Mozilla Firefox vulnerabilities

3,148 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70

Vulnerabilities

Page 64 of 158
CVE-2018-18500CRITICALCVSS 9.8fixed in 65.02019-02-05
CVE-2018-18500 [CRITICAL] CWE-416 CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML e A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
nvdosv
CVE-2018-18504CRITICALCVSS 9.8fixed in 65.02019-02-05
CVE-2018-18504 [CRITICAL] CWE-125 CVE-2018-18504: A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is st A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This results is a potentially exploitable crash and the possibility of reading from the memory of the freed buffers. This vulnerability affects Firefox < 65.
nvdosv
CVE-2018-18501CRITICALCVSS 9.8fixed in 65.0≥ unspecified, < 652019-02-05
CVE-2018-18501 [CRITICAL] CWE-119 CVE-2018-18501: Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox <
nvd
CVE-2018-18505CRITICALCVSS 10.0fixed in 60.5.0fixed in 65.02019-02-05
CVE-2018-18505 [CRITICAL] CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authenti An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later chann
nvd
CVE-2018-18503HIGHCVSS 8.8fixed in 65.0≥ unspecified, < 652019-02-05
CVE-2018-18503 [HIGH] CWE-119 CVE-2018-18503: When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash ma When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < 65.
nvdosv
CVE-2018-18506MEDIUMCVSS 5.9fixed in 65.0≥ unspecified, < 652019-02-05
CVE-2018-18506 [MEDIUM] CVE-2018-18506: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file o When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attack
nvd
CVE-2018-5156CRITICALCVSS 9.8fixed in 52.9.0fixed in 61.0+2 more2018-10-18
CVE-2018-5156 [CRITICAL] CWE-20 CVE-2018-5156: A vulnerability can occur when capturing a media stream when the media source type is changed as the A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvdosv
CVE-2018-12387CRITICALCVSS 9.1fixed in 60.2.2fixed in 62.0.3+1 more2018-10-18
CVE-2018-12387 [CRITICAL] CWE-20 CVE-2018-12387: A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple argumen A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2
nvd
CVE-2018-12378CRITICALCVSS 9.8fixed in 60.2.0fixed in 62.0+1 more2018-10-18
CVE-2018-12378 [CRITICAL] CWE-416 CVE-2018-12378: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by Ja A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2018-5186CRITICALCVSS 9.8fixed in 61.0≥ unspecified, < 612018-10-18
CVE-2018-5186 [CRITICAL] CWE-119 CVE-2018-5186: Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption an Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 61.
nvdosv
CVE-2018-12377CRITICALCVSS 9.8fixed in 60.2.0fixed in 62.0+1 more2018-10-18
CVE-2018-12377 [CRITICAL] CWE-416 CVE-2018-12377: A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstan A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2018-12376CRITICALCVSS 9.8fixed in 60.2.0fixed in 62.0+1 more2018-10-18
CVE-2018-12376 [CRITICAL] CWE-119 CVE-2018-12376: Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2018-5188CRITICALCVSS 9.8fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-5188 [CRITICAL] CWE-119 CVE-2018-5188: Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs s Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefo
nvd
CVE-2018-12369CRITICALCVSS 9.8fixed in 60.1.0fixed in 61.0+1 more2018-10-18
CVE-2018-12369 [CRITICAL] CWE-863 CVE-2018-12369: WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.
nvdosv
CVE-2018-5187CRITICALCVSS 9.8fixed in 60.1.0fixed in 61.0+1 more2018-10-18
CVE-2018-5187 [CRITICAL] CWE-119 CVE-2018-5187: Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of m Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd
CVE-2018-12370HIGHCVSS 8.8fixed in 61.0≥ unspecified, < 612018-10-18
CVE-2018-12370 [HIGH] CWE-352 CVE-2018-12370: In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61.
nvdosv
CVE-2018-12368HIGHCVSS 8.1fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-12368 [HIGH] CVE-2018-12368: Windows 10 does not warn users before opening executable files with the SettingContent-ms extension Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable. This also allows a WebExtension with the limited downloads.open per
nvd
CVE-2018-12375HIGHCVSS 8.8fixed in 62.0≥ unspecified, < 622018-10-18
CVE-2018-12375 [HIGH] CWE-119 CVE-2018-12375: Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption an Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62.
nvdosv
CVE-2018-12379HIGHCVSS 7.8fixed in 60.2.0fixed in 62.0+1 more2018-10-18
CVE-2018-12379 [HIGH] CWE-787 CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2
nvd
CVE-2018-12361HIGHCVSS 8.8fixed in 61.0≥ unspecified, < 612018-10-18
CVE-2018-12361 [HIGH] CWE-190 CVE-2018-12361: An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd