Mozilla Firefox vulnerabilities

3,029 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,029
CISA KEV
15
actively exploited
Public exploits
118
Exploited in wild
20
Severity breakdown
CRITICAL853HIGH879MEDIUM1228LOW69

Vulnerabilities

Page 10 of 152
CVE-2025-10532MEDIUMCVSS 6.5fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10532 [MEDIUM] CWE-754 CVE-2025-10532: Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firef Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvd
CVE-2025-10536MEDIUMCVSS 6.2fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10536 [MEDIUM] CWE-200 CVE-2025-10536: Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 1 Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvd
CVE-2025-10531MEDIUMCVSS 5.4fixed in 143.02025-09-16
CVE-2025-10531 [MEDIUM] CWE-288 CVE-2025-10531: Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firef Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-10529MEDIUMCVSS 6.5fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10529 [MEDIUM] CWE-942 CVE-2025-10529: Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Fire Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvd
CVE-2025-10530MEDIUMCVSS 6.5fixed in 143.02025-09-16
CVE-2025-10530 [MEDIUM] CWE-290 CVE-2025-10530: Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Fir Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-9187CRITICALCVSS 9.8fixed in 142.02025-08-19
CVE-2025-9187 [CRITICAL] CWE-119 CVE-2025-9187: Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142 and Thunderbird 142.
nvd
CVE-2025-55031CRITICALCVSS 9.8fixed in 142.02025-08-19
CVE-2025-55031 [CRITICAL] CWE-601 CVE-2025-55031: Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passk Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability was fixed in Firefox for iOS 142 and Focus for iOS 142.
nvd
CVE-2025-54145CRITICALCVSS 9.1fixed in 141.02025-08-19
CVE-2025-54145 [CRITICAL] CWE-601 CVE-2025-54145: The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a mal The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme. This vulnerability was fixed in Firefox for iOS 141.
nvd
CVE-2025-54143CRITICALCVSS 9.8fixed in 141.02025-08-19
CVE-2025-54143 [CRITICAL] CWE-693 CVE-2025-54143: Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expecte Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
nvd
CVE-2025-8042CRITICALCVSS 9.8fixed in 141.02025-08-19
CVE-2025-8042 [CRITICAL] CWE-732 CVE-2025-8042: Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start down Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.
nvd
CVE-2025-9179CRITICALCVSS 9.8fixed in 115.27.0fixed in 142.0+2 more2025-08-19
CVE-2025-9179 [CRITICAL] CWE-119 CVE-2025-9179: An attacker was able to perform memory corruption in the GMP process which processes encrypted media An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.1
nvd
CVE-2025-9185HIGHCVSS 8.1fixed in 115.27.0fixed in 142.0+2 more2025-08-19
CVE-2025-9185 [HIGH] CWE-119 CVE-2025-9185: Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefo Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed
nvd
CVE-2025-55029HIGHCVSS 7.5fixed in 142.02025-08-19
CVE-2025-55029 [HIGH] CWE-400 CVE-2025-55029: Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial o Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed in Firefox for iOS 142.
nvd
CVE-2025-9184HIGHCVSS 8.1fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9184 [HIGH] CWE-119 CVE-2025-9184: Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderb
nvd
CVE-2025-9180HIGHCVSS 8.1fixed in 115.27.0fixed in 142.0+2 more2025-08-19
CVE-2025-9180 [HIGH] CWE-346 CVE-2025-9180: Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firef Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
nvd
CVE-2025-9182HIGHCVSS 7.5fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9182 [HIGH] CWE-400 CVE-2025-9182: Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.
nvd
CVE-2025-9183MEDIUMCVSS 6.5fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9183 [MEDIUM] CWE-451 CVE-2025-9183: Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.
nvd
CVE-2025-9186MEDIUMCVSS 6.5fixed in 142.02025-08-19
CVE-2025-9186 [MEDIUM] CWE-451 CVE-2025-9186: Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fix Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.
nvd
CVE-2025-9181MEDIUMCVSS 6.5fixed in 128.14.0fixed in 142.0+1 more2025-08-19
CVE-2025-9181 [MEDIUM] CWE-457 CVE-2025-9181: Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142 Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
nvd
CVE-2025-8364MEDIUMCVSS 4.3fixed in 141.02025-08-19
CVE-2025-8364 [MEDIUM] CWE-451 CVE-2025-8364: A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potent A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 141.
nvd