Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 74 of 162
CVE-2013-1680P3CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1680 [CRITICAL] CWE-119 CVE-2013-1680: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0,
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2011-0080P3CRITICALCVSS 10.0v3.6v3.6.2+32 more2011-05-07
CVE-2011-0080 [CRITICAL] CVE-2011-0080: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-2364P3CRITICALCVSS 10.0v3.6.2v3.6.3+13 more2011-06-30
CVE-2011-2364 [CRITICAL] CVE-2011-2364: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbi
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2365.
nvd
CVE-2009-3380P3CRITICALCVSS 10.0v3.0.1v3.0.2+15 more2009-10-29
CVE-2009-3380 [CRITICAL] CVE-2009-3380: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-1686P3CRITICALCVSS 10.0≤ 21.0v19.0+11 more2013-06-26
CVE-2013-1686 [CRITICAL] CWE-399 CVE-2013-1686: Use-after-free vulnerability in the mozilla::ResetDir function in Mozilla Firefox before 22.0, Firef
Use-after-free vulnerability in the mozilla::ResetDir function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-1682P3CRITICALCVSS 10.0≤ 21.0v19.0+11 more2013-06-26
CVE-2013-1682 [CRITICAL] CVE-2013-1682: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-0801P3CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-0801 [CRITICAL] CVE-2013-0801: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2007-1092P3CRITICALCVSS 9.3v1.5.0.9v2.0.0.12007-02-26
CVE-2007-1092 [CRITICAL] CVE-2007-1092: Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute ar
Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.
nvd
CVE-2006-5747P3HIGHCVSS 7.5v1.5v1.5.0.1+6 more2006-11-08
CVE-2006-5747 [HIGH] CVE-2006-5747: Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonk
Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function.
nvd
CVE-2016-2792P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2792 [HIGH] CWE-119 CVE-2016-2792: The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Fir
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2800.
nvd
CVE-2016-2800P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2800 [HIGH] CVE-2016-2800: The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Fir
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2792.
nvd
CVE-2016-2801P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2801 [HIGH] CVE-2016-2801: The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797.
nvd
CVE-2016-1979P3HIGHCVSS 8.8≤ 44.0.22016-03-13
CVE-2016-1979 [HIGH] CVE-2016-1979: Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Net
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
nvd
CVE-2014-1575P3HIGHCVSS 7.5≤ 32.0v30.0+2 more2014-10-15
CVE-2014-1575 [HIGH] CWE-264 CVE-2014-1575: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to improper interaction between threading and garbage collection in the GCRuntime::triggerGC function in js/src/jsgc
nvdosv
CVE-2016-10196P3HIGHCVSS 7.5fixed in 45.9.0fixed in 53.0+1 more2017-03-15
CVE-2016-10196 [HIGH] CWE-787 CVE-2016-10196: Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent befor
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
nvd
CVE-2014-1538P3CRITICALCVSS 10.0≤ 29.0.1v24.0+4 more2014-06-11
CVE-2014-1538 [CRITICAL] CVE-2014-1538: Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before
Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvdosv
CVE-2018-12364P3HIGHCVSS 8.8fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-12364 [HIGH] CWE-352 CVE-2018-12364: NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by mak
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR
nvd
CVE-2010-0159P3CRITICALCVSS 10.0≥ 3.0, < 3.0.18≥ 3.5, < 3.5.82010-02-22
CVE-2010-0159 [CRITICAL] CVE-2010-0159: The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before
The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cp
nvd
CVE-2013-0788P3CRITICALCVSS 10.0≤ 19.0.2v19.0+6 more2013-04-03
CVE-2013-0788 [CRITICAL] CVE-2013-0788: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2009-3377P3CRITICALCVSS 10.0v3.5v3.5.1+2 more2009-10-29
CVE-2009-3377 [CRITICAL] CVE-2009-3377: Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox
Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
nvd