Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 64 of 162
CVE-2014-1531P3HIGHCVSS 8.8fixed in 29.0≥ 24.0, < 24.52014-04-30
CVE-2014-1531 [HIGH] CWE-416 CVE-2014-1531: Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla
Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that i
nvdosv
CVE-2017-5440P3CRITICALCVSS 9.8fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5440 [CRITICAL] CWE-416 CVE-2017-5440: A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 5
nvd
CVE-2009-2665P3CRITICALCVSS 10.0v3.5v3.5.1+1 more2009-08-04
CVE-2009-2665 [CRITICAL] CWE-94 CVE-2009-2665: The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox
The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.
nvd
CVE-2018-5145P3CRITICALCVSS 9.8fixed in 52.7.02018-06-11
CVE-2018-5145 [CRITICAL] CWE-119 CVE-2018-5145: Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruptio
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvd
CVE-2015-4498P3HIGHCVSS 7.5≤ 40.0.2v38.0+4 more2015-08-29
CVE-2015-4498 [HIGH] CWE-254 CVE-2015-4498: The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.
nvdosv
CVE-2017-7810P3CRITICALCVSS 9.8fixed in 56.0fixed in 52.4.0+1 more2018-06-11
CVE-2017-7810 [CRITICAL] CWE-119 CVE-2017-7810: Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2017-5454P3HIGHCVSS 7.5fixed in 53.0fixed in 52.1.0+1 more2018-06-11
CVE-2017-5454 [HIGH] CWE-200 CVE-2017-5454: A mechanism to bypass file system access protections in the sandbox to use the file picker to access
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2024-1555P3HIGHCVSS 8.3fixed in 123.0≥ unspecified, < 1232024-02-20
CVE-2024-1555 [HIGH] CWE-290 CVE-2024-1555: When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly r
When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.
nvdosv
CVE-2004-1380P4MEDIUMCVSS 5.0PoCv0.8v0.9+5 more2004-10-20
CVE-2004-1380 [MEDIUM] CVE-2004-1380: Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes
Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."
nvd
CVE-2017-7809P3CRITICALCVSS 9.8fixed in 55.0fixed in 52.3.02018-06-11
CVE-2017-7809 [CRITICAL] CWE-416 CVE-2017-7809: A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2012-1971P3CRITICALCVSS 9.3≤ 14.0v1.0+129 more2012-08-29
CVE-2012-1971 [CRITICAL] CVE-2012-1971: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after certain MethodJIT execution, and unknown
nvd
CVE-2015-2735P3CRITICALCVSS 9.3≤ 38.1.0v31.0+7 more2015-07-06
CVE-2015-2735 [CRITICAL] CWE-17 CVE-2015-2735: nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1,
nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
nvdosv
CVE-2004-0904P3CRITICALCVSS 10.0v0.8v0.9+3 more2004-12-31
CVE-2004-0904 [CRITICAL] CVE-2004-0904: Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
nvd
CVE-2013-1720P3MEDIUMCVSS 6.8≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1720 [MEDIUM] CWE-119 CVE-2013-1720: The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox
The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffe
nvd
CVE-2018-5112P3HIGHCVSS 7.5≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5112 [HIGH] CWE-552 CVE-2018-5112: Development Tools panels of an extension are required to load URLs for the panels as relative URLs f
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnera
nvdosv
CVE-2025-10534P3HIGHCVSS 8.1fixed in 143.02025-09-16
CVE-2025-10534 [HIGH] CWE-79 CVE-2025-10534: Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Th
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-8030P3HIGHCVSS 8.1fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8030 [HIGH] CWE-94 CVE-2025-8030: Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into e
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvd
CVE-2011-0076P3HIGHCVSS 7.5v3.6v3.6.2+101 more2011-05-07
CVE-2011-0076 [HIGH] CVE-2011-0076: Unspecified vulnerability in the Java Embedding Plugin (JEP) in Mozilla Firefox before 3.5.19 and 3.
Unspecified vulnerability in the Java Embedding Plugin (JEP) in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, on Mac OS X allows remote attackers to bypass intended access restrictions via unknown vectors.
nvd
CVE-2017-5386P3HIGHCVSS 7.3fixed in 51.0fixed in 45.7.0+1 more2018-06-11
CVE-2017-5386 [HIGH] CVE-2017-5386: WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions usi
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.
nvd
CVE-2026-0878P3HIGHCVSS 8.0fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0878 [HIGH] CWE-20 CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vul
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvd