mozilla firefox
500 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
allow-downloads attribute to start downloads. This vulnerability wasusername:password part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication crejavascript: URLs when used in object and embed tags. This vulnerability was fixed in Firefox 141, Firefbr_table instruction with a lot of entries could lead to the label being too far from the instruction causing tContent-Disposition header, that directive would be ignored if the file was included vconnect-src directive of a Content Security Policy by manipulating subdocuments. This would hterminal extension. *This bug only affects FirefoxOrderedHashTable used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0vpx_codec_enc_init_multi after a failed allocation when initializing the encoder for WebRTCPromise object. This vulnerability was fixed in F.url shortcut from the local filesystem, an unexpected file could be uploaded. *This bug opk12util, and specifically in the SEC_ASN1DecodeItem_Util functiNSC_DeriveKey inadvertently assumed that the phKey parameter is always non-NULL. When it was passed as NULL, a segmentation fasec_pkcs7_decoder_start_decrypt() when handling an error path. Under specific conditiloadManifestFromFile method during add-on signature verification.frame-src bypass and DOM-based XSS through the GContent-Disposition: attachment in the response header was not respected and did not foriframe. This vulnerabilitembed or object elements. This vulnerabilitwindow.open with specifically set protocol handlers, an attacker could determine if the appliresource://devtools originresource://pdf.js origin.withPK11_Encrypt() in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel SaStreamFilter which could be used to read and modify the__Secure were being ignored if they were not correctly capitalized - by spec they<input> tag, an attacker could have caused corrupt memory leading to a potentially exploitaX-Frame-Options header, a sandboxed iframe could have presented a button that, if clicked by a us