Mozilla Firefox vulnerabilities
3,029 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,029
CISA KEV
15
actively exploited
Public exploits
118
Exploited in wild
20
Severity breakdown
CRITICAL853HIGH879MEDIUM1228LOW69
Vulnerabilities
Page 15 of 152
CVE-2025-1930HIGHCVSS 8.8fixed in 115.21.0fixed in 136.0+1 more2025-03-04
CVE-2025-1930 [HIGH] CWE-416 CVE-2025-1930: On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a u
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvd
CVE-2025-27426MEDIUMCVSS 5.4fixed in 136.02025-03-04
CVE-2025-27426 [MEDIUM] CWE-601 CVE-2025-27426: Malicious websites utilizing a server-side redirect to an internal error page could result in a spoo
Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.
nvd
CVE-2025-1935MEDIUMCVSS 4.3fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1935 [MEDIUM] CWE-79 CVE-2025-1935: A web page could trick a user into setting that site as the default handler for a custom URL protoco
A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvd
CVE-2025-1938MEDIUMCVSS 6.5fixed in 128.7.0fixed in 135.02025-03-04
CVE-2025-1938 [MEDIUM] CWE-787 CVE-2025-1938: Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderb
nvd
CVE-2025-27424MEDIUMCVSS 4.3fixed in 136.02025-03-04
CVE-2025-27424 [MEDIUM] CWE-601 CVE-2025-27424: Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a mali
Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.
nvd
CVE-2025-27425MEDIUMCVSS 4.3fixed in 136.02025-03-04
CVE-2025-27425 [MEDIUM] CWE-287 CVE-2025-27425: Scanning certain QR codes that included text with a website URL could allow the URL to be opened wit
Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.
nvd
CVE-2025-1934MEDIUMCVSS 6.5fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1934 [MEDIUM] CVE-2025-1934: It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, poten
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvd
CVE-2025-1939LOWCVSS 3.9fixed in 136.02025-03-04
CVE-2025-1939 [LOW] CWE-359 CVE-2025-1939: Android apps can load web pages using the Custom Tabs feature. This feature supports a transition an
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.
nvd
CVE-2025-1414MEDIUMCVSS 6.5fixed in 135.0.12025-02-18
CVE-2025-1414 [MEDIUM] CWE-787 CVE-2025-1414: Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135.0.1.
nvdosv
CVE-2025-1017CRITICALCVSS 9.8fixed in 128.7.0fixed in 135.02025-02-04
CVE-2025-1017 [CRITICAL] CWE-787 CVE-2025-1017: Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thun
nvd
CVE-2025-1020CRITICALCVSS 9.8fixed in 135.02025-02-04
CVE-2025-1020 [CRITICAL] CWE-787 CVE-2025-1020: Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2025-1009CRITICALCVSS 9.8fixed in 115.20.0fixed in 135.0+1 more2025-02-04
CVE-2025-1009 [CRITICAL] CWE-416 CVE-2025-1009: An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially explo
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2025-1016CRITICALCVSS 9.8fixed in 115.20.0fixed in 135.0+1 more2025-02-04
CVE-2025-1016 [CRITICAL] CWE-787 CVE-2025-1016: Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, T
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135, Firefo
nvd
CVE-2025-1014HIGHCVSS 8.8fixed in 128.7.0fixed in 135.02025-02-04
CVE-2025-1014 [HIGH] CWE-295 CVE-2025-1014: Certificate length was not properly checked when added to a certificate store. In practice only trus
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2025-1011HIGHCVSS 8.8fixed in 128.7.0fixed in 135.02025-02-04
CVE-2025-1011 [HIGH] CWE-94 CVE-2025-1011: A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an at
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdosv
CVE-2025-1012HIGHCVSS 7.5fixed in 115.20.0fixed in 135.0+1 more2025-02-04
CVE-2025-1012 [HIGH] CWE-416 CVE-2025-1012: A race during concurrent delazification could have led to a use-after-free. This vulnerability was f
A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2025-1010HIGHCVSS 8.8fixed in 115.20.0fixed in 135.0+1 more2025-02-04
CVE-2025-1010 [HIGH] CWE-416 CVE-2025-1010: An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentiall
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2025-1013MEDIUMCVSS 6.5fixed in 128.7.0fixed in 135.02025-02-04
CVE-2025-1013 [MEDIUM] CWE-362 CVE-2025-1013: A race condition could have led to private browsing tabs being opened in normal browsing windows. Th
A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2025-1018MEDIUMCVSS 5.3fixed in 135.02025-02-04
CVE-2025-1018 [MEDIUM] CWE-1021 CVE-2025-1018: The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the use
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv
CVE-2025-1019MEDIUMCVSS 4.3fixed in 135.02025-02-04
CVE-2025-1019 [MEDIUM] CWE-1021 CVE-2025-1019: The z-order of the browser windows could be manipulated to hide the fullscreen notification. This co
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosv