Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 76 of 162
CVE-2020-35114P3HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-35114 [HIGH] CWE-787 CVE-2020-35114: Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.
nvdosv
CVE-2012-5843P3CRITICALCVSS 9.3fixed in 10.0.11fixed in 17.02012-11-21
CVE-2012-5843 [CRITICAL] CVE-2012-5843: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2020-12409P3HIGHCVSS 8.8fixed in 77.0≥ unspecified, < 772020-07-09
CVE-2020-12409 [HIGH] CVE-2020-12409: When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of a
When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox < 77.
nvdosv
CVE-2017-7776P3HIGHCVSS 8.1fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7776 [HIGH] CWE-125 CVE-2017-7776: Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getCla
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
nvd
CVE-2021-29966P3HIGHCVSS 8.8≥ 78.11.0, < 89.0≥ unspecified, < 892021-06-24
CVE-2021-29966 [HIGH] CWE-787 CVE-2021-29966: Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 89.
nvdosv
CVE-2021-23972P3HIGHCVSS 8.8fixed in 86.0fixed in 862021-02-26
CVE-2021-23972 [HIGH] CVE-2021-23972: One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishin
One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://[email protected]'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.
nvdosv
CVE-2021-29990P3HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29990 [HIGH] CWE-787 CVE-2021-29990: Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of
Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 91.
nvdosv
CVE-2021-29977P3HIGHCVSS 8.8fixed in 90.0≥ unspecified, < 902021-08-05
CVE-2021-29977 [HIGH] CWE-787 CVE-2021-29977: Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 90.
nvdosv
CVE-2021-23965P3HIGHCVSS 8.8fixed in 85.0fixed in 852021-02-26
CVE-2021-23965 [HIGH] CWE-787 CVE-2021-23965: Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85.
nvdosv
CVE-2013-1724P3CRITICALCVSS 9.3≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1724 [CRITICAL] CWE-399 CVE-2013-1724: Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function i
Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.
nvd
CVE-2006-4565P3CRITICALCVSS 9.3≤ 1.5.0.62006-09-15
CVE-2006-4565 [CRITICAL] CWE-119 CVE-2006-4565: Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMon
Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."
nvd
CVE-2015-7179P3HIGHCVSS 7.5≤ 40.0.3v38.0+6 more2015-09-24
CVE-2015-7179 [HIGH] CWE-119 CVE-2015-7179: The VertexBufferInterface::reserveVertexSpace function in libGLES in ANGLE, as used in Mozilla Firef
The VertexBufferInterface::reserveVertexSpace function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, incorrectly allocates memory for shader attribute arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via crafted
nvd
CVE-2021-23979P3HIGHCVSS 8.8fixed in 86.0fixed in 862021-02-26
CVE-2021-23979 [HIGH] CWE-787 CVE-2021-23979: Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86.
nvdosv
CVE-2021-29947P3HIGHCVSS 8.8fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-29947 [HIGH] CWE-787 CVE-2021-29947: Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of
Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 88.
nvdosv
CVE-2023-4052P3MEDIUMCVSS 6.5fixed in 116.0≥ unspecified, < 1162023-08-01
CVE-2023-4052 [MEDIUM] CWE-59 CVE-2023-4052: The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox,
The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privilege
nvd
CVE-2020-15674P3HIGHCVSS 8.8fixed in 81.0≥ unspecified, < 812020-10-01
CVE-2020-15674 [HIGH] CWE-667 CVE-2020-15674: Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evid
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81.
nvdosv
CVE-2014-1505P3HIGHCVSS 7.5fixed in 28.0≥ 24.0, < 24.42014-03-19
CVE-2014-1505 [HIGH] CVE-2014-1505: The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderb
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements
nvd
CVE-2009-3986P3HIGHCVSS 7.6≤ 3.0.15v0.1+97 more2009-12-17
CVE-2009-3986 [HIGH] CWE-94 CVE-2009-3986: Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote atta
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.
nvd
CVE-2018-5177P3HIGHCVSS 7.5fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5177 [HIGH] CWE-119 CVE-2018-5177: A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocate
A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a buffer overflow and crash if it occurs. This vulnerability affects Firefox < 60.
nvdosv
CVE-2015-4488P3HIGHCVSS 7.5≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4488 [HIGH] CVE-2015-4488: Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefo
Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment.
nvdosv