cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 77 of 162
CVE-2015-0803P3HIGHCVSS 7.5≤ 36.0.42015-04-01
CVE-2015-0803 [HIGH] CWE-264 CVE-2015-0803: The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constr The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.
nvdosv
CVE-2008-5024P3HIGHCVSS 7.5≥ 2.0, < 2.0.0.18≥ 3.0, < 3.0.42008-11-13
CVE-2008-5024 [HIGH] CWE-91 CVE-2008-5024: Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
nvd
CVE-2015-0806P3HIGHCVSS 7.5≤ 36.0.42015-04-01
CVE-2015-0806 [HIGH] CWE-17 CVE-2015-0806: The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vecto
nvdosv
CVE-2013-0777P3CRITICALCVSS 9.3fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0777 [CRITICAL] CWE-416 CVE-2013-0777: Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox befor Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2018-5141P3HIGHCVSS 8.2fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5141 [HIGH] CWE-20 CVE-2018-5141: A vulnerability in the notifications Push API where notifications can be sent through service worker A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction. This could be used to open new tabs in a denial of service (DOS) attack or to display unwanted content from arbitrary URLs to users. This vulnerability affects Firefox < 59.
nvdosv
CVE-2012-5833P3CRITICALCVSS 9.3fixed in 10.0.11fixed in 17.02012-11-21
CVE-2012-5833 [CRITICAL] CWE-119 CVE-2012-5833: The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10. The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup
nvd
CVE-2013-0784P3CRITICALCVSS 9.3fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0784 [CRITICAL] CVE-2013-0784: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbi Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2017-5410P3CRITICALCVSS 9.8fixed in 52.0fixed in 45.8.0+1 more2018-06-11
CVE-2017-5410 [CRITICAL] CWE-119 CVE-2017-5410: Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScri Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-7805P3HIGHCVSS 7.5v52.4.0v56.0+1 more2018-06-11
CVE-2017-7805 [HIGH] CWE-416 CVE-2017-7805: During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-fr
nvd
CVE-2013-0763P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0763 [CRITICAL] CWE-416 CVE-2013-0763: Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunder Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to Mesa drivers and a resized WebGL canvas.
nvd
CVE-2013-0761P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0761 [CRITICAL] CWE-416 CVE-2013-0761: Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Fi Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via uns
nvd
CVE-2009-2044P4MEDIUMCVSS 4.3PoC≤ 3.0.102009-06-12
CVE-2009-2044 [MEDIUM] CWE-20 CVE-2009-2044: Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (ap Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of a BODY element.
nvd
CVE-2016-5254P3CRITICALCVSS 9.8≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-5254 [CRITICAL] CWE-416 CVE-2016-5254: Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48 Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) by leveraging keyboard access to use the Alt key during selection of top-level menu items.
nvd
CVE-2021-23976P3HIGHCVSS 8.1fixed in 86.02021-02-26
CVE-2021-23976 [HIGH] CVE-2021-23976: When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020
nvd
CVE-2008-3836P3HIGHCVSS 7.5≤ 2.0.0.16v0.8+46 more2008-09-24
CVE-2008-3836 [HIGH] CWE-264 CVE-2008-3836: feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.
nvd
CVE-2018-5151P3CRITICALCVSS 9.8fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5151 [CRITICAL] CWE-119 CVE-2018-5151: Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 60.
nvdosv
CVE-2017-7827P3CRITICALCVSS 9.8≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7827 [CRITICAL] CWE-119 CVE-2017-7827: Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57.
nvdosv
CVE-2011-3005P3CRITICALCVSS 9.3v4.0v4.0.1+2 more2011-09-29
CVE-2011-3005 [CRITICAL] CWE-119 CVE-2011-3005: Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OGG headers in a .ogg file.
nvd
CVE-2005-0233P4HIGHCVSS 7.5v1.02005-02-08
CVE-2005-0233 [HIGH] CVE-2005-0233: The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 al The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
nvd
CVE-2013-0781P3CRITICALCVSS 9.3fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0781 [CRITICAL] CWE-416 CVE-2013-0781: Use-after-free vulnerability in the nsPrintEngine::CommonPrint function in Mozilla Firefox before 19 Use-after-free vulnerability in the nsPrintEngine::CommonPrint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
Mozilla Firefox vulnerabilities | cvebase