cbcvebase.

Mozilla Firefox Mobile vulnerabilities

23 known vulnerabilities affecting mozilla/firefox_mobile.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH2MEDIUM3

Vulnerabilities

Page 1 of 2
CVE-2012-1133P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1133 [CRITICAL] CWE-119 CVE-2012-1133: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.
nvd
CVE-2012-1134P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1134 [CRITICAL] CWE-119 CVE-2012-1134: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted private-dictionary data in a Type 1 font.
nvd
CVE-2012-1126P3CRITICALCVSS 10.0≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1126 [CRITICAL] CWE-119 CVE-2012-1126: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF font.
nvd
CVE-2012-1144P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1144 [CRITICAL] CWE-119 CVE-2012-1144: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.
nvd
CVE-2012-1142P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1142 [CRITICAL] CWE-119 CVE-2012-1142: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a font.
nvd
CVE-2012-1136P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1136 [CRITICAL] CWE-119 CVE-2012-1136: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field.
nvd
CVE-2012-1132P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1132 [CRITICAL] CWE-119 CVE-2012-1132: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.
nvd
CVE-2012-1128P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1128 [CRITICAL] CWE-119 CVE-2012-1128: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.
nvd
CVE-2012-1141P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1141 [CRITICAL] CWE-119 CVE-2012-1141: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF font.
nvd
CVE-2012-1127P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1127 [CRITICAL] CWE-119 CVE-2012-1127: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.
nvd
CVE-2012-1139P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1139 [CRITICAL] CWE-119 CVE-2012-1139: Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and othe Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.
nvd
CVE-2012-1129P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1129 [CRITICAL] CWE-119 CVE-2012-1129: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.
nvd
CVE-2026-16373P3HIGHCVSS 7.5fixed in 153.02026-07-21
CVE-2026-16373 [HIGH] CWE-200 CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
nvd
CVE-2012-1135P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1135 [CRITICAL] CWE-119 CVE-2012-1135: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the NPUSHB and NPUSHW instructions in a TrueType font.
nvd
CVE-2012-1138P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1138 [CRITICAL] CWE-119 CVE-2012-1138: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font.
nvd
CVE-2012-1140P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1140 [CRITICAL] CWE-119 CVE-2012-1140: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted PostScript font object.
nvd
CVE-2012-1137P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1137 [CRITICAL] CWE-119 CVE-2012-1137: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted header in a BDF font.
nvd
CVE-2012-1130P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1130 [CRITICAL] CWE-119 CVE-2012-1130: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows re FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF font.
nvd
CVE-2012-1131P3CRITICALCVSS 9.3≤ 10.0.3v1.0+11 more2012-04-25
CVE-2012-1131 [CRITICAL] CWE-119 CVE-2012-1131: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors related to the cell table of a font.
nvd
CVE-2026-16404P3HIGHCVSS 7.4fixed in 153.02026-07-21
CVE-2026-16404 [HIGH] CWE-290 CVE-2026-16404: Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
nvd
Mozilla Firefox Mobile vulnerabilities | cvebase