Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 99 of 162
CVE-2015-7175P4HIGHCVSS 7.5≤ 40.0.3v38.0+6 more2015-09-24
CVE-2015-7175 [HIGH] CWE-119 CVE-2015-7175: The XULContentSinkImpl::AddText function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before
The XULContentSinkImpl::AddText function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
nvdosv
CVE-2015-7174P4HIGHCVSS 7.5≤ 40.0.3v38.0+6 more2015-09-24
CVE-2015-7174 [HIGH] CWE-119 CVE-2015-7174: The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before
The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
nvdosv
CVE-2015-4522P4HIGHCVSS 7.5v38.0v38.0.1+6 more2015-09-24
CVE-2015-4522 [HIGH] CWE-119 CVE-2015-4522: The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x befor
The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
nvdosv
CVE-2012-0454P4HIGHCVSS 7.5v4.0v4.0.1+12 more2012-03-14
CVE-2012-0454 [HIGH] CWE-399 CVE-2012-0454: Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th
Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 on 32-bit Windows 7 platforms allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving use of
nvd
CVE-2026-6757P4MEDIUMCVSS 6.3fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6757 [MEDIUM] CWE-824 CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 15
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2015-7199P4HIGHCVSS 7.5≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-7199 [HIGH] CWE-119 CVE-2015-7199: The (1) AddWeightedPathSegLists and (2) SVGPathSegListSMILType::Interpolate functions in Mozilla Fir
The (1) AddWeightedPathSegLists and (2) SVGPathSegListSMILType::Interpolate functions in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lack status checking, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted SVG document.
nvdosv
CVE-2013-5607P4HIGHCVSS 7.5v17.0v17.0.1+22 more2013-11-20
CVE-2013-5607 [HIGH] CVE-2013-5607: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509
nvd
CVE-2006-3808P4HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3808 [HIGH] CVE-2006-3808: Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote Proxy AutoConfig (PAC) serve
Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote Proxy AutoConfig (PAC) servers to execute code with elevated privileges via a PAC script that sets the FindProxyForURL function to an eval method on a privileged object.
nvd
CVE-2017-7771P4HIGHCVSS 8.1fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7771 [HIGH] CWE-125 CVE-2017-7771: Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
nvd
CVE-2015-7200P4HIGHCVSS 7.5≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-7200 [HIGH] CWE-17 CVE-2015-7200: The CryptoKey interface implementation in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38
The CryptoKey interface implementation in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lacks status checking, which allows attackers to have an unspecified impact via vectors related to a cryptographic key.
nvdosv
CVE-2007-2867P4CRITICALCVSS 9.3v1.5v1.5.0.1+22 more2007-06-01
CVE-2007-2867 [CRITICAL] CWE-119 CVE-2007-2867: Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x befo
Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption, signed/unsigned, and other issue
nvd
CVE-2010-3174P4CRITICALCVSS 9.3v3.5v3.5.1+12 more2010-10-21
CVE-2010-3174 [CRITICAL] CVE-2010-3174: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird before 3.0.9, and SeaMonkey before 2.0.9 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-4510P4MEDIUMCVSS 6.8≤ 40.0.32015-09-24
CVE-2015-4510 [MEDIUM] CWE-362 CVE-2015-4510: Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows r
Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.
nvdosv
CVE-2018-5105P4HIGHCVSS 7.8≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5105 [HIGH] CVE-2018-5105: WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. Th
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.
nvdosv
CVE-2012-0458P4MEDIUMCVSS 6.8≤ 3.6.27≤ 10.0+3 more2012-03-14
CVE-2012-0458 [MEDIUM] CWE-264 CVE-2012-0458: Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird befo
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrar
nvd
CVE-2009-1840P4CRITICALCVSS 9.3≤ 3.0.10v3.0+11 more2009-06-12
CVE-2009-1840 [CRITICAL] CWE-264 CVE-2009-1840: Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
nvd
CVE-2012-3978P4MEDIUMCVSS 6.8v10.0v10.0.1+133 more2012-08-29
CVE-2012-3978 [MEDIUM] CWE-264 CVE-2012-3978: The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Th
The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspe
nvd
CVE-2009-3983P4MEDIUMCVSS 6.8≤ 3.0.15v0.1+97 more2009-12-17
CVE-2009-3983 [MEDIUM] CVE-2009-3983: Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote atta
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.
nvd
CVE-2006-3113P4HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3113 [HIGH] CVE-2006-3113: Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows re
Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to be deleted in a way that triggers memory corruption.
nvd
CVE-2014-1526P4MEDIUMCVSS 6.8fixed in 29.02014-04-30
CVE-2014-1526 [MEDIUM] CWE-269 CVE-2014-1526: The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-
The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.
nvdosv