Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 98 of 162
CVE-2014-8639P4MEDIUMCVSS 6.8≤ 34.0.5v31.0+3 more2015-01-14
CVE-2014-8639 [MEDIUM] CVE-2014-8639: Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey be
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to th
nvdosv
CVE-2016-1963P4HIGHCVSS 7.4≤ 44.0.22016-03-13
CVE-2016-1963 [HIGH] CWE-119 CVE-2016-1963: The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a
The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.
nvd
CVE-2015-7184P4MEDIUMCVSS 6.8≤ 41.0.12015-10-18
CVE-2015-7184 [MEDIUM] CWE-284 CVE-2015-7184: The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP r
The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvdosv
CVE-2016-2816P4MEDIUMCVSS 6.5≤ 45.0.22016-04-30
CVE-2016-2816 [MEDIUM] CWE-284 CVE-2016-2816: Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) prot
Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.
nvdosv
CVE-2006-3806P4HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3806 [HIGH] CWE-189 CVE-2006-3806: Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird b
Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."
nvd
CVE-2020-26964P4MEDIUMCVSS 6.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26964 [MEDIUM] CVE-2020-26964: If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version pri
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however,
nvd
CVE-2023-6209P4MEDIUMCVSS 6.5fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6209 [MEDIUM] CWE-22 CVE-2023-6209: Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2020-26965P4MEDIUMCVSS 6.5fixed in 83.0fixed in 832020-12-09
CVE-2020-26965 [MEDIUM] CWE-212 CVE-2020-26965: Some websites have a feature "Show Password" where clicking a button will change a password field in
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and t
nvd
CVE-2023-37207P4MEDIUMCVSS 6.5fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37207 [MEDIUM] CWE-470 CVE-2023-37207: A website could have obscured the fullscreen notification by using a URL with a scheme handled by an
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2010-0164P4CRITICALCVSS 9.3v3.62010-03-25
CVE-2010-0164 [CRITICAL] CWE-399 CVE-2010-0164: Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContaine
Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames h
nvd
CVE-2024-5692P4MEDIUMCVSS 6.5fixed in 115.12fixed in 127.0+1 more2024-06-11
CVE-2024-5692 [MEDIUM] CVE-2024-5692: On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser in
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firef
nvd
CVE-2025-0246P4MEDIUMCVSS 6.5fixed in 134.02025-01-07
CVE-2025-0246 [MEDIUM] CVE-2025-0246: When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue o
When using an invalid protocol scheme, an attacker could spoof the address bar.
*Note: This issue only affected Android operating systems. Other operating systems are unaffected.*
*Note: This issue is a different issue from CVE-2025-0244. This vulnerability was fixed in Firefox 134.
nvd
CVE-2013-6629P4MEDIUMCVSS 5.0fixed in 24.2fixed in 26.02013-11-19
CVE-2013-6629 [MEDIUM] CWE-200 CVE-2013-6629: The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive
nvd
CVE-2015-4487P4HIGHCVSS 7.5≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4487 [HIGH] CWE-119 CVE-2015-4487: The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2,
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
nvdosv
CVE-2026-8961P4MEDIUMCVSS 6.5fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8961 [MEDIUM] CWE-290 CVE-2026-8961: Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2025-10532P4MEDIUMCVSS 6.5fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10532 [MEDIUM] CWE-754 CVE-2025-10532: Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firef
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvd
CVE-2008-5052P4CRITICALCVSS 10.0≥ 2.0, < 2.0.0.182008-11-13
CVE-2008-5052 [CRITICAL] CWE-399 CVE-2008-5052: The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, T
The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.
nvd
CVE-2013-5619P4HIGHCVSS 7.5fixed in 26.02013-12-11
CVE-2013-5619 [HIGH] CWE-190 CVE-2013-5619: Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox be
Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2026-24868P4MEDIUMCVSS 6.5fixed in 147.0.22026-01-27
CVE-2026-24868 [MEDIUM] CWE-693 CVE-2026-24868: Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 1
Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.
nvd
CVE-2005-2702P4HIGHCVSS 7.5≤ 1.0.6v1.0+5 more2005-09-23
CVE-2005-2702 [HIGH] CVE-2005-2702: Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of se
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.
nvd