Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 89 of 162
CVE-2017-5385P3HIGHCVSS 7.5fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5385 [HIGH] CWE-200 CVE-2017-5385: Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore t
Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to potential information disclosure for sites using this header. This vulnerability affects Firefox < 51.
nvdosv
CVE-2012-1939P4CRITICALCVSS 9.3v10.0v10.0.1+3 more2012-06-05
CVE-2012-1939 [CRITICAL] CWE-119 CVE-2012-1939: jsinfer.cpp in Mozilla Firefox ESR 10.x before 10.0.5 and Thunderbird ESR 10.x before 10.0.5 does no
jsinfer.cpp in Mozilla Firefox ESR 10.x before 10.0.5 and Thunderbird ESR 10.x before 10.0.5 does not properly determine data types, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted JavaScript code.
nvd
CVE-2018-5136P3HIGHCVSS 7.5fixed in 59.0≥ unspecified, < 592018-06-11
CVE-2018-5136 [HIGH] CWE-20 CVE-2018-5136: A shared worker created from a "data:" URL in one tab can be shared by another tab with a different
A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vulnerability affects Firefox < 59.
nvdosv
CVE-2019-17010P3HIGHCVSS 7.5fixed in 71.0vbefore 712020-01-08
CVE-2019-17010 [HIGH] CWE-362 CVE-2019-17010: Under certain conditions, when checking the Resist Fingerprinting preference during device orientati
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2019-17011P3HIGHCVSS 7.5fixed in 71.0vbefore 712020-01-08
CVE-2019-17011 [HIGH] CWE-362 CVE-2019-17011: Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a rac
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2020-6821P3HIGHCVSS 7.5fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6821 [HIGH] CWE-908 CVE-2020-6821: When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSub
When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvdosv
CVE-2020-12423P3HIGHCVSS 7.8fixed in 78.0≥ unspecified, < 782020-07-09
CVE-2020-12423 [HIGH] CWE-427 CVE-2020-12423: When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was p
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. *Note: This issue only affects the Windows operating system; other operating systems are unaffected.* This vulnerability affects Firefox < 78.
nvd
CVE-2017-7760P3HIGHCVSS 7.8fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7760 [HIGH] CWE-417 CVE-2017-7760: The Mozilla Windows updater modifies some files to be updated by reading the original file and apply
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter through the Mozilla Maintenance Service, allowing the manipulation of files in the installation directory and privi
nvd
CVE-2007-4841P3CRITICALCVSS 9.3≤ 2.0.0.82007-09-12
CVE-2007-4841 [CRITICAL] CVE-2007-4841: Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote
Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file type handling on Windows XP with Internet Explorer 7 installed, a variant of CVE-2007-3845.
nvd
CVE-2018-12379P3HIGHCVSS 7.8fixed in 60.2.0fixed in 62.0+1 more2018-10-18
CVE-2018-12379 [HIGH] CWE-787 CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2
nvd
CVE-2019-17009P3HIGHCVSS 7.8fixed in 71.0vbefore 712020-01-08
CVE-2019-17009 [HIGH] CVE-2019-17009: When running, the updater service wrote status and log files to an unrestricted location; potentiall
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Th
nvd
CVE-2017-7835P3HIGHCVSS 7.3≤ 56.0.2≥ unspecified, < 572018-06-11
CVE-2017-7835 [HIGH] CVE-2017-7835: Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correct
Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resources that redirect from HTTPS to HTTP, allowing content that should be blocked, such as scripts, to be loaded on a page. This vulnerability affects Firefox < 57.
nvdosv
CVE-2019-9789P4CRITICALCVSS 9.8fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9789 [CRITICAL] CWE-787 CVE-2019-9789: Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of
Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 66.
nvdosv
CVE-2023-4048P3HIGHCVSS 7.5fixed in 116.0≥ 102.0, < 102.14+2 more2023-08-01
CVE-2023-4048 [HIGH] CWE-125 CVE-2023-4048: An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2023-32209P3HIGHCVSS 7.5fixed in 113.0≥ unspecified, < 1132023-06-19
CVE-2023-32209 [HIGH] CWE-787 CVE-2023-32209: A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects F
A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.
nvdosv
CVE-2017-7759P3HIGHCVSS 7.5fixed in 54.0≥ unspecified, < 542018-06-11
CVE-2017-7759 [HIGH] CWE-200 CVE-2017-7759: Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.
nvd
CVE-2023-25733P3HIGHCVSS 7.5fixed in 110.0≥ unspecified, < 1102023-06-19
CVE-2023-25733 [HIGH] CWE-252 CVE-2023-25733: The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potenti
The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null pointer dereference. This vulnerability affects Firefox < 110.
nvdosv
CVE-2022-34477P3HIGHCVSS 7.5fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34477 [HIGH] CWE-203 CVE-2022-34477: The MediaError message property should be consistent to avoid leaking information about cross-origin
The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.
nvdosv
CVE-2023-5170P3HIGHCVSS 7.4fixed in 118.0≥ unspecified, < 1182023-09-27
CVE-2023-5170 [HIGH] CWE-401 CVE-2023-5170: In canvas rendering, a compromised content process could have caused a surface to change unexpectedl
In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.
nvdosv
CVE-2007-0777P3CRITICALCVSS 9.3≥ 1.5, < 1.5.0.10≥ 2.0, < 2.0.0.22007-02-26
CVE-2007-0777 [CRITICAL] CWE-119 CVE-2007-0777: The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before
The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.
nvd