Mozilla Firefox vulnerabilities
3,148 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70
Vulnerabilities
Page 69 of 158
CVE-2018-5122CRITICALCVSS 9.8≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5122 [CRITICAL] CWE-190 CVE-2018-5122: A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was f
A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting it, it could result in an out-of-bounds write. This vulnerability affects Firefox < 58.
nvdosv
CVE-2017-7811CRITICALCVSS 9.8fixed in 56.0≥ unspecified, < 562018-06-11
CVE-2017-7811 [CRITICAL] CWE-119 CVE-2017-7811: Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corrupt
Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56.
nvdosv
CVE-2017-5373CRITICALCVSS 9.8fixed in 45.7.0fixed in 51.0+1 more2018-06-11
CVE-2017-5373 [CRITICAL] CWE-119 CVE-2017-5373: Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evi
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvdosv
CVE-2018-5159CRITICALCVSS 9.8PoCfixed in 52.8.0fixed in 60.0+1 more2018-06-11
CVE-2018-5159 [CRITICAL] CWE-190 CVE-2018-5159: An integer overflow can occur in the Skia library due to 32-bit integer use in an array without inte
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8
nvd
CVE-2017-5456CRITICALCVSS 9.8fixed in 53.0fixed in 52.1.0+1 more2018-06-11
CVE-2017-5456 [CRITICAL] CWE-732 CVE-2017-5456: A mechanism to bypass file system access protections in the sandbox using the file system request co
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
nvdosv
CVE-2018-5090CRITICALCVSS 9.8≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5090 [CRITICAL] CWE-119 CVE-2018-5090: Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corrupt
Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 58.
nvdosv
CVE-2017-5469CRITICALCVSS 9.8fixed in 45.9.0fixed in 53.0+1 more2018-06-11
CVE-2017-5469 [CRITICAL] CVE-2017-5469: Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5399CRITICALCVSS 9.8fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5399 [CRITICAL] CWE-119 CVE-2017-5399: Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corrupt
Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2017-5429CRITICALCVSS 9.8fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5429 [CRITICAL] CWE-119 CVE-2017-5429: Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Fi
nvdosv
CVE-2018-5151CRITICALCVSS 9.8fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5151 [CRITICAL] CWE-119 CVE-2018-5151: Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corrupt
Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 60.
nvdosv
CVE-2017-5402CRITICALCVSS 9.8fixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5402 [CRITICAL] CWE-416 CVE-2017-5402: A use-after-free can occur when events are fired for a "FontFace" object after the object has been a
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2016-9899CRITICALCVSS 9.8PoC≥ 52.0, < 52.1.0fixed in 53.0+2 more2018-06-11
CVE-2016-9899 [CRITICAL] CWE-416 CVE-2016-9899: Use-after-free while manipulating DOM events and removing audio elements due to errors in the handli
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-5375CRITICALCVSS 9.8PoCfixed in 45.7.0fixed in 51.0.1+1 more2018-06-11
CVE-2017-5375 [CRITICAL] CWE-119 CVE-2017-5375: JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory c
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2018-5099CRITICALCVSS 9.8fixed in 58.0fixed in 52.6.0+1 more2018-06-11
CVE-2018-5099 [CRITICAL] CWE-416 CVE-2018-5099: A use-after-free vulnerability can occur when the widget listener is holding strong references to br
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2017-5401CRITICALCVSS 9.8fixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5401 [CRITICAL] CWE-388 CVE-2017-5401: A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a l
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2018-5116CRITICALCVSS 9.8≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5116 [CRITICAL] CWE-346 CVE-2018-5116: WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58
nvdosv
CVE-2017-5439CRITICALCVSS 9.8≥ 52.0, < 52.1.0fixed in 53.0+2 more2018-06-11
CVE-2017-5439 [CRITICAL] CWE-416 CVE-2017-5439: A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. T
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5404CRITICALCVSS 9.8PoCfixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5404 [CRITICAL] CWE-416 CVE-2017-5404: A use-after-free error can occur when manipulating ranges in selections with one node inside a nativ
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5400CRITICALCVSS 9.8fixed in 45.8.0fixed in 52.0+1 more2018-06-11
CVE-2017-5400 [CRITICAL] CWE-119 CVE-2017-5400: JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protection
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2016-9063CRITICALCVSS 9.8fixed in 50≥ unspecified, < 502018-06-11
CVE-2016-9063 [CRITICAL] CWE-190 CVE-2016-9063: An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Fi
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
nvd