Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 75 of 162
CVE-2011-2989P3CRITICALCVSS 10.0v4.0v4.0.1+1 more2011-08-18
CVE-2011-2989 [CRITICAL] CWE-119 CVE-2011-2989: The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6,
The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products does not properly implement WebGL, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2015-7221P3CRITICALCVSS 10.0≤ 42.02015-12-16
CVE-2015-7221 [CRITICAL] CWE-119 CVE-2015-7221: Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox b
Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.
nvdosv
CVE-2016-1949P3HIGHCVSS 8.8≤ 44.0.12016-02-13
CVE-2016-1949 [HIGH] CWE-264 CVE-2016-1949: Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and
Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
nvdosv
CVE-2018-12371P3HIGHCVSS 8.8fixed in 60.1.0fixed in 61.0+1 more2020-07-09
CVE-2018-12371 [HIGH] CWE-190 CVE-2018-12371: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.
nvd
CVE-2013-5591P3CRITICALCVSS 10.0≤ 24.0v19.0+11 more2013-10-30
CVE-2013-5591 [CRITICAL] CVE-2013-5591: Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x bef
Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-0443P3CRITICALCVSS 10.0v4.0v4.0.1+9 more2012-02-01
CVE-2012-0443 [CRITICAL] CVE-2012-0443: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 9.0, Thund
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2017-7772P3HIGHCVSS 8.8fixed in 54.0vAll versions prior to Firefox 542019-04-12
CVE-2017-7772 [HIGH] CWE-119 CVE-2017-7772: Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
nvd
CVE-2020-6801P3HIGHCVSS 8.8fixed in 73.0≥ unspecified, < 732020-03-02
CVE-2020-6801 [HIGH] CWE-787 CVE-2020-6801: Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 73.
nvdosv
CVE-2012-4217P3CRITICALCVSS 9.3fixed in 17.02012-11-21
CVE-2012-4217 [CRITICAL] CWE-416 CVE-2012-4217: Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox
Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-4213P3CRITICALCVSS 9.3fixed in 10.0.11fixed in 17.02012-11-21
CVE-2012-4213 [CRITICAL] CWE-416 CVE-2012-4213: Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17
Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2009-0352P3CRITICALCVSS 10.0v3.0v3.0.1+4 more2009-02-04
CVE-2009-0352 [CRITICAL] CWE-399 CVE-2009-0352: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.2
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the
nvd
CVE-2019-9811P3HIGHCVSS 8.3fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-9811 [HIGH] CWE-74 CVE-2019-9811: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malic
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvdosv
CVE-2015-7203P3CRITICALCVSS 10.0≤ 42.02015-12-16
CVE-2015-7203 [CRITICAL] CWE-119 CVE-2015-7203: Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontL
Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font-family name.
nvdosv
CVE-2020-12411P3HIGHCVSS 8.8fixed in 77.0≥ unspecified, < 772020-07-09
CVE-2020-12411 [HIGH] CWE-787 CVE-2020-12411: Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 77.
nvdosv
CVE-2014-1532P3CRITICALCVSS 9.8fixed in 29.0≥ 24.0, < 24.52014-04-30
CVE-2014-1532 [CRITICAL] CWE-416 CVE-2014-1532: Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so
Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resol
nvdosv
CVE-2021-43535P3HIGHCVSS 8.8fixed in 93.0≥ unspecified, < 932021-12-08
CVE-2021-43535 [HIGH] CWE-416 CVE-2021-43535: A use-after-free could have occured when an HTTP2 session object was released on a different thread,
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2013-0770P3CRITICALCVSS 9.3fixed in 10.0.12fixed in 18.0+1 more2013-01-13
CVE-2013-0770 [CRITICAL] CVE-2013-0770: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbird before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2021-23954P3HIGHCVSS 8.8fixed in 85.0fixed in 852021-02-26
CVE-2021-23954 [HIGH] CWE-843 CVE-2021-23954: Using the new logical assignment operators in a JavaScript switch statement could have caused a type
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2021-23988P3HIGHCVSS 8.8fixed in 87.0≥ unspecified, < 872021-03-31
CVE-2021-23988 [HIGH] CWE-787 CVE-2021-23988: Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 87.
nvdosv
CVE-2012-0449P3CRITICALCVSS 9.3fixed in 3.6.26≥ 4.0, < 10.02012-02-01
CVE-2012-0449 [CRITICAL] CWE-119 CVE-2012-0449: Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, an
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.
nvd