Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 15 of 162
CVE-2026-16365P3HIGHCVSS 8.8fixed in 153.0.02026-07-21
CVE-2026-16365 [HIGH] CWE-269 CVE-2026-16365: Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16366P3HIGHCVSS 8.8fixed in 153.0.02026-07-21
CVE-2026-16366 [HIGH] CWE-269 CVE-2026-16366: Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 a
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16401P3HIGHCVSS 8.8fixed in 153.0.02026-07-21
CVE-2026-16401 [HIGH] CWE-269 CVE-2026-16401: Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox
Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2010-3772P3CRITICALCVSS 9.3v3.6v3.6.2+112 more2010-12-10
CVE-2010-3772 [CRITICAL] CWE-189 CVE-2010-3772: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properl
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV element within a treechildren element.
nvd
CVE-2018-5146P3HIGHCVSS 8.8fixed in 52.7.2fixed in 59.0.12018-06-11
CVE-2018-5146 [HIGH] CWE-787 CVE-2018-5146: An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own co
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
nvdosv
CVE-2017-5456P3CRITICALCVSS 9.8fixed in 53.0fixed in 52.1.0+1 more2018-06-11
CVE-2017-5456 [CRITICAL] CWE-732 CVE-2017-5456: A mechanism to bypass file system access protections in the sandbox using the file system request co
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
nvdosv
CVE-2015-4497P3CRITICALCVSS 10.0v38.0v38.0.1+4 more2015-08-29
CVE-2015-4497 [CRITICAL] CVE-2015-4497: Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox befor
Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.
nvdosv
CVE-2026-12328P3HIGHCVSS 8.1fixed in 115.37.0fixed in 152.0+1 more2026-06-16
CVE-2026-12328 [HIGH] CWE-120 CVE-2026-12328: Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefo
Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Fir
nvdmozilla
CVE-2025-14333P3HIGHCVSS 8.1fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14333 [HIGH] CWE-787 CVE-2025-14333: Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird
Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunde
nvd
CVE-2012-4180P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4180 [CRITICAL] CWE-119 CVE-2012-4180: Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firef
Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2017-5391P3CRITICALCVSS 9.8fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5391 [CRITICAL] CVE-2017-5391: Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.
nvdosv
CVE-2011-0055P3CRITICALCVSS 10.0v3.6v3.6.2+96 more2011-03-02
CVE-2011-0055 [CRITICAL] CWE-399 CVE-2011-0055: Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.
Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via unspecified vectors related to the js_HasOwnProperty function and garbage collection.
nvd
CVE-2016-1950P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1950 [HIGH] CWE-119 CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
nvdosv
CVE-2025-1009P3CRITICALCVSS 9.8fixed in 115.20.0fixed in 135.0+1 more2025-02-04
CVE-2025-1009 [CRITICAL] CWE-416 CVE-2025-1009: An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially explo
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2015-2722P3CRITICALCVSS 10.0v31.0v31.1.0+7 more2015-07-06
CVE-2015-2722 [CRITICAL] CVE-2015-2722: Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.
nvdosv
CVE-2015-2733P3CRITICALCVSS 10.0≤ 38.1.0v31.0+7 more2015-07-06
CVE-2015-2733 [CRITICAL] CVE-2015-2733: Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.
nvdosv
CVE-2026-2796P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2796 [CRITICAL] CWE-843 CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2014-1544P3CRITICALCVSS 10.0≤ 30.0v24.0+4 more2014-07-23
CVE-2014-1544 [CRITICAL] CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Networ
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a
nvd
CVE-2025-49709P3CRITICALCVSS 9.8fixed in 139.0.42025-06-11
CVE-2025-49709 [CRITICAL] CWE-787 CVE-2025-49709: Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Fire
Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
nvd
CVE-2026-2771P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2771 [CRITICAL] CWE-125 CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, F
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd