Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 90 of 162
CVE-2005-2269P4HIGHCVSS 7.5v0.8v0.9+10 more2005-07-13
CVE-2005-2269 [HIGH] CVE-2005-2269: Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associat
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom propert
nvd
CVE-2009-3074P4CRITICALCVSS 10.0≤ 3.0.13v0.1+91 more2009-09-10
CVE-2009-3074 [CRITICAL] CVE-2009-3074: Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote at
Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-2465P4CRITICALCVSS 10.0≤ 3.0.11v0.1+81 more2009-07-22
CVE-2009-2465 [CRITICAL] CWE-399 CVE-2009-2465: Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (m
Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.
nvd
CVE-2004-0867P4HIGHCVSS 7.5v0.9.22004-12-23
CVE-2004-0867 [HIGH] CWE-264 CVE-2004-0867: Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such a
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
nvd
CVE-2016-2824P4HIGHCVSS 8.8v45.1.0v45.1.1+1 more2016-06-13
CVE-2016-2824 [HIGH] CWE-119 CVE-2016-2824: The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x be
The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact by triggering use of a WebGL shader that writes to an array.
nvd
CVE-2016-1970P4HIGHCVSS 8.8≤ 44.0.22016-03-13
CVE-2016-1970 [HIGH] CWE-119 CVE-2016-1970: Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox bef
Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2008-4068P4HIGHCVSS 7.8fixed in 2.0.0.17≥ 3.0, < 3.0.22008-09-24
CVE-2008-4068 [HIGH] CWE-22 CVE-2008-4068: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbi
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a re
nvd
CVE-2015-2708P4HIGHCVSS 7.5≤ 37.0.2v31.0+6 more2015-05-14
CVE-2015-2708 [HIGH] CVE-2015-2708: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-4500P4HIGHCVSS 7.5≤ 40.0.3v38.0+6 more2015-09-24
CVE-2015-4500 [HIGH] CWE-119 CVE-2015-4500: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-7220P4CRITICALCVSS 10.0≤ 42.02015-12-16
CVE-2015-7220 [CRITICAL] CWE-119 CVE-2015-7220: Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0
Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.
nvdosv
CVE-2010-1201P4CRITICALCVSS 9.3v3.5v3.5.1+7 more2010-06-24
CVE-2010-1201 [CRITICAL] CVE-2010-1201: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-3383P4CRITICALCVSS 10.0v3.5.1v3.5.2+1 more2009-10-29
CVE-2009-3383 [CRITICAL] CVE-2009-3383: Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-4514P4HIGHCVSS 7.5≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-4514 [HIGH] CWE-119 CVE-2015-4514: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-0815P4HIGHCVSS 7.5≤ 31.5.3≤ 36.0.42015-04-01
CVE-2015-0815 [HIGH] CVE-2015-0815: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-0836P4HIGHCVSS 7.5v31.0v31.1.1+214 more2015-02-25
CVE-2015-0836 [HIGH] CVE-2015-0836: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-2709P4HIGHCVSS 7.5≤ 37.0.22015-05-14
CVE-2015-2709 [HIGH] CVE-2015-2709: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2015-0835P4HIGHCVSS 7.5≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0835 [HIGH] CVE-2015-0835: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2014-8635P4HIGHCVSS 7.5≤ 34.0.52015-01-14
CVE-2014-8635 [HIGH] CVE-2014-8635: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMon
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2023-23599P3MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23599 [MEDIUM] CWE-116 CVE-2023-23599: When copying a network request from the developer tools panel as a curl command the output was not b
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvdosv
CVE-2014-1574P4HIGHCVSS 7.5≤ 32.0v30.0+2 more2014-10-15
CVE-2014-1574 [HIGH] CVE-2014-1574: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv