Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 70 of 162
CVE-2012-4183P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4183 [CRITICAL] CWE-416 CVE-2012-4183: Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox bef
Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified ve
nvd
CVE-2012-4181P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4181 [CRITICAL] CWE-416 CVE-2012-4181: Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox
Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified
nvd
CVE-2012-5842P3CRITICALCVSS 9.3fixed in 10.0.11fixed in 17.02012-11-21
CVE-2012-5842 [CRITICAL] CVE-2012-5842: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2009-3389P3CRITICALCVSS 9.3v3.5.1v3.5.2+3 more2009-12-17
CVE-2009-3389 [CRITICAL] CWE-189 CVE-2009-3389: Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3
Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions.
nvd
CVE-2015-0801P3HIGHCVSS 7.5≤ 31.5.3≤ 36.0.4+6 more2015-04-01
CVE-2015-0801 [HIGH] CWE-264 CVE-2015-0801: Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.
nvdosv
CVE-2012-4179P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4179 [CRITICAL] CWE-416 CVE-2012-4179: Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox
Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecifie
nvd
CVE-2012-3982P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-3982 [CRITICAL] CVE-2012-3982: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-4182P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4182 [CRITICAL] CWE-416 CVE-2012-4182: Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 1
Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors
nvd
CVE-2015-4511P3MEDIUMCVSS 6.8v38.0v38.0.1+6 more2015-09-24
CVE-2015-4511 [MEDIUM] CWE-119 CVE-2015-4511: Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 a
Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.
nvdosv
CVE-2019-9818P3HIGHCVSS 8.3fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9818 [HIGH] CWE-362 CVE-2019-9818: A race condition is present in the crash generation server used to generate data for the crash repor
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability only affects Windows. Other operating systems are unaffected.*. This vulnerability affects Thund
nvd
CVE-2012-0472P3CRITICALCVSS 9.3v4.0v4.0.1+15 more2012-04-25
CVE-2012-0472 [CRITICAL] CWE-119 CVE-2012-0472: The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4,
The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a
nvd
CVE-2018-5181P3HIGHCVSS 7.5fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5181 [HIGH] CWE-200 CVE-2018-5181: If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a dif
If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to policy. One way to make the target tab open more reliably in a separate process is to open it with the "noopener" keyword. This vulnerability affects Firefox
nvdosv
CVE-2017-7757P3CRITICALCVSS 9.8fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7757 [CRITICAL] CWE-416 CVE-2017-7757: A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a m
A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2021-29991P3HIGHCVSS 8.1fixed in 91.0.1≥ unspecified, < 91.0.12021-11-03
CVE-2021-29991 [HIGH] CWE-444 CVE-2021-29991: Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers.
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.
nvdosv
CVE-2012-4191P3CRITICALCVSS 9.3fixed in 16.0.12012-10-12
CVE-2012-4191 [CRITICAL] CWE-787 CVE-2012-4191: The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Fire
The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2017-5470P3CRITICALCVSS 9.8fixed in 54.0fixed in 52.2.0+1 more2018-06-11
CVE-2017-5470 [CRITICAL] CWE-119 CVE-2017-5470: Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvdosv
CVE-2009-3378P3CRITICALCVSS 9.3v3.5.1v3.5.2+1 more2009-10-29
CVE-2009-3378 [CRITICAL] CVE-2009-3378: The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in l
The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and applic
nvd
CVE-2019-11719P3HIGHCVSS 7.5fixed in 60.8.0fixed in 68.0+1 more2019-07-23
CVE-2019-11719 [HIGH] CWE-125 CVE-2019-11719: When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to t
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2024-6606P3HIGHCVSS 8.2fixed in 128.0≥ unspecified, < 1282024-07-09
CVE-2024-6606 [HIGH] CWE-125 CVE-2024-6606: Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunderbird < 128.
nvdosv
CVE-2008-5021P3CRITICALCVSS 9.3≥ 2.0, < 2.0.0.18≥ 3.0, < 3.0.42008-11-13
CVE-2008-5021 [CRITICAL] CWE-362 CVE-2008-5021: nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.
nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to a
nvd