cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 93 of 162
CVE-2020-6830P4HIGHCVSS 7.5fixed in 25.02020-05-26
CVE-2020-6830 [HIGH] CWE-200 CVE-2020-6830: For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code ca For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.
nvd
CVE-2015-2706P4MEDIUMCVSS 6.8≤ 37.0.12015-04-27
CVE-2015-2706 [MEDIUM] CWE-362 CVE-2015-2706: Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37 Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.
nvdosv
CVE-2017-7797P4HIGHCVSS 7.5fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7797 [HIGH] CWE-346 CVE-2017-7797: Response header name interning does not have same-origin protections and these headers are stored in Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin. This vulnerability affects Firefox < 55.
nvdosv
CVE-2016-1938P4MEDIUMCVSS 6.5≤ 43.0.42016-01-31
CVE-2016-1938 [MEDIUM] CWE-310 CVE-2016-1938: The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21 The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.
nvd
CVE-2006-1727P4HIGHCVSS 7.6≥ 1.0, < 1.0.8≥ 1.5, < 1.5.0.22006-04-14
CVE-2006-1727 [HIGH] CVE-2006-1727: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0 Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".
nvd
CVE-2025-1933P3HIGHCVSS 7.6fixed in 115.21.0fixed in 136.0+1 more2025-03-04
CVE-2025-1933 [HIGH] CVE-2025-1933: On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over me On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosv
CVE-2006-3805P3HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3805 [HIGH] CVE-2006-3805: The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey b The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.
nvd
CVE-2009-2061P4CRITICALCVSS 9.3≤ 3.0.9v0.1+78 more2009-06-15
CVE-2009-2061 [CRITICAL] CWE-310 CVE-2009-2061: Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshak Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
nvd
CVE-2024-0741P3MEDIUMCVSS 6.5fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0741 [MEDIUM] CWE-787 CVE-2024-0741: An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potent An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvdosv
CVE-2006-2779P4CRITICALCVSS 9.3v0.8v0.9+20 more2006-06-02
CVE-2006-2779 [CRITICAL] CWE-94 CVE-2006-2779: Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service ( Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which l
nvd
CVE-2006-3807P3HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3807 [HIGH] CVE-2006-3807: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling "named JavaScript functions" that use the constructor.
nvd
CVE-2009-0071P4LOWCVSS 2.6PoCv3.0v3.0.1+4 more2009-01-08
CVE-2009-0071 [LOW] CWE-399 CVE-2009-0071: Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attacker Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call. NOTE: it was later reporte
nvd
CVE-2006-1734P3MEDIUMCVSS 6.8≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1734 [MEDIUM] CVE-2006-1734: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watch method to access the "clone parent" internal function.
nvd
CVE-2016-2831P4HIGHCVSS 8.8v45.1.0v45.1.1+1 more2016-06-13
CVE-2016-2831 [HIGH] CWE-254 CVE-2016-2831: Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves th Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
nvd
CVE-2018-12370P4HIGHCVSS 8.8fixed in 61.0≥ unspecified, < 612018-10-18
CVE-2018-12370 [HIGH] CWE-352 CVE-2018-12370: In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61.
nvdosv
CVE-2023-5388P4MEDIUMCVSS 6.5fixed in 115.9.0fixed in 124.0+1 more2024-03-19
CVE-2023-5388 [MEDIUM] CWE-203 CVE-2023-5388: NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack coul NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2015-4513P4HIGHCVSS 7.5≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-4513 [HIGH] CWE-119 CVE-2015-4513: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2008-5018P4CRITICALCVSS 10.0≥ 2.0, < 2.0.0.18≥ 3.0, < 3.0.42008-11-13
CVE-2008-5018 [CRITICAL] CWE-399 CVE-2008-5018: The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.
nvd
CVE-2026-0885P3MEDIUMCVSS 6.5fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0885 [MEDIUM] CWE-416 CVE-2026-0885: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvd
CVE-2012-0462P4HIGHCVSS 7.5v4.0v4.0.1+12 more2012-03-14
CVE-2012-0462 [HIGH] CVE-2012-0462: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Fire Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vec
nvd
Mozilla Firefox vulnerabilities | cvebase