Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 13 of 162
CVE-2024-29944P3HIGHCVSS 8.4fixed in 115.9.1≤ 124.0.1+1 more2024-03-22
CVE-2024-29944 [HIGH] CWE-830 CVE-2024-29944: An attacker was able to inject an event handler into a privileged object that would allow arbitrary
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.
nvd
CVE-2012-5829P3CRITICALCVSS 9.3fixed in 17.0≥ 10.0, < 10.0.112012-11-21
CVE-2012-5829 [CRITICAL] CWE-787 CVE-2012-5829: Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, F
Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2014-1486P3CRITICALCVSS 9.8fixed in 27.0≥ 24.0, < 24.32014-02-06
CVE-2014-1486 [CRITICAL] CWE-416 CVE-2014-1486: Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox
Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.
nvd
CVE-2023-5168P3CRITICALCVSS 9.8fixed in 118≥ unspecified, < 1182023-09-27
CVE-2023-5168 [CRITICAL] CWE-787 CVE-2023-5168: A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process.
*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbir
nvd
CVE-2018-18500P3CRITICALCVSS 9.8fixed in 65.02019-02-05
CVE-2018-18500 [CRITICAL] CWE-416 CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML e
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
nvdosv
CVE-2007-1377P4MEDIUMCVSS 5.0PoCv2.0.0.32007-03-10
CVE-2007-1377 [MEDIUM] CVE-2007-1377: AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remo
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027 and CVE-2006-6236.
nvd
CVE-2026-8956P3CRITICALCVSS 9.8fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8956 [CRITICAL] CWE-190 CVE-2026-8956: Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Fire
Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2024-8385P3CRITICALCVSS 9.8fixed in 130.0≥ unspecified, < 1302024-09-03
CVE-2024-8385 [CRITICAL] CWE-843 CVE-2024-8385: A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an expl
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvd
CVE-2026-0879P3CRITICALCVSS 9.8fixed in 115.32.0fixed in 147.0+1 more2026-01-13
CVE-2026-0879 [CRITICAL] CWE-119 CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability wa
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvd
CVE-2025-11708P3CRITICALCVSS 9.8fixed in 140.4.0fixed in 144.02025-10-14
CVE-2025-11708 [CRITICAL] CWE-416 CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, F
Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
nvd
CVE-2026-2772P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2772 [CRITICAL] CWE-416 CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148,
Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-16369P3CRITICALCVSS 9.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16369 [CRITICAL] CWE-190 CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 1
Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-4720P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4720 [CRITICAL] CWE-120 CVE-2026-4720: Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun
nvd
CVE-2026-6748P3CRITICALCVSS 9.8fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6748 [CRITICAL] CWE-457 CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2012-3968P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3968 [CRITICAL] CWE-416 CVE-2012-3968: Use-after-free vulnerability in the WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR
Use-after-free vulnerability in the WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via vectors related to deletion of a fragment shader by its accessor.
nvd
CVE-2026-2767P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2767 [CRITICAL] CWE-416 CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2777P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2777 [CRITICAL] CWE-269 CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148,
Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2025-13026P3CRITICALCVSS 9.8fixed in 145.02025-11-11
CVE-2025-13026 [CRITICAL] CWE-703 CVE-2025-13026: Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerab
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
nvd
CVE-2025-13023P3CRITICALCVSS 9.8fixed in 145.02025-11-11
CVE-2025-13023 [CRITICAL] CWE-703 CVE-2025-13023: Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerab
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
nvd
CVE-2026-16402P3CRITICALCVSS 9.8fixed in 153.0.02026-07-21
CVE-2026-16402 [CRITICAL] CWE-190 CVE-2026-16402: Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 an
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla