Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 92 of 162
CVE-2018-5180P4HIGHCVSS 7.5fixed in 60.0≥ unspecified, < 602018-06-11
CVE-2018-5180 [HIGH] CWE-416 CVE-2018-5180: A use-after-free vulnerability can occur during WebGL operations. While this results in a potentiall
A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited because the memory is freed and reused in a brief window of time during the freeing of the same callstack. This vulnerability affects Firefox < 60.
nvdosv
CVE-2018-12401P4HIGHCVSS 7.5fixed in 63.0≥ unspecified, < 632019-02-28
CVE-2018-12401 [HIGH] CWE-20 CVE-2018-12401: Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters fol
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.
nvdosv
CVE-2010-0165P4CRITICALCVSS 9.3v3.62010-03-25
CVE-2010-0165 [CRITICAL] CWE-119 CVE-2010-0165: The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozil
The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.
nvd
CVE-2008-3835P4HIGHCVSS 7.5≤ 2.0.0.16v0.8+46 more2008-09-24
CVE-2008-3835 [HIGH] CWE-264 CVE-2008-3835: The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.
nvd
CVE-2016-5284P4HIGHCVSS 7.4≤ 48.0.2v45.0+5 more2016-09-22
CVE-2016-5284 [HIGH] CWE-20 CVE-2016-5284: Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.
nvd
CVE-2016-9068P3HIGHCVSS 7.5fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9068 [HIGH] CWE-416 CVE-2016-9068: A use-after-free during web animations when working with timelines resulting in a potentially exploi
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.
nvdosv
CVE-2009-3374P4HIGHCVSS 7.5v3.0v3.0.1+15 more2009-10-29
CVE-2009-3374 [HIGH] CWE-264 CVE-2009-3374: The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before
The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspec
nvd
CVE-2018-5101P4HIGHCVSS 7.5≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5101 [HIGH] CWE-416 CVE-2018-5101: A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, r
A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.
nvdosv
CVE-2017-5406P4HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5406 [HIGH] CWE-119 CVE-2017-5406: A segmentation fault can occur in the Skia graphics library during some canvas operations due to iss
A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2017-5416P4HIGHCVSS 7.5fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5416 [HIGH] CWE-476 CVE-2017-5416: In certain circumstances a networking event listener can be prematurely released. This appears to re
In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2015-0826P4MEDIUMCVSS 6.8≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0826 [MEDIUM] CWE-119 CVE-2015-0826: The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote at
The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascading Style Sheets (CSS) token sequence that triggers a restyle or reflow operation.
nvdosv
CVE-2014-1592P3MEDIUMCVSS 6.8≤ 31.2≤ 33.02014-12-11
CVE-2014-1592 [MEDIUM] CVE-2014-1592: Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox befo
Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code by adding a second root element to an HTML5 document during parsing.
nvdosv
CVE-2016-9072P4HIGHCVSS 7.5fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9072 [HIGH] CWE-254 CVE-2016-9072: When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and other operating systems are unaffected. This vulnerability affects Firefox < 50.
nvd
CVE-2010-3773P4MEDIUMCVSS 6.8v3.6v3.6.2+112 more2010-12-10
CVE-2010-3773 [MEDIUM] CVE-2010-3773: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttp
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response. NOTE: this vulne
nvd
CVE-2010-1212P4CRITICALCVSS 9.3v3.6.1v3.6.2+3 more2010-07-30
CVE-2010-1212 [CRITICAL] CWE-119 CVE-2010-1212: js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.
js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) propagation of deep aborts in the TraceRecorder::record_JSOP_BINDNAME function,
nvd
CVE-2020-15657P4HIGHCVSS 7.8fixed in 79.0≥ unspecified, < 792020-08-10
CVE-2020-15657 [HIGH] CWE-427 CVE-2020-15657: Firefox could be made to load attacker-supplied DLL files from the installation directory. This requ
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, an
nvd
CVE-2020-15681P3HIGHCVSS 7.5fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15681 [HIGH] CVE-2020-15681: When multiple WASM threads had a reference to a module, and were looking up exported functions, one
When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entry in a shared stub table, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 82.
nvdosv
CVE-2016-2826P4HIGHCVSS 7.8v45.1.0v45.1.1+1 more2016-06-13
CVE-2016-2826 [HIGH] CWE-264 CVE-2016-2826: The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows d
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.
nvd
CVE-2017-7794P4HIGHCVSS 7.8fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7794 [HIGH] CWE-276 CVE-2017-7794: On Linux systems, if the content process is compromised, the sandbox broker will allow files to be t
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 5
nvdosv
CVE-2016-5295P4HIGHCVSS 7.8fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-5295 [HIGH] CWE-264 CVE-2016-5295: This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege b
This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access and is a variant of MFSA2013-44. Note: this issue only affects Windows operating systems. This vulnerability affects
nvd