cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 84 of 162
CVE-2015-0817P3MEDIUMCVSS 6.8≤ 36.0.1v31.0+4 more2015-03-24
CVE-2015-0817 [MEDIUM] CWE-17 CVE-2015-0817: The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaM The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine the cases in which bounds checking may be safely skipped during JIT compilation and heap access, which allows remote attackers to read or write to unintended memory locations, and consequently execute arbit
nvdosv
CVE-2017-5450P3HIGHCVSS 7.5fixed in 53.0≥ unspecified, < 532018-06-11
CVE-2017-5450 [HIGH] CWE-20 CVE-2017-5450: A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for An A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, making the resulting location less visibly a spoofed site and showing an incorrect domain in appended notifications. This vulnerability affects Firefox < 53.
nvd
CVE-2017-5411P3HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5411 [HIGH] CWE-416 CVE-2017-5411: A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulne
nvd
CVE-2017-5379P3HIGHCVSS 7.5fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5379 [HIGH] CWE-416 CVE-2017-5379: Use-after-free vulnerability in Web Animations when interacting with cycle collection found through Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51.
nvdosv
CVE-2025-8039P3HIGHCVSS 8.1fixed in 140.1fixed in 141.02025-07-22
CVE-2025-8039 [HIGH] CWE-200 CVE-2025-8039: In some cases search terms persisted in the URL bar even after navigating away from the search page. In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvd
CVE-2008-3837P3CRITICALCVSS 9.3fixed in 2.0.0.17≥ 3.0, < 3.0.22008-09-24
CVE-2008-3837 [CRITICAL] CVE-2008-3837: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assist Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
nvd
CVE-2006-2723P4MEDIUMCVSS 5.0PoCv2.02006-06-01
CVE-2006-2723 [MEDIUM] CVE-2006-2723: Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags. NOTE: a followup post indicated that the initial report could not be verified.
nvd
CVE-2018-5153P3HIGHCVSS 7.5fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5153 [HIGH] CWE-125 CVE-2018-5153: If websocket data is sent with mixed text and binary in a single message, the binary data can be cor If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read with the read memory sent to the originating server in response. This vulnerability affects Firefox < 60.
nvdosv
CVE-2014-1594P3MEDIUMCVSS 6.8≤ 31.2≤ 33.02014-12-11
CVE-2014-1594 [MEDIUM] CWE-20 CVE-2014-1594: Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey be Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute arbitrary code by leveraging an incorrect cast from the BasicThebesLayer data type to the BasicContainerLayer data type.
nvdosv
CVE-2016-5299P3HIGHCVSS 7.5fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-5299 [HIGH] CWE-275 CVE-2016-5299: A previously installed malicious Android application with same signature-level permissions as Firefo A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
nvd
CVE-2019-9809P3HIGHCVSS 7.5fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9809 [HIGH] CWE-399 CVE-2019-9809: If the source for resources on a page is through an FTP connection, it is possible to trigger a seri If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These messages cannot be immediately dismissed, allowing for a denial of service (DOS) attack. This vulnerability affects Firefox < 66.
nvdosv
CVE-2012-3991P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-3991 [CRITICAL] CWE-264 CVE-2012-3991: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to bypass the Same Origin Policy and possibly have unspecified other impact via a crafted web site.
nvd
CVE-2017-5382P3HIGHCVSS 7.5fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5382 [HIGH] CWE-200 CVE-2017-5382: Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged cont Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal information not meant to be seen by web content. This vulnerability affects Firefox < 51.
nvdosv
CVE-2018-5126P3CRITICALCVSS 9.8fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5126 [CRITICAL] CWE-119 CVE-2018-5126: Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 59.
nvdosv
CVE-2017-7765P3HIGHCVSS 7.5fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7765 [HIGH] CWE-20 CVE-2017-7765: The "Mark of the Web" was not correctly saved on Windows when files with very long names were downlo The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, the security warning that Windows displays before running executables downloaded from the Internet is not shown. Note: This attack only affects Windows operating systems. Other operating systems are
nvd
CVE-2015-7189P3MEDIUMCVSS 6.8v38.0v38.0.1+7 more2015-11-05
CVE-2015-7189 [MEDIUM] CWE-119 CVE-2015-7189: Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x befor Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
nvdosv
CVE-2009-2043P4MEDIUMCVSS 4.3PoCv3.0.2v3.0.3+7 more2009-06-12
CVE-2009-2043 [MEDIUM] CWE-20 CVE-2009-2043: nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE.
nvd
CVE-2016-9902P3HIGHCVSS 7.5fixed in 45.6.0fixed in 50.1+1 more2018-06-11
CVE-2016-9902 [HIGH] CWE-346 CVE-2016-9902: The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 a
nvd
CVE-2017-5381P3HIGHCVSS 7.5fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5381 [HIGH] CWE-22 CVE-2017-5381: The "export" function in the Certificate Viewer can force local filesystem navigation when the "comm The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerability affects Firefox < 51.
nvdosv
CVE-2019-9799P3HIGHCVSS 7.5fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9799 [HIGH] CWE-20 CVE-2019-9799: Insufficient bounds checking of data during inter-process communication might allow a compromised co Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.
nvdosv
Mozilla Firefox vulnerabilities | cvebase