Mozilla Firefox vulnerabilities

3,148 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,148
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL862HIGH921MEDIUM1295LOW70

Vulnerabilities

Page 87 of 158
CVE-2016-1958MEDIUMCVSS 4.3≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1958 [MEDIUM] CWE-254 CVE-2016-1958: browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allo browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.
nvd
CVE-2016-1965MEDIUMCVSS 4.3≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1965 [MEDIUM] CWE-254 CVE-2016-1965: Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that re Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.
nvd
CVE-2016-1522HIGHCVSS 8.8v38.0v38.0.1+11 more2016-02-13
CVE-2016-1522 [HIGH] CWE-119 CVE-2016-1522: Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
nvd
CVE-2016-1521HIGHCVSS 8.8≤ 42.0v38.0.1+11 more2016-02-13
CVE-2016-1521 [HIGH] CWE-119 CVE-2016-1521: The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla F The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application cras
nvd
CVE-2016-1526HIGHCVSS 8.1v38.0v38.0.1+11 more2016-02-13
CVE-2016-1526 [HIGH] CWE-119 CVE-2016-1526: The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozill The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smar
nvd
CVE-2016-1949HIGHCVSS 8.8≤ 44.0.12016-02-13
CVE-2016-1949 [HIGH] CWE-264 CVE-2016-1949: Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
nvdosv
CVE-2016-1523MEDIUMCVSS 6.5v38.0v38.0.1+11 more2016-02-13
CVE-2016-1523 [MEDIUM] CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozi The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
nvd
CVE-2016-1946CRITICALCVSS 9.8≤ 43.0.42016-01-31
CVE-2016-1946 [CRITICAL] CWE-119 CVE-2016-1946: The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox bef The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.
nvdosv
CVE-2016-1931CRITICALCVSS 10.0≤ 43.0.42016-01-31
CVE-2016-1931 [CRITICAL] CWE-119 CVE-2016-1931: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to uninitialized memory encountered during brotli data compression, and other vectors.
nvdosv
CVE-2016-1944CRITICALCVSS 9.8v43.0.42016-01-31
CVE-2016-1944 [CRITICAL] CWE-119 CVE-2016-1944: The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might a The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvdosv
CVE-2016-1930CRITICALCVSS 9.8≤ 43.0.4v38.0+5 more2016-01-31
CVE-2016-1930 [CRITICAL] CWE-119 CVE-2016-1930: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2016-1942HIGHCVSS 7.4≤ 43.0.42016-01-31
CVE-2016-1942 [HIGH] CWE-20 CVE-2016-1942: Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in t Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
nvdosv
CVE-2016-1945HIGHCVSS 8.8v43.0.42016-01-31
CVE-2016-1945 [HIGH] CVE-2016-1945: The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a den The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
nvdosv
CVE-2016-1935HIGHCVSS 8.8≤ 43.0.4v38.0+5 more2016-01-31
CVE-2016-1935 [HIGH] CWE-119 CVE-2016-1935: Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x be Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
nvdosv
CVE-2016-1933MEDIUMCVSS 6.5≤ 43.0.42016-01-31
CVE-2016-1933 [MEDIUM] CWE-189 CVE-2016-1933: Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remo Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted GIF image.
nvdosv
CVE-2016-1939MEDIUMCVSS 5.3≤ 43.0.42016-01-31
CVE-2016-1939 [MEDIUM] CVE-2016-1939: Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allo Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7208.
nvdosv
CVE-2016-1943MEDIUMCVSS 4.7v43.0.42016-01-31
CVE-2016-1943 [MEDIUM] CWE-17 CVE-2016-1943: Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scro Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
nvd
CVE-2016-1948MEDIUMCVSS 5.3v43.0.42016-01-31
CVE-2016-1948 [MEDIUM] CWE-310 CVE-2016-1948: Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme in Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.
nvd
CVE-2016-1940MEDIUMCVSS 5.3≤ 43.0.42016-01-31
CVE-2016-1940 [MEDIUM] CWE-17 CVE-2016-1940: Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.
nvd
CVE-2016-1941MEDIUMCVSS 6.1≤ 43.0.42016-01-31
CVE-2016-1941 [MEDIUM] CWE-79 CVE-2016-1941: The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
nvd