cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 83 of 162
CVE-2012-0442P3CRITICALCVSS 9.3fixed in 3.6.26≥ 4.0, < 10.02012-02-01
CVE-2012-0442 [CRITICAL] CVE-2012-0442: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-3176P3CRITICALCVSS 9.3v3.6v3.6.2+21 more2010-10-21
CVE-2010-3176 [CRITICAL] CVE-2010-3176: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 an Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-1940P3CRITICALCVSS 9.3v4.0v4.0.1+18 more2012-06-05
CVE-2012-1940 [CRITICAL] CWE-399 CVE-2012-1940: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox 4.x through Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application cra
nvd
CVE-2013-1704P3CRITICALCVSS 9.3≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1704 [CRITICAL] CWE-399 CVE-2013-1704: Use-after-free vulnerability in the nsINode::GetParentNode function in Mozilla Firefox before 23.0 a Use-after-free vulnerability in the nsINode::GetParentNode function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a DOM modification at the time of a SetBody mutation event.
nvd
CVE-2015-7193P3HIGHCVSS 7.5v38.0v38.0.1+7 more2015-11-05
CVE-2015-7193 [HIGH] CWE-254 CVE-2015-7193: Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.
nvdosv
CVE-2008-2801P3HIGHCVSS 7.5≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2801 [HIGH] CWE-287 CVE-2008-2801: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, w Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.
nvd
CVE-2016-9904P3HIGHCVSS 7.5fixed in 45.6.0fixed in 51.0+1 more2018-06-11
CVE-2016-9904 [HIGH] CWE-200 CVE-2016-9904: An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by ano An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-7754P3HIGHCVSS 7.5fixed in 54.0fixed in 52.2.0+1 more2018-06-11
CVE-2017-7754 [HIGH] CWE-125 CVE-2017-7754: An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2014-1490P3CRITICALCVSS 9.3fixed in 24.3fixed in 27.02014-02-06
CVE-2014-1490 [CRITICAL] CWE-362 CVE-2014-1490: Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozill Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involv
nvd
CVE-2016-2812P3HIGHCVSS 7.5≤ 45.0.22016-04-30
CVE-2016-2812 [HIGH] CWE-362 CVE-2016-2812: Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker sub Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.
nvdosv
CVE-2015-7213P3MEDIUMCVSS 6.8v38.0v38.0.1+8 more2015-12-16
CVE-2015-7213 [MEDIUM] CWE-189 CVE-2015-7213: Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefrigh Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers a buffer overflow.
nvdosv
CVE-2005-1155P3HIGHCVSS 7.5v0.8v0.9+8 more2005-05-02
CVE-2005-1155 [HIGH] CWE-94 CVE-2005-1155: The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attac The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a tag with a javascript: URL in the href attribute, aka "Firelinking."
nvd
CVE-2013-1725P3MEDIUMCVSS 6.8≤ 23.0.1v19.0+16 more2013-09-18
CVE-2013-1725 [MEDIUM] CWE-119 CVE-2013-1725: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.
nvd
CVE-2010-3175P3CRITICALCVSS 9.3v3.6v3.6.2+7 more2010-10-21
CVE-2010-3175 [CRITICAL] CVE-2010-3175: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.11 an Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.11 and Thunderbird 3.1.x before 3.1.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2021-29993P3HIGHCVSS 8.1fixed in 92.0≥ unspecified, < 922021-11-03
CVE-2021-29993 [HIGH] CVE-2021-29993: Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cau Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.
nvd
CVE-2024-4776P3HIGHCVSS 8.2fixed in 126.0≥ unspecified, < 1262024-05-14
CVE-2024-4776 [HIGH] CWE-79 CVE-2024-4776: A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.
nvdosv
CVE-2017-7803P3HIGHCVSS 7.5fixed in 52.3.0fixed in 55.0+1 more2018-06-11
CVE-2017-7803 [HIGH] CWE-269 CVE-2017-7803: When a page's content security policy (CSP) header contains a "sandbox" directive, other directives When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-7811P3CRITICALCVSS 9.8fixed in 56.0≥ unspecified, < 562018-06-11
CVE-2017-7811 [CRITICAL] CWE-119 CVE-2017-7811: Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56.
nvdosv
CVE-2018-5090P3CRITICALCVSS 9.8≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5090 [CRITICAL] CWE-119 CVE-2018-5090: Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 58.
nvdosv
CVE-2017-7762P3HIGHCVSS 7.5fixed in 54.0≥ unspecified, < 542018-06-11
CVE-2017-7762 [HIGH] CWE-20 CVE-2017-7762: When entered directly, Reader Mode did not strip the username and password section of URLs displayed When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.
nvdosv