cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 69 of 162
CVE-2020-26952P3HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26952 [HIGH] CWE-787 CVE-2020-26952: Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruptio Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash when handling out-of-memory errors. This vulnerability affects Firefox < 83.
nvdosv
CVE-2012-4204P3CRITICALCVSS 9.3fixed in 17.02012-11-21
CVE-2012-4204 [CRITICAL] CWE-119 CVE-2012-4204: The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird befor The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2020-15675P3HIGHCVSS 8.8fixed in 81.0≥ unspecified, < 812020-10-01
CVE-2020-15675 [HIGH] CWE-416 CVE-2020-15675: When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 81.
nvdosv
CVE-2013-1722P3CRITICALCVSS 9.3≤ 23.0.1v19.0+16 more2013-09-18
CVE-2013-1722 [CRITICAL] CWE-399 CVE-2013-1722: Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Ma Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory co
nvd
CVE-2021-38499P3HIGHCVSS 8.8fixed in 93.0≥ unspecified, < 932021-11-03
CVE-2021-38499 [HIGH] CWE-787 CVE-2021-38499: Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evid Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93.
nvdosv
CVE-2021-38494P3HIGHCVSS 8.8fixed in 92.0≥ unspecified, < 922021-11-03
CVE-2021-38494 [HIGH] CWE-787 CVE-2021-38494: Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evid Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 92.
nvdosv
CVE-2014-1581P3HIGHCVSS 7.5v31.0v31.1.0+2 more2014-10-15
CVE-2014-1581 [HIGH] CVE-2014-1581: Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 33.0, Firefox ESR Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.
nvdosv
CVE-2013-5615P3CRITICALCVSS 9.8fixed in 26.0≥ 24.0, < 24.22013-12-11
CVE-2013-5615 [CRITICAL] CVE-2013-5615: The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderb The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors.
nvd
CVE-2014-1522P3CRITICALCVSS 9.3fixed in 29.02014-04-30
CVE-2014-1522 [CRITICAL] CWE-125 CVE-2014-1522: The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via crafted content.
nvdosv
CVE-2014-1481P3HIGHCVSS 7.5fixed in 27.0≥ 24.0, < 24.32014-02-06
CVE-2014-1481 [HIGH] CVE-2014-1481: Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey be Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
nvd
CVE-2022-34480P3HIGHCVSS 8.8fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34480 [HIGH] CWE-824 CVE-2022-34480: Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an un Within the lg_init() function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.
nvdosv
CVE-2022-29918P3HIGHCVSS 8.8fixed in 100.0≥ unspecified, < 1002022-12-22
CVE-2022-29918 [HIGH] CWE-787 CVE-2022-29918: Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safet Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 100.
nvdosv
CVE-2022-22752P3HIGHCVSS 8.8fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22752 [HIGH] CWE-787 CVE-2022-22752: Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 96.
nvdosv
CVE-2022-28288P3HIGHCVSS 8.8fixed in 99.0≥ unspecified, < 992022-12-22
CVE-2022-28288 [HIGH] CWE-787 CVE-2022-28288: Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Te Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 98. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 99.
nvdosv
CVE-2022-46885P3HIGHCVSS 8.8fixed in 106.0≥ unspecified, < 1062022-12-22
CVE-2022-46885 [HIGH] CWE-787 CVE-2022-46885: Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106.
nvdosv
CVE-2014-1494P3CRITICALCVSS 9.3fixed in 28.02014-03-19
CVE-2014-1494 [CRITICAL] CVE-2014-1494: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMon Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2014-1542P3MEDIUMCVSS 6.8≤ 29.0.12014-06-11
CVE-2014-1542 [MEDIUM] CWE-119 CVE-2014-1542: Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 all Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.
nvdosv
CVE-2016-5297P3CRITICALCVSS 9.8fixed in 45.5.0fixed in 50.0+1 more2018-06-11
CVE-2016-5297 [CRITICAL] CWE-190 CVE-2016-5297: An error in argument length checking in JavaScript, leading to potential integer overflows or other An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2017-5378P3HIGHCVSS 7.5fixed in 51.0fixed in 45.7.0+1 more2018-06-11
CVE-2017-5378 [HIGH] CWE-200 CVE-2017-5378: Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because a Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2012-1948P3CRITICALCVSS 9.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1948 [CRITICAL] CVE-2012-1948: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Fire Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknow
nvd
Mozilla Firefox vulnerabilities | cvebase