cbcvebase.

Mozilla Firefox vulnerabilities

3,257 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,257
CISA KEV
17
actively exploited
Public exploits
123
Exploited in wild
22
Severity breakdown
CRITICAL875HIGH984MEDIUM1324LOW72UNKNOWN2

Vulnerabilities

Page 15 of 163
CVE-2025-10859MEDIUMCVSS 4.0fixed in 143.1.02025-09-30
CVE-2025-10859 [MEDIUM] CWE-359 CVE-2025-10859: Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing co Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs. This vulnerability was fixed in Firefox for iOS 143.1.
nvdmozilla
CVE-2025-10537HIGHCVSS 8.8fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10537 [HIGH] CWE-119 CVE-2025-10537: Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunde
nvdmozilla
CVE-2025-10533HIGHCVSS 8.8fixed in 115.28.0fixed in 143.0+1 more2025-09-16
CVE-2025-10533 [HIGH] CWE-190 CVE-2025-10533: Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115. Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdmozilla
CVE-2025-10528HIGHCVSS 7.3fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10528 [HIGH] CWE-693 CVE-2025-10528: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdmozilla
CVE-2025-10527HIGHCVSS 7.1fixed in 140.3.0≤ 143.02025-09-16
CVE-2025-10527 [HIGH] CWE-416 CVE-2025-10527: Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fix Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdmozilla
CVE-2025-10534HIGHCVSS 8.1fixed in 143.02025-09-16
CVE-2025-10534 [HIGH] CWE-79 CVE-2025-10534: Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Th Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvdmozilla
CVE-2025-10535HIGHCVSS 7.5fixed in 143.02025-09-16
CVE-2025-10535 [HIGH] CWE-200 CVE-2025-10535: Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vuln Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 143.
nvdmozilla
CVE-2025-10536MEDIUMCVSS 6.2fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10536 [MEDIUM] CWE-200 CVE-2025-10536: Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 1 Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdmozilla
CVE-2025-10529MEDIUMCVSS 6.5fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10529 [MEDIUM] CWE-942 CVE-2025-10529: Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Fire Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdmozilla
CVE-2025-10530MEDIUMCVSS 6.5fixed in 143.02025-09-16
CVE-2025-10530 [MEDIUM] CWE-290 CVE-2025-10530: Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Fir Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvdmozilla
CVE-2025-10532MEDIUMCVSS 6.5fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10532 [MEDIUM] CWE-754 CVE-2025-10532: Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firef Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvdmozilla
CVE-2025-10531MEDIUMCVSS 5.4fixed in 143.02025-09-16
CVE-2025-10531 [MEDIUM] CWE-288 CVE-2025-10531: Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firef Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
nvdmozilla
CVE-2025-9187CRITICALCVSS 9.8fixed in 142.02025-08-19
CVE-2025-9187 [CRITICAL] CWE-119 CVE-2025-9187: Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142 and Thunderbird 142.
nvdmozilla
CVE-2025-9179CRITICALCVSS 9.8fixed in 115.27.0fixed in 142.0+2 more2025-08-19
CVE-2025-9179 [CRITICAL] CWE-119 CVE-2025-9179: An attacker was able to perform memory corruption in the GMP process which processes encrypted media An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.1
nvdmozilla
CVE-2025-8042CRITICALCVSS 9.8fixed in 141.02025-08-19
CVE-2025-8042 [CRITICAL] CWE-732 CVE-2025-8042: Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start down Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.
nvdmozilla
CVE-2025-55031CRITICALCVSS 9.8fixed in 142.02025-08-19
CVE-2025-55031 [CRITICAL] CWE-601 CVE-2025-55031: Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passk Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability was fixed in Firefox for iOS 142 and Focus for iOS 142.
nvdmozilla
CVE-2025-54145CRITICALCVSS 9.1fixed in 141.02025-08-19
CVE-2025-54145 [CRITICAL] CWE-601 CVE-2025-54145: The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a mal The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme. This vulnerability was fixed in Firefox for iOS 141.
nvdmozilla
CVE-2025-54143CRITICALCVSS 9.8fixed in 141.02025-08-19
CVE-2025-54143 [CRITICAL] CWE-693 CVE-2025-54143: Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expecte Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
nvdmozilla
CVE-2025-9184HIGHCVSS 8.1fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9184 [HIGH] CWE-119 CVE-2025-9184: Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderb
nvdmozilla
CVE-2025-9185HIGHCVSS 8.1fixed in 115.27.0fixed in 142.0+2 more2025-08-19
CVE-2025-9185 [HIGH] CWE-119 CVE-2025-9185: Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefo Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed
nvdmozilla