cbcvebase.

Mozilla Firefox vulnerabilities

3,257 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,257
CISA KEV
17
actively exploited
Public exploits
123
Exploited in wild
22
Severity breakdown
CRITICAL875HIGH984MEDIUM1324LOW72UNKNOWN2

Vulnerabilities

Page 16 of 163
CVE-2025-9180HIGHCVSS 8.1fixed in 115.27.0fixed in 142.0+2 more2025-08-19
CVE-2025-9180 [HIGH] CWE-346 CVE-2025-9180: Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firef Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
nvdmozilla
CVE-2025-55029HIGHCVSS 7.5fixed in 142.02025-08-19
CVE-2025-55029 [HIGH] CWE-400 CVE-2025-55029: Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial o Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed in Firefox for iOS 142.
nvdmozilla
CVE-2025-9182HIGHCVSS 7.5fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9182 [HIGH] CWE-400 CVE-2025-9182: Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.
nvdmozilla
CVE-2025-55028MEDIUMCVSS 6.5fixed in 142.02025-08-19
CVE-2025-55028 [MEDIUM] CWE-400 CVE-2025-55028: Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in so Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed in Firefox for iOS 142.
nvdmozilla
CVE-2025-54144MEDIUMCVSS 5.4fixed in 141.02025-08-19
CVE-2025-54144 [MEDIUM] CWE-601 CVE-2025-54144: The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attac The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link. This vulnerability was fixed in Firefox for iOS 141.
nvdmozilla
CVE-2025-9181MEDIUMCVSS 6.5fixed in 128.14.0fixed in 142.0+1 more2025-08-19
CVE-2025-9181 [MEDIUM] CWE-457 CVE-2025-9181: Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142 Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
nvdmozilla
CVE-2025-9183MEDIUMCVSS 6.5fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9183 [MEDIUM] CWE-451 CVE-2025-9183: Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.
nvdmozilla
CVE-2025-9186MEDIUMCVSS 6.5fixed in 142.02025-08-19
CVE-2025-9186 [MEDIUM] CWE-451 CVE-2025-9186: Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fix Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.
nvdmozilla
CVE-2025-8041MEDIUMCVSS 5.3fixed in 141.02025-08-19
CVE-2025-8041 [MEDIUM] CWE-451 CVE-2025-8041: In the address bar, Firefox for Android truncated the display of URLs from the end instead of priori In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in Firefox 141.
nvdmozilla
CVE-2025-8364MEDIUMCVSS 4.3fixed in 141.02025-08-19
CVE-2025-8364 [MEDIUM] CWE-451 CVE-2025-8364: A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potent A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 141.
nvdmozilla
CVE-2025-55030MEDIUMCVSS 6.1fixed in 142.02025-08-19
CVE-2025-55030 [MEDIUM] CWE-640 CVE-2025-55030: Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrec Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks. This vulnerability was fixed in Firefox for iOS 142.
nvdmozilla
CVE-2025-8037CRITICALCVSS 9.1fixed in 140.1fixed in 141.02025-07-22
CVE-2025-8037 [CRITICAL] CWE-614 CVE-2025-8037: Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the namel Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvdmozilla
CVE-2025-8044CRITICALCVSS 9.8fixed in 141.02025-07-22
CVE-2025-8044 [CRITICAL] CWE-119 CVE-2025-8044: Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141 and Thunderbird 141.
nvdmozilla
CVE-2025-8031CRITICALCVSS 9.8fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8031 [CRITICAL] CWE-276 CVE-2025-8031: The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
nvdmozilla
CVE-2025-8038CRITICALCVSS 9.8fixed in 140.1.0fixed in 141.02025-07-22
CVE-2025-8038 [CRITICAL] CWE-345 CVE-2025-8038: Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability w Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvdmozilla
CVE-2025-8028CRITICALCVSS 9.8fixed in 115.26.0fixed in 141.0+2 more2025-07-22
CVE-2025-8028 [CRITICAL] CWE-1332 CVE-2025-8028: On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1
nvdmozilla
CVE-2025-8043CRITICALCVSS 9.8fixed in 141.02025-07-22
CVE-2025-8043 [CRITICAL] CWE-451 CVE-2025-8043: Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerabil Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.
nvdmozilla
CVE-2025-8036HIGHCVSS 8.1fixed in 140.1.0fixed in 141.02025-07-22
CVE-2025-8036 [HIGH] CWE-350 CVE-2025-8036: Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CO Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvdmozilla
CVE-2025-8040HIGHCVSS 8.8fixed in 140.1fixed in 141.02025-07-22
CVE-2025-8040 [HIGH] CWE-119 CVE-2025-8040: Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderb
nvdmozilla
CVE-2025-8034HIGHCVSS 8.8fixed in 115.26.0fixed in 141.0+2 more2025-07-22
CVE-2025-8034 [HIGH] CWE-119 CVE-2025-8034: Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefo Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed
nvdmozilla