Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 17 of 162
CVE-2025-6436P3HIGHCVSS 8.1fixed in 140.02025-06-24
CVE-2025-6436 [HIGH] CWE-119 CVE-2025-6436: Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
nvd
CVE-2013-1738P3CRITICALCVSS 9.3≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1738 [CRITICAL] CWE-399 CVE-2013-1738: Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.
Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code by leveraging incorrect garbage collection in situations involving default compartments and frame-chain restoration.
nvd
CVE-2025-1941P3CRITICALCVSS 9.1fixed in 136.02025-03-04
CVE-2025-1941 [CRITICAL] CVE-2025-1941: Under certain circumstances, a user opt-in setting that Focus should require authentication before u
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firefox 136.
nvd
CVE-2026-16364P3CRITICALCVSS 9.1fixed in 153.0.02026-07-21
CVE-2026-16364 [CRITICAL] CWE-119 CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed i
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2009-3079P3CRITICALCVSS 10.0≤ 3.0.13v0.1+94 more2009-09-10
CVE-2009-3079 [CRITICAL] CWE-94 CVE-2009-3079: Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote at
Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter.
nvd
CVE-2024-3854P3HIGHCVSS 8.8fixed in 115.10fixed in 125.0+1 more2024-04-16
CVE-2024-3854 [HIGH] CWE-125 CVE-2024-3854: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2025-10533P3HIGHCVSS 8.8fixed in 115.28.0fixed in 143.0+1 more2025-09-16
CVE-2025-10533 [HIGH] CWE-190 CVE-2025-10533: Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvd
CVE-2013-0754P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0754 [CRITICAL] CWE-416 CVE-2013-0754: Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, F
Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors involving the trigger
nvd
CVE-2008-2419P4MEDIUMCVSS 4.3PoCv2.0.0.142008-05-23
CVE-2008-2419 [MEDIUM] CWE-399 CVE-2008-2419: Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and a
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript
nvd
CVE-2026-8974P3HIGHCVSS 8.8fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8974 [HIGH] CWE-119 CVE-2026-8974: Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence
Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2025-8035P3HIGHCVSS 8.8fixed in 128.13.0fixed in 141.0+1 more2025-07-22
CVE-2025-8035 [HIGH] CWE-119 CVE-2025-8035: Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunder
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Fir
nvd
CVE-2025-10537P3HIGHCVSS 8.8fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10537 [HIGH] CWE-119 CVE-2025-10537: Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunde
nvd
CVE-2026-16362P3HIGHCVSS 8.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16362 [HIGH] CWE-416 CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Fi
Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16371P3HIGHCVSS 8.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16371 [HIGH] CWE-269 CVE-2026-16371: Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153,
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16372P3HIGHCVSS 8.8fixed in 153.0.02026-07-21
CVE-2026-16372 [HIGH] CWE-269 CVE-2026-16372: Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefo
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2022-46872P3HIGHCVSS 8.6fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46872 [HIGH] CWE-125 CVE-2022-46872: An attacker who compromised a content process could have partially escaped the sandbox to read arbit
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2014-1557P3CRITICALCVSS 9.3≤ 30.0v24.0+4 more2014-07-23
CVE-2014-1557 [CRITICAL] CWE-94 CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a hig
nvdosv
CVE-2018-18492P3CRITICALCVSS 9.8fixed in 60.4.0fixed in 64.0+1 more2019-02-28
CVE-2018-18492 [CRITICAL] CWE-416 CVE-2018-18492: A use-after-free vulnerability can occur after deleting a selection element due to a weak reference
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2012-1941P3CRITICALCVSS 9.3v4.0v4.0.1+18 more2012-06-05
CVE-2012-1941 [CRITICAL] CWE-119 CVE-2012-1941: Heap-based buffer overflow in the nsHTMLReflowState::CalculateHypotheticalBox function in Mozilla Fi
Heap-based buffer overflow in the nsHTMLReflowState::CalculateHypotheticalBox function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code by resizing a window displaying absolutely positioned
nvd
CVE-2012-1947P3CRITICALCVSS 9.3v4.0v4.0.1+18 more2012-06-05
CVE-2012-1947 [CRITICAL] CWE-119 CVE-2012-1947: Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, F
Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.
nvd