Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 106 of 162
CVE-2025-9181P4MEDIUMCVSS 6.5fixed in 128.14.0fixed in 142.0+1 more2025-08-19
CVE-2025-9181 [MEDIUM] CWE-457 CVE-2025-9181: Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142
Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
nvd
CVE-2016-5288P4MEDIUMCVSS 5.9fixed in 49.0.2≥ unspecified, < 49.0.22018-06-11
CVE-2016-5288 [MEDIUM] CWE-200 CVE-2016-5288: Web content could access information in the HTTP cache if e10s is disabled. This can reveal some vis
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
nvdosv
CVE-2024-38312P4MEDIUMCVSS 6.5fixed in 127.02024-06-13
CVE-2024-38312 [MEDIUM] CWE-922 CVE-2024-38312: When browsing private tabs, some data related to location history or webpage thumbnails could be per
When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.
nvd
CVE-2026-8951P4MEDIUMCVSS 6.5fixed in 151.0.02026-05-19
CVE-2026-8951 [MEDIUM] CWE-290 CVE-2026-8951: Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Fire
Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.
nvdmozilla
CVE-2022-34471P4MEDIUMCVSS 6.5fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34471 [MEDIUM] CWE-345 CVE-2022-34471: When downloading an update for an addon, the downloaded addon update's version was not verified to m
When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.
nvdosv
CVE-2026-4728P4MEDIUMCVSS 6.5fixed in 149.02026-03-24
CVE-2026-4728 [MEDIUM] CWE-290 CVE-2026-4728: Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149
Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-12325P4MEDIUMCVSS 6.5fixed in Firefox 152
CVE-2026-12325 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12325
Mozilla Foundation Security Advisory 2026-57
CVE: CVE-2026-12325
Product: Firefox
Impact: high
Fixed in: Firefox 152
mozilla
CVE-2025-11716P4MEDIUMCVSS 6.5fixed in 144.02025-10-14
CVE-2025-11716 [MEDIUM] CWE-284 CVE-2025-11716: Links in a sandboxed iframe could open an external app on Android without the required "allow-" perm
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
nvd
CVE-2025-6431P4MEDIUMCVSS 6.5fixed in 140.02025-06-24
CVE-2025-6431 [MEDIUM] CWE-285 CVE-2025-6431: When a link can be opened in an external application, Firefox for Android will, by default, prompt t
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffect
nvd
CVE-2026-16403P4MEDIUMCVSS 6.5fixed in 153.0.02026-07-21
CVE-2026-16403 [MEDIUM] CWE-451 CVE-2026-16403: Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunder
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2019-9793P4MEDIUMCVSS 5.9fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9793 [MEDIUM] CWE-119 CVE-2019-9793: A mechanism was discovered that removes some bounds checking for string, array, or typed array acces
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have
nvd
CVE-2005-1153P4HIGHCVSS 7.5v0.8v0.9+8 more2005-05-02
CVE-2005-1153 [HIGH] CVE-2005-1153: Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers
Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.
nvd
CVE-2017-5384P4MEDIUMCVSS 5.9fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5384 [MEDIUM] CWE-200 CVE-2017-5384: Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the
Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information than would be sent to the proxy itself in the case of HTTPS. Normally the Proxy Auto-Config file is specified by the user or machine owner and presumed to be non-malicious, but if a user has enabled Web Prox
nvdosv
CVE-2015-4521P4HIGHCVSS 7.5≤ 40.0.3v38.0+6 more2015-09-24
CVE-2015-4521 [HIGH] CWE-119 CVE-2015-4521: The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 mi
The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
nvdosv
CVE-2015-7177P4HIGHCVSS 7.5≤ 40.0.3v38.0+6 more2015-09-24
CVE-2015-7177 [HIGH] CWE-119 CVE-2015-7177: The InitTextures function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allo
The InitTextures function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
nvdosv
CVE-2015-7180P4HIGHCVSS 7.5≤ 40.0.3v38.0+6 more2015-09-24
CVE-2015-7180 [HIGH] CWE-119 CVE-2015-7180: The ReadbackResultWriterD3D11::Run function in Mozilla Firefox before 41.0 and Firefox ESR 38.x befo
The ReadbackResultWriterD3D11::Run function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 misinterprets the return value of a function call, which might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
nvdosv
CVE-2010-0179P4MEDIUMCVSS 5.1≤ 3.0.17v0.1+91 more2010-04-05
CVE-2010-0179 [MEDIUM] CWE-94 CVE-2010-0179: Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRe
Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.
nvd
CVE-2026-6762P4MEDIUMCVSS 6.3fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6762 [MEDIUM] CWE-290 CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firef
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2006-3809P4HIGHCVSS 7.5v1.5v1.5.0.1+3 more2006-07-27
CVE-2006-3809 [HIGH] CVE-2006-3809: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows script
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a privileged context.
nvd
CVE-2025-4082P4MEDIUMCVSS 5.9fixed in 115.23fixed in 138.0+1 more2025-04-29
CVE-2025-4082 [MEDIUM] CWE-125 CVE-2025-4082: Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when ch
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.
*This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Th
nvd