cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 11 of 162
CVE-2012-3957P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3957 [CRITICAL] CWE-787 CVE-2012-3957: Heap-based buffer overflow in the nsBlockFrame::MarkLineDirty function in Mozilla Firefox before 15. Heap-based buffer overflow in the nsBlockFrame::MarkLineDirty function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2020-12389P3CRITICALCVSS 10.0fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12389 [CRITICAL] CWE-20 CVE-2020-12389: The Firefox content processes did not sufficiently lockdown access control which could result in a s The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
nvd
CVE-2020-6823P3CRITICALCVSS 9.8fixed in 75.0≥ unspecified, < 752020-04-24
CVE-2020-6823 [CRITICAL] CWE-862 CVE-2020-6823: A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling A malicious extension could have called browser.identity.launchWebAuthFlow, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.
nvdosv
CVE-2022-24791P3CRITICALCVSS 9.8≥ 0, < 1:1snap1-0ubuntu12022-03-31
CVE-2022-24791 [CRITICAL] CVE-2022-24791: Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and enabling epoch interruption in Wasmtime. If you are not explicitly enabling epoch interruption (it is disabled by default) then you are not affected. If you are explicitly disabling the Wasm reference type
osv
CVE-2009-1839P4MEDIUMCVSS 5.4PoC≤ 3.0.10v3.0+11 more2009-06-12
CVE-2009-1839 [MEDIUM] CWE-264 CVE-2009-1839: Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through th Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
nvd
CVE-2021-30547P3HIGHCVSS 8.8fixed in 97.02021-06-15
CVE-2021-30547 [HIGH] CWE-787 CVE-2021-30547: Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to po Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2026-4698P3CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4698 [CRITICAL] CWE-843 CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-2773P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2773 [CRITICAL] CWE-119 CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 14 Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2775P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2775 [CRITICAL] CWE-288 CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Fi Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2024-9392P3CRITICALCVSS 9.8fixed in 115.6.0fixed in 131.0+1 more2024-10-01
CVE-2024-9392 [CRITICAL] CWE-346 CVE-2024-9392: A compromised content process could have allowed for the arbitrary loading of cross-origin pages. Th A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
nvdosv
CVE-2026-2757P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2757 [CRITICAL] CWE-1384 CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2025-14324P3CRITICALCVSS 9.8fixed in 115.31.0fixed in 146.0+1 more2025-12-09
CVE-2025-14324 [CRITICAL] CWE-94 CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvd
CVE-2026-4691P3CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4691 [CRITICAL] CWE-416 CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4696P3CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4696 [CRITICAL] CWE-416 CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-2758P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2758 [CRITICAL] CWE-416 CVE-2026-2758: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-4702P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4702 [CRITICAL] CWE-843 CVE-2026-4702: JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-8091P3CRITICALCVSS 9.8fixed in 115.35.2≥ 140.0, < 140.10.12026-05-07
CVE-2026-8091 [CRITICAL] CWE-754 CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed i Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.
nvd
CVE-2026-2763P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2763 [CRITICAL] CWE-416 CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2770P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2770 [CRITICAL] CWE-416 CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2764P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2764 [CRITICAL] CWE-416 CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was f JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
Mozilla Firefox vulnerabilities | cvebase