Mozilla Firefox vulnerabilities
3,029 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,029
CISA KEV
15
actively exploited
Public exploits
118
Exploited in wild
20
Severity breakdown
CRITICAL853HIGH879MEDIUM1228LOW69
Vulnerabilities
Page 1 of 152
CVE-2026-5734CRITICALCVSS 9.8fixed in 140.9.1fixed in 149.0.22026-04-07
CVE-2026-5734 [CRITICAL] CWE-787 CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thun
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunde
nvd
CVE-2026-5735CRITICALCVSS 9.8fixed in 149.0.22026-04-07
CVE-2026-5735 [CRITICAL] CWE-787 CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evi
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
nvd
CVE-2026-5732HIGHCVSS 8.8fixed in 140.9.1fixed in 149.0.22026-04-07
CVE-2026-5732 [HIGH] CWE-190 CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
nvd
CVE-2026-5733HIGHCVSS 8.8fixed in 149.0.22026-04-07
CVE-2026-5733 [HIGH] CWE-119 CVE-2026-5733: Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Fir
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
nvd
CVE-2026-4701CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4701 [CRITICAL] CWE-416 CVE-2026-4701: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Fire
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4725CRITICALCVSS 10.0fixed in 149.02026-03-24
CVE-2026-4725 [CRITICAL] CWE-416 CVE-2026-4725: Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fix
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-4689CRITICALCVSS 10.0fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4689 [CRITICAL] CWE-190 CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This v
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4688CRITICALCVSS 10.0fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4688 [CRITICAL] CWE-416 CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4711CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4711 [CRITICAL] CWE-416 CVE-2026-4711: Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox
Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4702CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4702 [CRITICAL] CWE-843 CVE-2026-4702: JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149,
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4710CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4710 [CRITICAL] CWE-119 CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4692CRITICALCVSS 10.0fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4692 [CRITICAL] CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149,
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4715CRITICALCVSS 9.1fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4715 [CRITICAL] CWE-908 CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 14
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4723CRITICALCVSS 9.8fixed in 149.02026-03-24
CVE-2026-4723 [CRITICAL] CWE-416 CVE-2026-4723: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and T
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-4691CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4691 [CRITICAL] CWE-416 CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4729CRITICALCVSS 9.8fixed in 149.02026-03-24
CVE-2026-4729 [CRITICAL] CWE-120 CVE-2026-4729: Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-4696CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4696 [CRITICAL] CWE-416 CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149,
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4705CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4705 [CRITICAL] CWE-758 CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149,
Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4698CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4698 [CRITICAL] CWE-843 CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4717CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4717 [CRITICAL] CVE-2026-4717: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firef
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
1 / 152Next →