cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 10 of 162
CVE-2026-2634P3CRITICALCVSS 9.8fixed in 147.42026-02-24
CVE-2026-2634 [CRITICAL] CWE-451 CVE-2026-2634: Malicious scripts could cause desynchronization between the address bar and web content before a res Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability was fixed in Firefox for iOS 147.4.
nvd
CVE-2026-6768P3CRITICALCVSS 9.8fixed in 150.02026-04-21
CVE-2026-6768 [CRITICAL] CWE-288 CVE-2026-6768: Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-16407P3CRITICALCVSS 9.8fixed in 153.0.02026-07-21
CVE-2026-16407 [CRITICAL] CWE-284 CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-6760P3CRITICALCVSS 9.8fixed in 150.02026-04-21
CVE-2026-6760 [CRITICAL] CWE-288 CVE-2026-6760: Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2025-14860P3CRITICALCVSS 9.8fixed in 146.0.12025-12-18
CVE-2025-14860 [CRITICAL] CWE-416 CVE-2025-14860: Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146. Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.
nvd
CVE-2026-14241P3CRITICALCVSS 9.8v152.0.32026-06-30
CVE-2026-14241 [CRITICAL] CWE-787 CVE-2026-14241: Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corrupti Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
nvdmozilla
CVE-2026-2790P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2790 [CRITICAL] CWE-346 CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-16375P3CRITICALCVSS 9.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16375 [CRITICAL] CWE-346 CVE-2026-16375: Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2010-0166P4MEDIUMCVSS 5.1PoCv3.62010-03-25
CVE-2010-0166 [MEDIUM] CWE-119 CVE-2010-0166: The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mo The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary
nvd
CVE-2005-2262P4MEDIUMCVSS 5.1PoCv1.0.3v1.0.42005-07-13
CVE-2005-2262 [MEDIUM] CVE-2005-2262: Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tr Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."
nvd
CVE-2026-16380P3CRITICALCVSS 9.1fixed in 153.0.02026-07-21
CVE-2026-16380 [CRITICAL] CWE-693 CVE-2026-16380: Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thund Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16370P3CRITICALCVSS 9.1fixed in 153.0.02026-07-21
CVE-2026-16370 [CRITICAL] CWE-693 CVE-2026-16370: Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-12316P3CRITICALCVSS 9.1fixed in Firefox 152
CVE-2026-12316 [CRITICAL] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12316 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12316 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2026-16381P3CRITICALCVSS 9.1fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16381 [CRITICAL] CWE-346 CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2013-5618P3CRITICALCVSS 9.8fixed in 26.0≥ 24.0, < 24.22013-12-11
CVE-2013-5618 [CRITICAL] CWE-416 CVE-2013-5618: Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user inte Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.
nvd
CVE-2015-7182P3CRITICALCVSS 9.8v38.0v38.0.1+7 more2015-11-05
CVE-2015-7182 [CRITICAL] CWE-119 CVE-2015-7182: Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3. Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING d
nvd
CVE-2005-1476P4MEDIUMCVSS 5.1PoC≤ 1.0.32005-05-09
CVE-2005-1476 [MEDIUM] CVE-2005-1476: Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an I Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.
nvd
CVE-2012-4202P3CRITICALCVSS 9.3fixed in 10.0.11fixed in 17.02012-11-21
CVE-2012-4202 [CRITICAL] CWE-787 CVE-2012-4202: Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via a crafted GIF image.
nvd
CVE-2017-5397P3CRITICALCVSS 9.8fixed in 51.0.3≥ unspecified, < 51.0.32018-06-11
CVE-2017-5397 [CRITICAL] CWE-829 CVE-2017-5397: The cache directory on the local file system is set to be world writable. Firefox defaults to extrac The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3.
nvd
CVE-2020-12388P3CRITICALCVSS 10.0fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12388 [CRITICAL] CWE-20 CVE-2020-12388: The Firefox content processes did not sufficiently lockdown access control which could result in a s The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
nvd
Mozilla Firefox vulnerabilities | cvebase