Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 97 of 162
CVE-2008-0419P4CRITICALCVSS 9.3≤ 2.0.0.112008-02-08
CVE-2008-0419 [CRITICAL] CWE-399 CVE-2008-0419: Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigati
Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize handles.
nvd
CVE-2015-2713P4MEDIUMCVSS 6.8≤ 37.0.2v31.0+6 more2015-05-14
CVE-2015-2713 [MEDIUM] CVE-2015-2713: Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 3
Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence contain
nvdosv
CVE-2009-3981P4CRITICALCVSS 9.3≤ 3.0.15v0.1+92 more2009-12-17
CVE-2009-3981 [CRITICAL] CVE-2009-3981: Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2
Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2016-9069P4HIGHCVSS 7.8fixed in 50.0≥ unspecified, < 502018-10-18
CVE-2016-9069 [HIGH] CWE-416 CVE-2016-9069: A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially ex
A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
nvdosv
CVE-2017-7814P4HIGHCVSS 7.8fixed in 52.4.0fixed in 56.0+1 more2018-06-11
CVE-2017-7814 [HIGH] CWE-20 CVE-2017-7814: File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks th
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firef
nvd
CVE-2015-7196P4MEDIUMCVSS 6.8≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-7196 [MEDIUM] CWE-17 CVE-2015-7196: Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow r
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (incorrect garbage collection and application crash) or possibly execute arbitrary code via a crafted Java applet that deallocates an in-use JavaScript wrapper.
nvdosv
CVE-2008-0412P4CRITICALCVSS 9.3≤ 2.0.0.112008-02-08
CVE-2008-0412 [CRITICAL] CWE-399 CVE-2008-0412: The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey be
The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableFrame::GetFrameAtOrBefore, (2) nsAccessibilityService::GetAccessible, (3) nsBindingManager::GetNestedI
nvd
CVE-2008-2786P4CRITICALCVSS 10.0v2.0v3.02008-06-19
CVE-2008-2786 [CRITICAL] CVE-2008-2786: Buffer overflow in Firefox 3.0 and 2.0.x has unknown impact and attack vectors. NOTE: due to lack o
Buffer overflow in Firefox 3.0 and 2.0.x has unknown impact and attack vectors. NOTE: due to lack of details as of 20080619, it is not clear whether this is the same issue as CVE-2008-2785. A CVE identifier has been assigned for tracking purposes.
nvd
CVE-2019-11696P4HIGHCVSS 7.8fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-11696 [HIGH] CWE-20 CVE-2019-11696: Files with the .JNLP extension used for "Java web start" applications are not treated as executable
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.
nvdosv
CVE-2006-3811P4HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3811 [HIGH] CVE-2006-3811: Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonke
Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in o
nvd
CVE-2006-4561P4HIGHCVSS 7.5v1.5.0.62006-09-06
CVE-2006-4561 [HIGH] CVE-2006-4561: Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of th
Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perfo
nvd
CVE-2009-2663P4CRITICALCVSS 9.3≤ 3.5.1v0.1+92 more2009-08-04
CVE-2009-2663 [CRITICAL] CWE-399 CVE-2009-2663: libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows co
libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.
nvd
CVE-2009-3388P4CRITICALCVSS 9.3v3.5.1v3.5.2+3 more2009-12-17
CVE-2009-3388 [CRITICAL] CWE-399 CVE-2009-3388: liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-depe
liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."
nvd
CVE-2006-1724P4HIGHCVSS 7.5≥ 1.0, < 1.0.8≥ 1.5, < 1.5.0.22006-04-14
CVE-2006-1724 [HIGH] CVE-2006-1724: Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Sui
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.
nvd
CVE-2020-15647P4HIGHCVSS 7.4fixed in 68.10.12020-08-10
CVE-2020-15647 [HIGH] CWE-200 CVE-2020-15647: A Content Provider in Firefox for Android allowed local files accessible by the browser to be read b
A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.
nvd
CVE-2018-12365P4MEDIUMCVSS 6.5fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-12365 [MEDIUM] CWE-200 CVE-2018-12365: A compromised IPC child process can escape the content sandbox and list the names of arbitrary files
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2012-4196P4MEDIUMCVSS 6.4fixed in 16.0.2≥ 10.0, < 10.0.102012-10-29
CVE-2012-4196 [MEDIUM] CWE-74 CVE-2012-4196: Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbi
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
nvd
CVE-2015-2715P4MEDIUMCVSS 6.8≤ 37.0.22015-05-14
CVE-2015-2715 [MEDIUM] CWE-362 CVE-2015-2715: Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0
Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) by leveraging improper Media Decoder Thread creation at the time of a shutdown.
nvdosv
CVE-2010-2762P4MEDIUMCVSS 6.8v3.6v3.6.2+5 more2010-09-09
CVE-2010-2762 [MEDIUM] CWE-264 CVE-2010-2762: The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Fir
The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privilege
nvd
CVE-2006-2776P4HIGHCVSS 7.5v0.8v0.9+17 more2006-06-02
CVE-2006-2776 [HIGH] CVE-2006-2776: Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined s
Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.
nvd