Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 79 of 162
CVE-2018-18502P3CRITICALCVSS 9.8fixed in 65.0≥ unspecified, < 652019-02-05
CVE-2018-18502 [CRITICAL] CWE-119 CVE-2018-18502: Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of
Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 65.
nvdosv
CVE-2022-34469P3HIGHCVSS 8.1fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34469 [HIGH] CWE-295 CVE-2022-34469: When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. *This bug only affects Firefox for Android. Other operating syste
nvd
CVE-2016-9065P3HIGHCVSS 7.5fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9065 [HIGH] CWE-20 CVE-2016-9065: The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, block
The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
nvd
CVE-2011-3671P3HIGHCVSS 7.5v4.0v4.0.1+8 more2012-06-18
CVE-2011-3671 [HIGH] CWE-399 CVE-2011-3671: Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozil
Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.
nvd
CVE-2025-8029P3HIGHCVSS 8.1fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8029 [HIGH] CWE-80 CVE-2025-8029: Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability w
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvd
CVE-2016-5289P3CRITICALCVSS 9.8fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-5289 [CRITICAL] CWE-119 CVE-2016-5289: Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corrupt
Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.
nvdosv
CVE-2017-7790P3HIGHCVSS 7.5fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7790 [HIGH] CVE-2017-7790: On Windows systems, if non-null-terminated strings are copied into the crash reporter for some speci
On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, stack memory data can be copied until a null is found. This can potentially contain private data from the local system. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affec
nvd
CVE-2018-5134P3HIGHCVSS 7.5fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5134 [HIGH] CWE-200 CVE-2018-5134: WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stor
WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that only allow WebExtensions to view specific content. This vulnerability affects Firefox < 59.
nvdosv
CVE-2009-1833P3CRITICALCVSS 9.3≤ 3.0.10v0.1+89 more2009-06-12
CVE-2009-1833 [CRITICAL] CWE-94 CVE-2009-1833: The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey b
The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c
nvd
CVE-2017-5388P3HIGHCVSS 7.5fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5388 [HIGH] CWE-770 CVE-2017-5388: A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowing for a denial of service attack. This vulnerability affects Firefox < 51.
nvdosv
CVE-2017-7780P3CRITICALCVSS 9.8fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7780 [CRITICAL] CWE-119 CVE-2017-7780: Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corrupt
Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 55.
nvdosv
CVE-2016-9073P3HIGHCVSS 7.5fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9073 [HIGH] CWE-264 CVE-2016-9073: WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExten
WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.
nvdosv
CVE-2007-5338P3CRITICALCVSS 9.3≤ 2.0.0.72007-10-21
CVE-2007-5338 [CRITICAL] CWE-16 CVE-2007-5338: Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrar
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.
nvd
CVE-2016-9061P3HIGHCVSS 7.5fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9061 [HIGH] CWE-275 CVE-2016-9061: A previously installed malicious Android application which defines a specific signature-level permis
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
nvd
CVE-2018-5157P3HIGHCVSS 7.5fixed in 52.8.0fixed in 60.0+1 more2018-06-11
CVE-2018-5157 [HIGH] CWE-200 CVE-2018-5157: Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept m
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
nvd
CVE-2018-5135P3HIGHCVSS 7.5fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5135 [HIGH] CWE-862 CVE-2018-5135: WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScri
WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivileged "about:" pages. This vulnerability affects Firefox < 59.
nvdosv
CVE-2017-5374P3CRITICALCVSS 9.8fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5374 [CRITICAL] CWE-119 CVE-2017-5374: Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corru
Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 51.
nvdosv
CVE-2021-38498P3HIGHCVSS 7.5fixed in 93.0≥ unspecified, < 932021-11-03
CVE-2021-38498 [HIGH] CWE-416 CVE-2021-38498: During process shutdown, a document could have caused a use-after-free of a languages service object
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvdosv
CVE-2017-5471P3CRITICALCVSS 9.8fixed in 54.0≥ unspecified, < 542018-06-11
CVE-2017-5471 [CRITICAL] CWE-119 CVE-2017-5471: Memory safety bugs were reported in Firefox 53. Some of these bugs showed evidence of memory corrupt
Memory safety bugs were reported in Firefox 53. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54.
nvdosv
CVE-2020-12391P3HIGHCVSS 7.5fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12391 [HIGH] CWE-863 CVE-2020-12391: Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating con
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin. This vulnerability affects Firefox < 76.
nvdosv