Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 88 of 162
CVE-2006-0749P3CRITICALCVSS 9.3≥ 1.0, < 1.52006-04-14
CVE-2006-0749 [CRITICAL] CWE-399 CVE-2006-0749: nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozi
nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.
nvd
CVE-2016-2821P3HIGHCVSS 7.5≤ 46.0.1v45.1.0+1 more2016-06-13
CVE-2016-2821 [HIGH] CVE-2016-2821: Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and F
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.
nvd
CVE-2018-5144P3HIGHCVSS 7.3fixed in 52.7.02018-06-11
CVE-2018-5144 [HIGH] CWE-190 CVE-2018-5144: An integer overflow can occur during conversion of text to some Unicode character sets due to an unc
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvd
CVE-2017-5445P3HIGHCVSS 7.5fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5445 [HIGH] CWE-129 CVE-2017-5445: A vulnerability while parsing "application/http-index-format" format content where uninitialized val
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-5160P3HIGHCVSS 7.5fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5160 [HIGH] CWE-416 CVE-2018-5160: WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.
nvdosv
CVE-2008-1233P3MEDIUMCVSS 6.8≤ 2.0.0.122008-03-27
CVE-2008-1233 [MEDIUM] CWE-94 CVE-2008-1233: Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMo
Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via "XPCNativeWrapper pollution."
nvd
CVE-2007-0008P3MEDIUMCVSS 6.8≤ 1.5.0.9v0.1+39 more2007-02-26
CVE-2007-0008 [MEDIUM] CWE-189 CVE-2007-0008: Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message
nvd
CVE-2009-0774P3CRITICALCVSS 9.3≤ 3.0.6v1.0+48 more2009-03-05
CVE-2009-0774 [CRITICAL] CVE-2009-0774: The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonke
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.
nvd
CVE-2008-4063P4CRITICALCVSS 9.3≤ 3.0.1v3.02008-09-24
CVE-2008-4063 [CRITICAL] CVE-2008-4063: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to c
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME ex
nvd
CVE-2017-5422P3HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5422 [HIGH] CWE-20 CVE-2017-5422: If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can t
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer making "view-source:" linkable. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2021-29968P3HIGHCVSS 8.1fixed in 89.0.1≥ unspecified, < 89.0.12021-06-24
CVE-2021-29968 [HIGH] CWE-125 CVE-2021-29968: When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bu
When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1.
nvd
CVE-2010-1211P3CRITICALCVSS 9.3v3.5.1v3.5.2+12 more2010-07-30
CVE-2010-1211 [CRITICAL] CVE-2010-1211: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 an
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-0772P3CRITICALCVSS 9.3≤ 3.0.6v1.0+48 more2009-03-05
CVE-2009-0772 [CRITICAL] CWE-399 CVE-2009-0772: The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonke
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.
nvd
CVE-2015-0828P3MEDIUMCVSS 6.8≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0828 [MEDIUM] CVE-2015-0828: Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36
Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data.
nvd
CVE-2017-7806P3HIGHCVSS 7.5fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7806 [HIGH] CWE-416 CVE-2017-7806: A use-after-free vulnerability can occur when the layer manager is freed too early when rendering sp
A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.
nvdosv
CVE-2017-5421P3HIGHCVSS 7.5fixed in 52.0.≥ unspecified, < 522018-06-11
CVE-2017-5421 [HIGH] CWE-20 CVE-2017-5421: A malicious site could spoof the contents of the print preview window if popup windows are enabled,
A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is currently loaded. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2022-42927P3HIGHCVSS 8.1fixed in 106.0≥ unspecified, < 1062022-12-22
CVE-2022-42927 [HIGH] CWE-346 CVE-2022-42927: A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvdosv
CVE-2016-1978P3HIGHCVSS 7.3≤ 43.0.42016-03-13
CVE-2016-1978 [HIGH] CVE-2016-1978: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Sec
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
nvd
CVE-2011-3002P4CRITICALCVSS 9.3fixed in 7.02011-09-29
CVE-2011-3002 [CRITICAL] CWE-119 CVE-2011-3002: Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey bef
Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a memory-allocation error and a re
nvd
CVE-2013-1687P3CRITICALCVSS 9.3≤ 21.0v19.0+11 more2013-06-26
CVE-2013-1687 [CRITICAL] CWE-264 CVE-2013-1687: The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox bef
The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly restrict XBL user-defined functions, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges,
nvd