCVSS 4.3fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9807 [MEDIUM] CWE-20 CVE-2019-9807: When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to
When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66.
nvdosv
CVE-2019-9797MEDIUMCVSS 5.3fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9797 [MEDIUM] CWE-346 CVE-2019-9797: Cross-origin images can be read in violation of the same-origin policy by exporting an image after u
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.
nvd
CVE-2019-9793MEDIUMCVSS 5.9fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9793 [MEDIUM] CWE-119 CVE-2019-9793: A mechanism was discovered that removes some bounds checking for string, array, or typed array acces
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have
nvd
CVE-2018-18511MEDIUMCVSS 4.3v65.0≥ unspecified, < 65.0.12019-04-26
CVE-2018-18511 [MEDIUM] CWE-200 CVE-2018-18511: Cross-origin images can be read from a canvas element in violation of the same-origin policy using t
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
nvd
CVE-2018-18510MEDIUMCVSS 6.5fixed in 64.0≥ unspecified, < 642019-04-26
CVE-2018-18510 [MEDIUM] CVE-2018-18510: The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are
The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.
nvdosv
CVE-2019-9808MEDIUMCVSS 5.3fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9808 [MEDIUM] CWE-346 CVE-2019-9808: If WebRTC permission is requested from documents with data: or blob: URLs, the permission notificati
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66.
nvdosv
CVE-2017-7774CRITICALCVSS 9.1fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7774 [CRITICAL] CWE-125 CVE-2017-7774: Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite functi
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
nvd
CVE-2017-7776HIGHCVSS 8.1fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7776 [HIGH] CWE-125 CVE-2017-7776: Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getCla
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
nvd
CVE-2017-7777HIGHCVSS 8.8fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7777 [HIGH] CWE-119 CVE-2017-7777: Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Load
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
nvd
CVE-2017-7771HIGHCVSS 8.1fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7771 [HIGH] CWE-125 CVE-2017-7771: Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
nvd
CVE-2017-7773HIGHCVSS 8.8fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7773 [HIGH] CWE-119 CVE-2017-7773: Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/De
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
nvd
CVE-2017-7772HIGHCVSS 8.8fixed in 54.0vAll versions prior to Firefox 542019-04-12
CVE-2017-7772 [HIGH] CWE-119 CVE-2017-7772: Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
nvd
CVE-2018-12390CRITICALCVSS 9.8fixed in 60.3.0fixed in 63.0+1 more2019-02-28
CVE-2018-12390 [CRITICAL] CWE-119 CVE-2018-12390: Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 6
nvd
CVE-2018-18498CRITICALCVSS 9.8fixed in 64.0≥ unspecified, < 642019-02-28
CVE-2018-18498 [CRITICAL] CWE-190 CVE-2018-18498: A potential vulnerability leading to an integer overflow can occur during buffer size calculations f
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2018-12405CRITICALCVSS 9.8fixed in 60.4.0fixed in 64.0+1 more2019-02-28
CVE-2018-12405 [CRITICAL] CWE-119 CVE-2018-12405: Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox <
nvdosv
CVE-2018-12392CRITICALCVSS 9.8fixed in 60.3.0fixed in 63.0+1 more2019-02-28
CVE-2018-12392 [CRITICAL] CVE-2018-12392: When manipulating user events in nested loops while opening a document through script, it is possibl
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
nvd
CVE-2018-12407CRITICALCVSS 9.8fixed in 64.0≥ unspecified, < 642019-02-28
CVE-2018-12407 [CRITICAL] CWE-119 CVE-2018-12407: A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.
nvdosv
CVE-2018-18493CRITICALCVSS 9.8fixed in 60.4.0fixed in 64.0+1 more2019-02-28
CVE-2018-18493 [CRITICAL] CWE-119 CVE-2018-18493: A buffer overflow can occur in the Skia library during buffer offset calculations with hardware acce
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2018-18492CRITICALCVSS 9.8fixed in 60.4.0fixed in 64.0+1 more2019-02-28
CVE-2018-18492 [CRITICAL] CWE-416 CVE-2018-18492: A use-after-free vulnerability can occur after deleting a selection element due to a weak reference
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd