cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 85 of 162
CVE-2017-7766P3HIGHCVSS 7.8fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7766 [HIGH] CVE-2017-7766: An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and pri An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems
nvd
CVE-2019-5849P3CRITICALCVSS 9.8≥ 0, < 69.0+build2-0ubuntu0.16.04.4≥ 0, < 69.0+build2-0ubuntu0.18.04.12019-09-04
CVE-2019-5849 [CRITICAL] firefox vulnerabilities firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to obtain sensitive information, bypass Content Security Policy (CSP) protections, bypass same-origin restrictions, conduct cross-site scripting (XSS) attacks, cause a denial of service, or execute arbitrary code. (CVE-2019-5849, CVE-2019-11734, CVE-2019-11735, C
osv
CVE-2017-7836P3HIGHCVSS 7.8≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7836 [HIGH] CWE-427 CVE-2017-7836: The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of lib The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges. Note: This attack requires an attacker have local system access and only affects OS X and Linux. Windows systems a
nvd
CVE-2021-23961P3HIGHCVSS 7.4fixed in 85.0fixed in 852021-02-26
CVE-2021-23961 [HIGH] CVE-2021-23961: Further techniques that built on the slipstream research combined with a malicious webpage could hav Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
nvd
CVE-2019-9814P3CRITICALCVSS 9.8fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9814 [CRITICAL] CWE-787 CVE-2019-9814: Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 67.
nvdosv
CVE-2019-11734P3CRITICALCVSS 9.8fixed in 69.0≥ unspecified, < 692019-09-27
CVE-2019-11734 [CRITICAL] CWE-787 CVE-2019-11734: Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69.
nvdosv
CVE-2024-26283P3HIGHCVSS 7.8fixed in 123.02024-02-22
CVE-2024-26283 [HIGH] CWE-83 CVE-2024-26283: An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This vulnerability affects Firefox for iOS < 123.
nvd
CVE-2020-6826P3CRITICALCVSS 9.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6826 [CRITICAL] CWE-787 CVE-2020-6826: Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 75.
nvdosv
CVE-2023-37208P3HIGHCVSS 7.8fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37208 [HIGH] CWE-434 CVE-2023-37208: When opening Diagcab files, Firefox did not warn the user that these files may contain malicious cod When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2019-11753P3HIGHCVSS 7.8fixed in 60.9.0fixed in 69.0+1 more2019-09-27
CVE-2019-11753 [HIGH] CWE-354 CVE-2019-11753: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenanc
nvd
CVE-2023-32214P3HIGHCVSS 7.5fixed in 113.0≥ unspecified, < 1132023-06-19
CVE-2023-32214 [HIGH] CVE-2023-32214: Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of servic Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2013-0773P3CRITICALCVSS 9.3fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0773 [CRITICAL] CVE-2013-0773: The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox bef The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects o
nvd
CVE-2019-11723P3HIGHCVSS 7.5fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11723 [HIGH] CWE-346 CVE-2019-11723: A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.
nvdosv
CVE-2006-6500P3MEDIUMCVSS 6.8≥ 1.5, < 1.5.0.9≥ 2.0, < 2.0.0.12006-12-20
CVE-2006-6500 [MEDIUM] CWE-119 CVE-2006-6500: Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows
nvd
CVE-2017-5468P3CRITICALCVSS 9.1fixed in 53.0≥ unspecified, < 532018-06-11
CVE-2017-5468 [CRITICAL] CWE-665 CVE-2017-5468: An issue with incorrect ownership model of "privateBrowsing" information exposed through developer t An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53.
nvdosv
CVE-2025-9182P3HIGHCVSS 7.5fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9182 [HIGH] CWE-400 CVE-2025-9182: Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.
nvd
CVE-2016-1952P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1952 [HIGH] CWE-119 CVE-2016-1952: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2014-1497P3HIGHCVSS 8.8fixed in 28.0≥ 24.0, < 24.42014-03-19
CVE-2014-1497 [HIGH] CWE-125 CVE-2014-1497: The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x b The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impac
nvd
CVE-2014-1589P3MEDIUMCVSS 6.8≤ 33.02014-12-11
CVE-2014-1589 [MEDIUM] CWE-284 CVE-2014-1589: Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypass intended access restrictions via an XBL binding.
nvdosv
CVE-2016-2793P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2793 [HIGH] CWE-119 CVE-2016-2793: CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38 CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
nvd
Mozilla Firefox vulnerabilities | cvebase