cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 62 of 162
CVE-2020-26969P3HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26969 [HIGH] CWE-787 CVE-2020-26969: Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evid Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.
nvdosv
CVE-2021-29972P3HIGHCVSS 8.8fixed in 90.0≥ unspecified, < 902021-08-05
CVE-2021-29972 [HIGH] CWE-416 CVE-2021-29972: A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Up A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. This vulnerability affects Firefox < 90.
nvdosv
CVE-2015-0829P3MEDIUMCVSS 6.8≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0829 [MEDIUM] CWE-119 CVE-2015-0829: Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
nvdosv
CVE-2022-22738P3HIGHCVSS 8.8fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22738 [HIGH] CWE-787 CVE-2022-22738: Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a hea Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2022-34468P3HIGHCVSS 8.8fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34468 [HIGH] CWE-829 CVE-2022-34468: An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascrip An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2014-8641P3HIGHCVSS 7.5v31.0v31.1.0+3 more2015-01-14
CVE-2014-8641 [HIGH] CVE-2014-8641: Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ES Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, and SeaMonkey before 2.32 allows remote attackers to execute arbitrary code via crafted track data.
nvdosv
CVE-2022-46871P3HIGHCVSS 8.8fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46871 [HIGH] CWE-1104 CVE-2022-46871: An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. T An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.
nvdosv
CVE-2021-23962P3HIGHCVSS 8.8fixed in 85.0fixed in 852021-02-26
CVE-2021-23962 [HIGH] CVE-2021-23962: Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentia Incorrect use of the '' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects Firefox < 85.
nvdosv
CVE-2022-29909P3HIGHCVSS 8.8fixed in 100.0≥ unspecified, < 1002022-12-22
CVE-2022-29909 [HIGH] CWE-276 CVE-2022-29909: Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2015-7212P3HIGHCVSS 7.5≤ 42.0v38.0+8 more2015-12-16
CVE-2015-7212 [HIGH] CWE-189 CVE-2015-7212: Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering a graphics operation that requires a large texture allocation.
nvdosv
CVE-2022-45412P3HIGHCVSS 8.8fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45412 [HIGH] CWE-59 CVE-2022-45412: When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produc When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. *This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird
nvd
CVE-2022-34481P3HIGHCVSS 8.8fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34481 [HIGH] CWE-190 CVE-2022-34481: In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occu In the nsTArray_Impl::ReplaceElementsAt() function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2023-32213P3HIGHCVSS 8.8fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32213 [HIGH] CWE-908 CVE-2023-32213: When reading a file, an uninitialized value could have been used as read limit. This vulnerability a When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2014-1541P3CRITICALCVSS 10.0≤ 29.0.1v24.0+4 more2014-06-11
CVE-2014-1541 [CRITICAL] CVE-2014-1541: Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Co Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Controller in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.
nvdosv
CVE-2016-5257P3CRITICALCVSS 9.8≤ 48.0.2v45.1.0+3 more2016-09-22
CVE-2016-5257 [CRITICAL] CWE-119 CVE-2016-5257: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2022-46881P3HIGHCVSS 8.8fixed in 106.0≥ unspecified, < 1062022-12-22
CVE-2022-46881 [HIGH] CWE-787 CVE-2022-46881: An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR <
nvd
CVE-2022-31741P3HIGHCVSS 8.8fixed in 101≥ unspecified, < 1012022-12-22
CVE-2022-31741 [HIGH] CWE-908 CVE-2022-31741: A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2022-46879P3HIGHCVSS 8.8fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46879 [HIGH] CWE-787 CVE-2022-46879: Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Moz Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 107. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affect
nvdosv
CVE-2022-0843P3HIGHCVSS 8.8fixed in 97.0≥ unspecified, < 982022-12-22
CVE-2022-0843 [HIGH] CWE-787 CVE-2022-0843: Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs p Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 98.
nvdosv
CVE-2023-23606P3HIGHCVSS 8.8fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23606 [HIGH] CWE-787 CVE-2023-23606: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109.
nvdosv
Mozilla Firefox vulnerabilities | cvebase