Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 144 of 162
CVE-2026-10702P4MEDIUMCVSS 4.3fixed in 151.0.32026-06-02
CVE-2026-10702 [MEDIUM] CWE-843 CVE-2026-10702: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
nvdmozilla
CVE-2022-22743P4MEDIUMCVSS 4.3fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22743 [MEDIUM] CVE-2022-22743: When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab
When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2022-34472P4MEDIUMCVSS 4.3fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34472 [MEDIUM] CWE-703 CVE-2022-34472: If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2023-4581P4MEDIUMCVSS 4.3fixed in 117.0≥ 115.0, < 115.2+1 more2023-09-11
CVE-2023-4581 [MEDIUM] CVE-2023-4581: Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which all
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
nvd
CVE-2023-6868P4MEDIUMCVSS 4.3fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6868 [MEDIUM] CVE-2023-6868: In some instances, the user-agent would allow push requests which lacked a valid VAPID even though t
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties.
*This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.
nvd
CVE-2005-4685P4MEDIUMCVSS 6.4v0.8v0.9+15 more2005-12-31
CVE-2005-4685 [MEDIUM] CVE-2005-4685: Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-roo
Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker wh
nvd
CVE-2022-38474P4MEDIUMCVSS 4.3fixed in 104.0≥ unspecified, < 1042022-12-22
CVE-2022-38474 [MEDIUM] CWE-668 CVE-2022-38474: A website that had permission to access the microphone could record audio without the audio notifica
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This
nvd
CVE-2025-6425P4MEDIUMCVSS 4.3fixed in 115.25.0fixed in 140.0+1 more2025-06-24
CVE-2025-6425 [MEDIUM] CWE-200 CVE-2025-6425: An attacker who enumerated resources from the WebCompat extension could have obtained a persistent U
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
nvd
CVE-2025-6434P4MEDIUMCVSS 4.3fixed in 140.02025-06-24
CVE-2025-6434 [MEDIUM] CWE-1021 CVE-2025-6434: The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked a
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
nvd
CVE-2026-2032P4MEDIUMCVSS 4.3fixed in 147.2.12026-02-16
CVE-2026-2032 [MEDIUM] CWE-451 CVE-2026-2032: Malicious scripts that interrupt new tab page loading could cause desynchronization between the addr
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1.
nvd
CVE-2013-0751P4MEDIUMCVSS 5.8≤ 17.0.1v0.1+154 more2013-01-13
CVE-2013-0751 [MEDIUM] CWE-264 CVE-2013-0751: Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a
Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a single IFRAME element, which allows remote attackers to obtain sensitive information or possibly conduct cross-site scripting (XSS) attacks via a crafted HTML document.
nvd
CVE-2013-1726P4MEDIUMCVSS 6.2≤ 23.0.1v19.0+16 more2013-09-18
CVE-2013-1726 [MEDIUM] CWE-264 CVE-2013-1726: Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 2
Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
nvd
CVE-2008-4065P4MEDIUMCVSS 4.3fixed in 2.0.0.17≥ 3.0, < 3.0.22008-09-24
CVE-2008-4065 [MEDIUM] CWE-79 CVE-2008-4065: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey bef
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."
nvd
CVE-2009-2975P4MEDIUMCVSS 5.0v3.5.22009-08-27
CVE-2009-2975 [MEDIUM] CVE-2009-2975: Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configure
Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involvin
nvd
CVE-2015-0830P4MEDIUMCVSS 5.0≤ 35.0.1v0.1+213 more2015-02-25
CVE-2015-0830 [MEDIUM] CWE-399 CVE-2015-0830: The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copyin
The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content.
nvdosv
CVE-2004-0762P4MEDIUMCVSS 5.0≤ 0.92004-08-18
CVE-2004-0762 [MEDIUM] CVE-2004-0762: Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to instal
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.
nvd
CVE-2008-0594P4MEDIUMCVSS 5.0≤ 2.0.0.112008-02-09
CVE-2008-0594 [MEDIUM] CVE-2008-0594: Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire c
Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks.
nvd
CVE-2005-2266P4MEDIUMCVSS 5.0v0.8v0.9+10 more2005-07-13
CVE-2005-2266 [MEDIUM] CVE-2005-2266: Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other metho
Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in
nvd
CVE-2005-0590P4MEDIUMCVSS 5.0v0.8v0.9+6 more2005-05-02
CVE-2005-0590 [MEDIUM] CVE-2005-0590: The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
nvd
CVE-2022-3266P4MEDIUMCVSS 5.5fixed in 105.0≥ unspecified, < 1052022-12-22
CVE-2022-3266 [MEDIUM] CWE-125 CVE-2022-3266: An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd