Mozilla Mozilla

Do you want an email whenever new security vulnerabilities are reported in any Mozilla product?

Products by Mozilla Sorted by Most Security Vulnerabilities since 2018

Mozilla Firefox1024 vulnerabilities
Open source web browser

Mozilla Thunderbird633 vulnerabilities
Email client

Mozilla SeaMonkey193 vulnerabilities
Browser, email and newsgroup client

Mozilla Thunderbird Esr107 vulnerabilities

Mozilla Firefox Mobile19 vulnerabilities

Mozilla Focus15 vulnerabilities

Mozilla Firefox Focus8 vulnerabilities

Mozilla7 vulnerabilities

Mozilla Bleach5 vulnerabilities

Mozilla Nss4 vulnerabilities

Mozilla Vpn3 vulnerabilities

Mozilla Pollbot2 vulnerabilities

Mozilla Geckodriver2 vulnerabilities

Mozilla Firefox Os2 vulnerabilities

Mozilla Convict2 vulnerabilities

Mozilla Webthings Gateway2 vulnerabilities

Mozilla Camino2 vulnerabilities

Mozilla Zamboni1 vulnerability

Mozilla Nss Esr1 vulnerability

Mozilla Mozjpeg1 vulnerability

Mozilla Vpn1 vulnerability

Mozilla Hubs Cloud1 vulnerability

Mozilla Hawk1 vulnerability

Mozilla Common Voice1 vulnerability

Mozilla Bugzilla1 vulnerability

Recent Mozilla Security Advisories

Advisory Title Published
mfsa2024-18 Security Vulnerabilities fixed in Firefox 125 mfsa2024-18 April 16, 2024
mfsa2024-19 Security Vulnerabilities fixed in Firefox ESR 115.10 mfsa2024-19 April 16, 2024
mfsa2024-17 Security Vulnerabilities fixed in Firefox for iOS 124 mfsa2024-17 April 2, 2024
mfsa2024-16 Security Vulnerabilities fixed in Firefox ESR 115.9.1 mfsa2024-16 March 22, 2024
mfsa2024-15 Security Vulnerabilities fixed in Firefox 124.0.1 mfsa2024-15 March 22, 2024
mfsa2024-13 Security Vulnerabilities fixed in Firefox ESR 115.9 mfsa2024-13 March 19, 2024
mfsa2024-14 Security Vulnerabilities fixed in Thunderbird 115.9 mfsa2024-14 March 19, 2024
mfsa2024-12 Security Vulnerabilities fixed in Firefox 124 mfsa2024-12 March 19, 2024
mfsa2024-11 Security Vulnerabilities fixed in Thunderbird 115.8.1 mfsa2024-11 March 4, 2024
mfsa2024-05 Security Vulnerabilities fixed in Firefox 123 mfsa2024-05 February 20, 2024

Known Exploited Mozilla Vulnerabilities

The following Mozilla vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. CVE-2016-9079 June 22, 2023
Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 May 25, 2022
Mozilla Firefox and Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. CVE-2019-11707 May 23, 2022
Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. CVE-2019-11708 May 23, 2022
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service or possibly execute arbitrary code via a crafted web site. CVE-2013-1690 March 28, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 March 7, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 March 7, 2022
Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 March 3, 2022
Mozilla Firefox 74 and Firefox ESR 68.6 nsDocShell vulnerability A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6819 November 3, 2021
Mozilla Firefox 74 and Firefox ESR 68.6 ReadableStream vulnerability A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6820 November 3, 2021
Mozilla Firefox IonMonkey JIT compiler Type Confusion Vulnerability Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1 CVE-2019-17026 November 3, 2021

By the Year

In 2024 there have been 68 vulnerabilities in Mozilla with an average score of 6.8 out of ten. Last year Mozilla had 200 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Mozilla in 2024 could surpass last years number. Last year, the average CVE base score was greater by 0.44

Year Vulnerabilities Average Score
2024 68 6.77
2023 200 7.20
2022 186 7.44
2021 158 7.11
2020 180 7.26
2019 144 7.67
2018 129 7.63

It may take a day or so for new Mozilla vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla Security Vulnerabilities

Memory safety bugs present in Firefox 124

CVE-2024-3865 - April 16, 2024

Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.

Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9

CVE-2024-3864 - April 16, 2024

Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed

CVE-2024-3302 - April 16, 2024

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

The executable file warning was not presented when downloading .xrm-ms files

CVE-2024-3863 - April 16, 2024

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment

CVE-2024-3862 - April 16, 2024

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free

CVE-2024-3861 - April 16, 2024

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

An out-of-memory condition during object initialization could result in an empty shape list

CVE-2024-3860 - April 16, 2024

An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.

On 32-bit versions there were integer-overflows

CVE-2024-3859 - April 16, 2024

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

It was possible to mutate a JavaScript object so that the JIT could crash while tracing it

CVE-2024-3858 - April 16, 2024

It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.

The JIT created incorrect code for arguments in certain cases

CVE-2024-3857 - April 16, 2024

The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array

CVE-2024-3856 - April 16, 2024

A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads

CVE-2024-3855 - April 16, 2024

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads

CVE-2024-3854 - April 16, 2024

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started

CVE-2024-3853 - April 16, 2024

A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.

GetBoundName could return the wrong version of an object when JIT optimizations were applied

CVE-2024-3852 - April 16, 2024

GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9

CVE-2024-3864 - April 16, 2024

Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed

CVE-2024-3302 - April 16, 2024

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

The executable file warning was not presented when downloading .xrm-ms files

CVE-2024-3863 - April 16, 2024

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free

CVE-2024-3861 - April 16, 2024

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

On 32-bit versions there were integer-overflows

CVE-2024-3859 - April 16, 2024

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

The JIT created incorrect code for arguments in certain cases

CVE-2024-3857 - April 16, 2024

The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads

CVE-2024-3854 - April 16, 2024

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

GetBoundName could return the wrong version of an object when JIT optimizations were applied

CVE-2024-3852 - April 16, 2024

GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.

If an insecure element was added to a page after a delay, Firefox

CVE-2024-31392 - April 03, 2024

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

Dragging Javascript URLs to the address bar could cause them to be loaded

CVE-2024-31393 - April 03, 2024

Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.

An attacker was able to inject an event handler into a privileged object

CVE-2024-29944 - March 22, 2024

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination

CVE-2024-29943 - March 22, 2024

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

An attacker was able to inject an event handler into a privileged object

CVE-2024-29944 - March 22, 2024

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.

The permission prompt input delay could have expired while the window is not in focus

CVE-2024-2609 - March 19, 2024

The permission prompt input delay could have expired while the window is not in focus, which made the prompt vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124.

Memory safety bugs present in Firefox 123

CVE-2024-2615 - March 19, 2024

Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8

CVE-2024-2614 - March 19, 2024

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash

CVE-2024-2613 - March 19, 2024

Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`

CVE-2024-2612 - March 19, 2024

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions

CVE-2024-2611 - March 19, 2024

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Using a markup injection an attacker could have stolen nonce values

CVE-2024-2610 - March 19, 2024

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

The permission prompt input delay could have expired while the window is not in focus

CVE-2024-2609 - March 19, 2024

The permission prompt input delay could have expired while the window is not in focus, which made the prompt vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124.

NSS was susceptible to a timing side-channel attack when performing RSA decryption

CVE-2023-5388 - March 19, 2024

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

`AppendEncodedAttributeValue()

CVE-2024-2608 - March 19, 2024

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Return registers were overwritten which could have allowed an attacker to execute arbitrary code

CVE-2024-2607 - March 19, 2024

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values

CVE-2024-2606 - March 19, 2024

Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox

CVE-2024-2605 - March 19, 2024

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8

CVE-2024-2614 - March 19, 2024

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`

CVE-2024-2612 - March 19, 2024

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions

CVE-2024-2611 - March 19, 2024

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Using a markup injection an attacker could have stolen nonce values

CVE-2024-2610 - March 19, 2024

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

NSS was susceptible to a timing side-channel attack when performing RSA decryption

CVE-2023-5388 - March 19, 2024

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue

CVE-2024-2616 - March 19, 2024

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 and Thunderbird < 115.9.

`AppendEncodedAttributeValue()

CVE-2024-2608 - March 19, 2024

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Return registers were overwritten which could have allowed an attacker to execute arbitrary code

CVE-2024-2607 - March 19, 2024

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox

CVE-2024-2605 - March 19, 2024

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8

CVE-2024-2614 - March 19, 2024

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`

CVE-2024-2612 - March 19, 2024

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions

CVE-2024-2611 - March 19, 2024

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Using a markup injection an attacker could have stolen nonce values

CVE-2024-2610 - March 19, 2024

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

NSS was susceptible to a timing side-channel attack when performing RSA decryption

CVE-2023-5388 - March 19, 2024

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue

CVE-2024-2616 - March 19, 2024

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 and Thunderbird < 115.9.

`AppendEncodedAttributeValue()

CVE-2024-2608 - March 19, 2024

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Return registers were overwritten which could have allowed an attacker to execute arbitrary code

CVE-2024-2607 - March 19, 2024

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox

CVE-2024-2605 - March 19, 2024

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache

CVE-2024-1936 - March 04, 2024

The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird < 115.8.1.

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition

CVE-2024-1563 - February 22, 2024

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.

Upon scanning a JavaScript URI with the QR code scanner

CVE-2024-26281 - February 22, 2024

Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.

Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page

CVE-2024-26282 - February 22, 2024

Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme

CVE-2024-26283 - February 22, 2024

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This vulnerability affects Firefox for iOS < 123.

Utilizing a 302 redirect

CVE-2024-26284 - February 22, 2024

Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to the attacker's website. This vulnerability affects Focus for iOS < 123.

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses

CVE-2024-1551 - February 20, 2024

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

When storing and re-accessing data on a networking channel

CVE-2024-1546 - February 20, 2024

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Through a series of API calls and redirects

CVE-2024-1547 - February 20, 2024

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

A website could have obscured the fullscreen notification by using a dropdown select input element

CVE-2024-1548 - February 20, 2024

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

If a website set a large custom cursor

CVE-2024-1549 - February 20, 2024

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly

CVE-2024-1550 - February 20, 2024

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses

CVE-2024-1551 - February 20, 2024

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior

CVE-2024-1552 - February 20, 2024

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7

CVE-2024-1553 - February 20, 2024

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

When storing and re-accessing data on a networking channel

CVE-2024-1546 - February 20, 2024

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Through a series of API calls and redirects

CVE-2024-1547 - February 20, 2024

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

The `fetch()` API and navigation incorrectly shared the same cache

CVE-2024-1554 - February 20, 2024

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.

A website could have obscured the fullscreen notification by using a dropdown select input element

CVE-2024-1548 - February 20, 2024

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

If a website set a large custom cursor

CVE-2024-1549 - February 20, 2024

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly

CVE-2024-1550 - February 20, 2024

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected

CVE-2024-1555 - February 20, 2024

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior

CVE-2024-1556 - February 20, 2024

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123.

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior

CVE-2024-1552 - February 20, 2024

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7

CVE-2024-1553 - February 20, 2024

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Memory safety bugs present in Firefox 122

CVE-2024-1557 - February 20, 2024

Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123.

When storing and re-accessing data on a networking channel

CVE-2024-1546 - February 20, 2024

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Through a series of API calls and redirects

CVE-2024-1547 - February 20, 2024

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

A website could have obscured the fullscreen notification by using a dropdown select input element

CVE-2024-1548 - February 20, 2024

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

If a website set a large custom cursor

CVE-2024-1549 - February 20, 2024

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly

CVE-2024-1550 - February 20, 2024

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses

CVE-2024-1551 - February 20, 2024

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior

CVE-2024-1552 - February 20, 2024

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7

CVE-2024-1553 - February 20, 2024

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

When a user scans a QR Code with the QR Code Scanner feature

CVE-2024-0953 6.1 - Medium - February 05, 2024

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content.

Open Redirect

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar

CVE-2024-0749 4.3 - Medium - January 23, 2024

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.

Origin Validation Error

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash

CVE-2024-0741 6.5 - Medium - January 23, 2024

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

Memory Corruption

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load

CVE-2024-0742 4.3 - Medium - January 23, 2024

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

A Linux user opening the print preview dialog could have caused the browser to crash

CVE-2024-0746 6.5 - Medium - January 23, 2024

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

When a parent page loaded a child in an iframe with `unsafe-inline`

CVE-2024-0747 6.5 - Medium - January 23, 2024

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

A malicious devtools extension could have been used to escalate privileges

CVE-2024-0751 8.8 - High - January 23, 2024

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

Improper Privilege Management

Built by Foundeo Inc., with data from the National Vulnerability Database (NVD), Icons by Icons8. Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.