Mozilla Firefox vulnerabilities

3,148 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70

Vulnerabilities

Page 67 of 158
CVE-2018-5089CRITICALCVSS 9.8fixed in 52.6.0≤ 58.0+1 more2018-06-11
CVE-2018-5089 [CRITICAL] CWE-119 CVE-2018-5089: Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evide Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvdosv
CVE-2017-7778CRITICALCVSS 9.8fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7778 [CRITICAL] CWE-119 CVE-2017-7778: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2017-5410CRITICALCVSS 9.8fixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5410 [CRITICAL] CWE-119 CVE-2017-5410: Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScri Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-7810CRITICALCVSS 9.8fixed in 56.0fixed in 52.4.0+1 more2018-06-11
CVE-2017-7810 [CRITICAL] CWE-119 CVE-2017-7810: Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evide Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2018-5104CRITICALCVSS 9.8fixed in 58.0fixed in 52.6.0+1 more2018-06-11
CVE-2018-5104 [CRITICAL] CWE-416 CVE-2018-5104: A use-after-free vulnerability can occur during font face manipulation when a font face is freed whi A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2017-5413CRITICALCVSS 9.8fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5413 [CRITICAL] CWE-119 CVE-2017-5413: A segmentation fault can occur during some bidirectional layout operations. This vulnerability affec A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2017-7793CRITICALCVSS 9.8fixed in 56.0fixed in 52.4.0+1 more2018-06-11
CVE-2017-7793 [CRITICAL] CWE-416 CVE-2017-7793: A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window a A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvdosv
CVE-2017-5434CRITICALCVSS 9.8fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5434 [CRITICAL] CWE-416 CVE-2017-5434: A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-5096CRITICALCVSS 9.8fixed in 52.6.02018-06-11
CVE-2018-5096 [CRITICAL] CWE-416 CVE-2018-5096: A use-after-free vulnerability can occur while editing events in form elements on a page, resulting A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.
nvd
CVE-2017-7802CRITICALCVSS 9.8fixed in 55.0fixed in 52.3.0+1 more2018-06-11
CVE-2017-7802 [CRITICAL] CWE-416 CVE-2017-7802: A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an ima A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements are accessed. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2018-5092CRITICALCVSS 9.8≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5092 [CRITICAL] CWE-416 CVE-2018-5092: A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prema A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread while cancelling fetch operations. This vulnerability affects Firefox < 58.
nvdosv
CVE-2017-5374CRITICALCVSS 9.8fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5374 [CRITICAL] CWE-119 CVE-2017-5374: Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corru Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 51.
nvdosv
CVE-2018-5147CRITICALCVSS 9.8fixed in 52.7.2fixed in 59.0.12018-06-11
CVE-2018-5147 [CRITICAL] CVE-2018-5147: The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place o The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
nvd
CVE-2018-5148CRITICALCVSS 9.8fixed in 59.0.2fixed in 52.7.3+1 more2018-06-11
CVE-2018-5148 [CRITICAL] CWE-416 CVE-2018-5148: A use-after-free vulnerability can occur in the compositor during certain graphics operations when a A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
nvd
CVE-2016-9080CRITICALCVSS 9.8fixed in 50.1≥ unspecified, < 50.12018-06-11
CVE-2016-9080 [CRITICAL] CWE-119 CVE-2016-9080: Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory cor Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1.
nvdosv
CVE-2018-5126CRITICALCVSS 9.8fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5126 [CRITICAL] CWE-119 CVE-2018-5126: Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 59.
nvdosv
CVE-2017-7827CRITICALCVSS 9.8≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7827 [CRITICAL] CWE-119 CVE-2017-7827: Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57.
nvdosv
CVE-2017-7800CRITICALCVSS 9.8fixed in 55.0fixed in 52.3.0+1 more2018-06-11
CVE-2017-7800 [CRITICAL] CWE-416 CVE-2017-7800: A use-after-free vulnerability can occur in WebSockets when the object holding the connection is fre A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-5441CRITICALCVSS 9.8fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5441 [CRITICAL] CWE-416 CVE-2017-5441: A use-after-free vulnerability when holding a selection during scroll events. This results in a pote A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-5145CRITICALCVSS 9.8fixed in 52.7.02018-06-11
CVE-2018-5145 [CRITICAL] CWE-119 CVE-2018-5145: Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruptio Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvd