Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 110 of 162
CVE-2025-8027P4MEDIUMCVSS 6.5fixed in 115.26.0fixed in 141.0+2 more2025-07-22
CVE-2025-8027 [MEDIUM] CWE-457 CVE-2025-8027: On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack.
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvd
CVE-2025-8033P4MEDIUMCVSS 6.5fixed in 115.26.0fixed in 141.0+2 more2025-07-22
CVE-2025-8033 [MEDIUM] CWE-476 CVE-2025-8033: The JavaScript engine did not handle closed generators correctly and it was possible to resume them
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvd
CVE-2023-28164P4MEDIUMCVSS 6.5fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28164 [MEDIUM] CWE-346 CVE-2023-28164: Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user co
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2023-29549P4MEDIUMCVSS 6.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29549 [MEDIUM] CWE-326 CVE-2023-29549: Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incor
Under certain circumstances, a call to the bind function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosv
CVE-2025-9183P4MEDIUMCVSS 6.5fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9183 [MEDIUM] CWE-451 CVE-2025-9183: Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.
nvd
CVE-2022-22757P4MEDIUMCVSS 6.5fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22757 [MEDIUM] CWE-346 CVE-2022-22757: Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowe
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. *This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.
nvdosv
CVE-2025-9186P4MEDIUMCVSS 6.5fixed in 142.02025-08-19
CVE-2025-9186 [MEDIUM] CWE-451 CVE-2025-9186: Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fix
Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.
nvd
CVE-2025-11718P4MEDIUMCVSS 6.5fixed in 144.02025-10-14
CVE-2025-11718 [MEDIUM] CWE-451 CVE-2025-11718: When the address bar was hidden due to scrolling on Android, a malicious page could create a fake ad
When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.
nvd
CVE-2026-16397P4MEDIUMCVSS 6.5fixed in 153.0.02026-07-21
CVE-2026-16397 [MEDIUM] CWE-1021 CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fix
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
nvdmozilla
CVE-2004-0764P4CRITICALCVSS 10.0≤ 0.92004-08-18
CVE-2004-0764 [CRITICAL] CVE-2004-0764: Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.
nvd
CVE-2014-1501P4MEDIUMCVSS 5.8≤ 27.0.1v0.1+198 more2014-03-19
CVE-2014-1501 [MEDIUM] CWE-264 CVE-2014-1501: Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
nvd
CVE-2005-1531P4HIGHCVSS 7.5v0.8v0.9+9 more2005-05-12
CVE-2005-1531 [HIGH] CVE-2005-1531: Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security che
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."
nvd
CVE-2015-4507P4MEDIUMCVSS 5.1≤ 40.0.32015-09-24
CVE-2015-4507 [MEDIUM] CVE-2015-4507: The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debu
The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.
nvdosv
CVE-2024-2610P4MEDIUMCVSS 6.1fixed in 115.9.0fixed in 124.0+1 more2024-03-19
CVE-2024-2610 [MEDIUM] CWE-94 CVE-2024-2610: Using a markup injection an attacker could have stolen nonce values. This could have been used to by
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2024-9397P4MEDIUMCVSS 6.1fixed in 131.0≥ unspecified, < 1312024-10-01
CVE-2024-9397 [MEDIUM] CWE-1021 CVE-2024-9397: A missing delay in directory upload UI could have made it possible for an attacker to trick a user i
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2024-3859P4MEDIUMCVSS 5.9fixed in 115.10fixed in 125.0+1 more2024-04-16
CVE-2024-3859 [MEDIUM] CWE-125 CVE-2024-3859: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially c
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2005-1157P4HIGHCVSS 7.5v0.8v0.9+8 more2005-05-02
CVE-2005-1157 [HIGH] CVE-2005-1157: Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replac
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."
nvd
CVE-2019-11727P4MEDIUMCVSS 5.3fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11727 [MEDIUM] CWE-295 CVE-2019-11727: A vulnerability exists where it possible to force Network Security Services (NSS) to sign Certificat
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.
nvd
CVE-2014-1587P4MEDIUMCVSS 6.8≤ 31.2≤ 33.02014-12-11
CVE-2014-1587 [MEDIUM] CWE-20 CVE-2014-1587: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2008-1380P4CRITICALCVSS 9.3≤ 2.0.0.13v2.0+12 more2008-04-17
CVE-2008-1380 [CRITICAL] CVE-2008-1380: The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey
The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.
nvd