Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 68 of 162
CVE-2009-3072P3CRITICALCVSS 10.0≤ 3.0.13v0.1+94 more2009-09-10
CVE-2009-3072 [CRITICAL] CVE-2009-3072: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/stre
nvd
CVE-2018-5100P3HIGHCVSS 7.5≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5100 [HIGH] CWE-416 CVE-2018-5100: A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" func
A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.
nvdosv
CVE-2018-12375P3HIGHCVSS 8.8fixed in 62.0≥ unspecified, < 622018-10-18
CVE-2018-12375 [HIGH] CWE-119 CVE-2018-12375: Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption an
Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62.
nvdosv
CVE-2020-12426P3HIGHCVSS 8.8fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12426 [HIGH] CWE-787 CVE-2020-12426: Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of
Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 78.
nvdosv
CVE-2020-6796P3HIGHCVSS 8.8fixed in 73.0≥ unspecified, < 73+1 more2020-03-02
CVE-2020-6796 [HIGH] CWE-787 CVE-2020-6796: A content process could have modified shared memory relating to crash reporting information, crash i
A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 73 and Firefox < ESR68.5.
nvd
CVE-2013-1701P3CRITICALCVSS 10.0v17.0v17.0.1+13 more2013-08-07
CVE-2013-1701 [CRITICAL] CVE-2013-1701: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2021-38504P3HIGHCVSS 8.8fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-38504 [HIGH] CWE-416 CVE-2021-38504: When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-aft
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2015-4475P3HIGHCVSS 7.5≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4475 [HIGH] CWE-119 CVE-2015-4475: The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mish
The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
nvdosv
CVE-2019-11756P3HIGHCVSS 8.8fixed in 71.0vbefore 712020-01-08
CVE-2019-11756 [HIGH] CWE-416 CVE-2019-11756: Improper refcounting of soft token session objects could cause a use-after-free and crash (likely li
Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.
nvdosv
CVE-2016-5283P3HIGHCVSS 8.8≤ 48.0.22016-09-22
CVE-2016-5283 [HIGH] CWE-284 CVE-2016-5283: Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted f
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.
nvdosv
CVE-2011-3660P3CRITICALCVSS 10.0v4.0v4.0.1+8 more2011-12-21
CVE-2011-3660 [CRITICAL] CVE-2011-3660: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thund
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageE
nvd
CVE-2011-2996P3CRITICALCVSS 10.0v3.6v3.6.2+19 more2011-09-29
CVE-2011-2996 [CRITICAL] CVE-2011-2996: Unspecified vulnerability in the plugin API in Mozilla Firefox 3.6.x before 3.6.23 allows remote att
Unspecified vulnerability in the plugin API in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-2995P3CRITICALCVSS 10.0≤ 3.6.22v3.6+23 more2011-09-29
CVE-2011-2995 [CRITICAL] CVE-2011-2995: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.23 and 4.x
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2019-11760P3HIGHCVSS 8.8fixed in 70.0vbefore 702020-01-08
CVE-2019-11760 [HIGH] CWE-787 CVE-2019-11760: A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2017-5031P3HIGHCVSS 8.8≥ unspecified, < 53.0.22017-04-24
CVE-2017-5031 [HIGH] CWE-416 CVE-2017-5031: A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attack
A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2020-12416P3HIGHCVSS 8.8fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12416 [HIGH] CWE-362 CVE-2020-12416: A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink,
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
nvdosv
CVE-2017-5412P3HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5412 [HIGH] CWE-119 CVE-2017-5412: A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vu
A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2012-0468P3CRITICALCVSS 10.0v4.0v4.0.1+15 more2012-04-25
CVE-2012-0468 [CRITICAL] CWE-119 CVE-2012-0468: The browser engine in Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey
The browser engine in Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (assertion failure and memory corruption) or possibly execute arbitrary code via vectors related to jsval.h and the js::array_shift function.
nvd
CVE-2019-11735P3HIGHCVSS 8.8fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11735 [HIGH] CWE-787 CVE-2019-11735: Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2021-29946P3HIGHCVSS 8.8fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-29946 [HIGH] CWE-190 CVE-2021-29946: Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypas
Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd