cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 95 of 162
CVE-2006-2787P4CRITICALCVSS 9.3v1.0v1.0.1+9 more2006-06-02
CVE-2006-2787 [CRITICAL] CVE-2006-2787: EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain priv EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.
nvd
CVE-2025-0244P4MEDIUMCVSS 5.3fixed in 134.02025-01-07
CVE-2025-0244 [MEDIUM] CWE-601 CVE-2025-0244: When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: Thi When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 134.
nvd
CVE-2022-45415P4HIGHCVSS 7.8fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45415 [HIGH] CWE-434 CVE-2022-45415: When downloading an HTML file, if the title of the page was formatted as a filename with a malicious When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.
nvd
CVE-2010-3771P4MEDIUMCVSS 6.8v3.6v3.6.2+112 more2010-12-10
CVE-2010-3771 [MEDIUM] CVE-2010-3771: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properl Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.
nvd
CVE-2014-8643P4HIGHCVSS 7.1≤ 34.0.52015-01-14
CVE-2014-8643 [HIGH] CWE-264 CVE-2014-8643: Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.
nvd
CVE-2015-0821P4MEDIUMCVSS 6.8≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0821 [MEDIUM] CWE-264 CVE-2015-0821: Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.
nvdosv
CVE-2011-2993P4CRITICALCVSS 9.3v4.0v4.0.1+1 more2011-08-18
CVE-2011-2993 [CRITICAL] CVE-2011-2993: The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2 The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-
nvd
CVE-2016-2825P4MEDIUMCVSS 6.5≤ 46.0.12016-06-13
CVE-2016-2825 [MEDIUM] CWE-284 CVE-2016-2825: Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
nvdosv
CVE-2021-23985P4MEDIUMCVSS 6.5fixed in 87.0≥ unspecified, < 872021-03-31
CVE-2021-23985 [MEDIUM] CVE-2021-23985: If an attacker is able to alter specific about:config values (for example malware running on the use If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unnoticable to the user. This would have allowed a remote attacker (able to make a direct network connection to the victim) to monitor the user's browsing activity
nvdosv
CVE-2017-7777P4HIGHCVSS 8.8fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7777 [HIGH] CWE-119 CVE-2017-7777: Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Load Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
nvd
CVE-2011-2668P4HIGHCVSS 8.8≤ 1.5.0.3v1.5.0.3 and earlier2020-01-21
CVE-2011-2668 [HIGH] CVE-2011-2668: Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header
nvd
CVE-2025-3028P4MEDIUMCVSS 6.5fixed in 115.22.0fixed in 137.0+1 more2025-04-01
CVE-2025-3028 [MEDIUM] CWE-416 CVE-2025-3028: JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-aft JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.
nvd
CVE-2018-18506P4MEDIUMCVSS 5.9fixed in 65.0≥ unspecified, < 652019-02-05
CVE-2018-18506 [MEDIUM] CVE-2018-18506: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file o When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attack
nvd
CVE-2012-0463P4HIGHCVSS 7.5≤ 3.6.27≤ 10.0+3 more2012-03-14
CVE-2012-0463 [HIGH] CWE-20 CVE-2012-0463: The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 1 The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 does not check the validity of an instance after event dispatching, which allows remote attackers to cause a d
nvd
CVE-2008-5017P4CRITICALCVSS 10.0≥ 2.0, < 2.0.0.18≥ 3.0, < 3.0.42008-11-13
CVE-2008-5017 [CRITICAL] CWE-189 CVE-2008-5017: Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.
nvd
CVE-2025-1414P4MEDIUMCVSS 6.5fixed in 135.0.12025-02-18
CVE-2025-1414 [MEDIUM] CWE-787 CVE-2025-1414: Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135.0.1.
nvdosv
CVE-2007-5959P4CRITICALCVSS 9.3v0.8v0.9+46 more2007-11-26
CVE-2007-5959 [CRITICAL] CVE-2007-5959: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 a Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption.
nvd
CVE-2024-7531P4MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7531 [MEDIUM] CWE-367 CVE-2024-7531: Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can resu Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection per
nvd
CVE-2024-4774P4MEDIUMCVSS 6.5fixed in 126.0≥ unspecified, < 1262024-05-14
CVE-2024-4774 [MEDIUM] CWE-758 CVE-2024-4774: The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing th The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.
nvdosv
CVE-2023-23597P4MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23597 [MEDIUM] CWE-326 CVE-2023-23597: A compromised web child process could disable web security opening restrictions, leading to a new ch A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This vulnerability affects Firefox < 109.
nvdosv