Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 16 of 162
CVE-2012-3963P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3963 [CRITICAL] CWE-416 CVE-2012-3963: Use-after-free vulnerability in the js::gc::MapAllocToTraceKind function in Mozilla Firefox before 1
Use-after-free vulnerability in the js::gc::MapAllocToTraceKind function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2026-0892P3CRITICALCVSS 9.8fixed in 147.02026-01-13
CVE-2026-0892 [CRITICAL] CWE-119 CVE-2026-0892: Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
nvd
CVE-2024-1554P3CRITICALCVSS 9.8fixed in 123.0≥ unspecified, < 1232024-02-20
CVE-2024-1554 [CRITICAL] CWE-345 CVE-2024-1554: The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same UR
nvdosv
CVE-2026-2785P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2785 [CRITICAL] CWE-824 CVE-2026-2785: Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Fir
Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2025-11721P3CRITICALCVSS 9.8≥ 143.0, < 144.02025-10-14
CVE-2025-11721 [CRITICAL] CWE-119 CVE-2025-11721: Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory cor
Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
nvd
CVE-2026-4729P3CRITICALCVSS 9.8fixed in 149.02026-03-24
CVE-2026-4729 [CRITICAL] CWE-120 CVE-2026-4729: Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-2799P3CRITICALCVSS 9.8fixed in 148.02026-02-24
CVE-2026-2799 [CRITICAL] CWE-416 CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Th
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2026-12293P3CRITICALCVSS 9.8fixed in 152.0.02026-06-16
CVE-2026-12293 [CRITICAL] CWE-416 CVE-2026-12293: Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Th
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
nvdmozilla
CVE-2011-0085P3CRITICALCVSS 10.0≤ 3.6.17v1.0+103 more2011-06-30
CVE-2011-0085 [CRITICAL] CWE-399 CVE-2011-0085: Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18
Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.
nvd
CVE-2011-2378P3CRITICALCVSS 10.0≤ 3.6.19v1.0+105 more2011-08-18
CVE-2011-2378 [CRITICAL] CWE-94 CVE-2011-2378: The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey
The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."
nvd
CVE-2026-12297P3CRITICALCVSS 9.6fixed in 115.37.0fixed in 152.0.0+1 more2026-06-16
CVE-2026-12297 [CRITICAL] CWE-119 CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-12296P3CRITICALCVSS 9.6fixed in 140.12.0fixed in 152.0.02026-06-16
CVE-2026-12296 [CRITICAL] CWE-693 CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefo
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2013-5600P3CRITICALCVSS 10.0≤ 24.0v19.0+21 more2013-10-30
CVE-2013-5600 [CRITICAL] CVE-2013-5600: Use-after-free vulnerability in the nsIOService::NewChannelFromURIWithProxyFlags function in Mozilla
Use-after-free vulnerability in the nsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code via vectors involving a blob: URL.
nvd
CVE-2013-5601P3CRITICALCVSS 10.0≤ 24.0v19.0+21 more2013-10-30
CVE-2013-5601 [CRITICAL] CVE-2013-5601: Use-after-free vulnerability in the nsEventListenerManager::SetEventHandler function in Mozilla Fire
Use-after-free vulnerability in the nsEventListenerManager::SetEventHandler function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code via vectors related to a memory allocation through
nvd
CVE-2012-5839P3CRITICALCVSS 9.3fixed in 10.0.11fixed in 17.02012-11-21
CVE-2012-5839 [CRITICAL] CWE-787 CVE-2012-5839: Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla
Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-3973P3HIGHCVSS 7.6≤ 14.0v1.0+129 more2012-08-29
CVE-2012-3973 [HIGH] CWE-264 CVE-2012-3973: The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging
The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging the presence of the HTTPMonitor extension and connecting to that service through the HTTPMonitor port.
nvd
CVE-2011-0084P3CRITICALCVSS 10.0≤ 3.6.19v1.0+108 more2011-08-18
CVE-2011-0084 [CRITICAL] CWE-94 CVE-2011-0084: The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangli
nvd
CVE-2009-0775P3CRITICALCVSS 10.0≤ 3.0.6v1.0+48 more2009-03-05
CVE-2009-0775 [CRITICAL] CWE-399 CVE-2009-0775: Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonke
Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.
nvd
CVE-2016-5280P3CRITICALCVSS 9.8≤ 48.0.2v45.0+5 more2016-09-22
CVE-2016-5280 [CRITICAL] CWE-416 CVE-2016-5280: Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap funct
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text.
nvd
CVE-2026-8948P3CRITICALCVSS 9.1fixed in 151.0.02026-05-19
CVE-2026-8948 [CRITICAL] CWE-942 CVE-2026-8948: Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla