Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 102 of 162
CVE-2021-23986P4MEDIUMCVSS 6.5fixed in 87.0≥ unspecified, < 872021-03-31
CVE-2021-23986 [MEDIUM] CWE-346 CVE-2021-23986: A malicious extension with the 'search' permission could have installed a new search engine whose fa
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was
nvdosv
CVE-2005-0592P4HIGHCVSS 7.5v0.8v0.9+6 more2005-03-25
CVE-2005-0592 [HIGH] CVE-2005-0592: Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla bef
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.
nvd
CVE-2024-11708P4MEDIUMCVSS 6.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11708 [MEDIUM] CWE-362 CVE-2024-11708: Missing thread synchronization primitives could have led to a data race on members of the PlaybackPa
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
nvdosv
CVE-2025-1013P4MEDIUMCVSS 6.5fixed in 128.7.0fixed in 135.02025-02-04
CVE-2025-1013 [MEDIUM] CWE-362 CVE-2025-1013: A race condition could have led to private browsing tabs being opened in normal browsing windows. Th
A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2025-6429P4MEDIUMCVSS 6.5fixed in 128.12.0fixed in 140.02025-06-24
CVE-2025-6429 [MEDIUM] CWE-116 CVE-2025-6429: Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
nvd
CVE-2025-10530P4MEDIUMCVSS 6.5fixed in 143.02025-09-16
CVE-2025-10530 [MEDIUM] CWE-290 CVE-2025-10530: Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Fir
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvd
CVE-2025-5271P4MEDIUMCVSS 6.5fixed in 139.02025-05-27
CVE-2025-5271 [MEDIUM] CWE-116 CVE-2025-5271: Previewing a response in Devtools ignored CSP headers, which could have allowed content injection at
Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
nvd
CVE-2026-8388P4MEDIUMCVSS 6.5fixed in 150.0.32026-05-12
CVE-2026-8388 [MEDIUM] CWE-119 CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
nvdmozilla
CVE-2025-14744P4MEDIUMCVSS 6.5fixed in 144.02025-12-18
CVE-2025-14744 [MEDIUM] CWE-451 CVE-2025-14744: Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Fi
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0.
nvd
CVE-2015-4489P4HIGHCVSS 7.5≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4489 [HIGH] CWE-119 CVE-2015-4489: The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.
nvdosv
CVE-2005-2705P4HIGHCVSS 7.5≤ 1.0.6v1.0+5 more2005-09-23
CVE-2005-2705 [HIGH] CVE-2005-2705: Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 mi
Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.
nvd
CVE-2026-3846P4MEDIUMCVSS 6.5fixed in 148.0.22026-03-10
CVE-2026-3846 [MEDIUM] CWE-346 CVE-2026-3846: Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed
Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.
nvd
CVE-2015-4517P4HIGHCVSS 7.5≤ 40.0.3v38.0+6 more2015-09-24
CVE-2015-4517 [HIGH] CWE-119 CVE-2015-4517: NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote
NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
nvdosv
CVE-2008-5500P4CRITICALCVSS 10.0≥ 2.0, < 2.0.0.19≥ 3.0, < 3.0.52008-12-17
CVE-2008-5500 [CRITICAL] CWE-399 CVE-2008-5500: The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x befor
The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.
nvd
CVE-2024-6600P4MEDIUMCVSS 6.3fixed in 115.13fixed in 128.0+1 more2024-07-09
CVE-2024-6600 [MEDIUM] CWE-770 CVE-2024-6600: Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access c
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2006-1737P4CRITICALCVSS 9.3v1.0v1.0.1+7 more2006-04-14
CVE-2006-1737 [CRITICAL] CWE-189 CVE-2006-1737: Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla S
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.
nvd
CVE-2026-13356P4MEDIUMCVSS 6.3fixed in 152.32026-07-07
CVE-2026-13356 [MEDIUM] CWE-451 CVE-2026-13356: A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialo
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.
nvd
CVE-2024-2605P4MEDIUMCVSS 5.9fixed in 115.9.0fixed in 124.0+1 more2024-03-19
CVE-2024-2605 [MEDIUM] CVE-2024-2605: An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system esca
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2009-3987P4HIGHCVSS 7.8≤ 3.0.15v0.1+97 more2009-12-17
CVE-2009-3987 [HIGH] CWE-200 CVE-2009-3987: The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonk
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls t
nvd
CVE-2025-4084P4MEDIUMCVSS 5.7fixed in 115.23≥ 128.0, < 128.102025-04-29
CVE-2025-4084 [MEDIUM] CWE-116 CVE-2025-4084: Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker co
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system.
*This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox ESR 128.10, Firef
nvd