Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 19 of 162
CVE-2016-1931P3CRITICALCVSS 10.0≤ 43.0.42016-01-31
CVE-2016-1931 [CRITICAL] CWE-119 CVE-2016-1931: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to uninitialized memory encountered during brotli data compression, and other vectors.
nvdosv
CVE-2015-4493P3CRITICALCVSS 9.3≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4493 [CRITICAL] CVE-2015-4493: Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.
nvdosv
CVE-2016-1962P3CRITICALCVSS 9.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1962 [CRITICAL] CVE-2016-1962: Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefo
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.
nvd
CVE-2009-3985P4MEDIUMCVSS 6.8PoC≤ 3.0.15v0.1+97 more2009-12-17
CVE-2009-3985 [MEDIUM] CVE-2009-3985: Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote atta
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.
nvd
CVE-2026-12295P3CRITICALCVSS 9.6fixed in 115.37.0fixed in 152.0.0+1 more2026-06-16
CVE-2026-12295 [CRITICAL] CWE-693 CVE-2026-12295: Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefo
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-12294P3CRITICALCVSS 9.6fixed in 115.37.0fixed in 152.0.0+1 more2026-06-16
CVE-2026-12294 [CRITICAL] CWE-693 CVE-2026-12294: Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox E
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-7321P3CRITICALCVSS 9.6fixed in 140.10.1fixed in 150.02026-04-28
CVE-2026-7321 [CRITICAL] CWE-120 CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulner
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.
nvd
CVE-2005-4134P4MEDIUMCVSS 5.0PoC≤ 1.52005-12-09
CVE-2005-4134 [MEDIUM] CVE-2005-4134: Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to c
Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. NOTE: despite initial reports, the Mozilla vendor does not believe that
nvd
CVE-2013-0787P3CRITICALCVSS 9.3≤ 19.0.1v19.0+4 more2013-03-11
CVE-2013-0787 [CRITICAL] CWE-399 CVE-2013-0787: Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEdi
Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand
nvd
CVE-2021-24002P3HIGHCVSS 8.8fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-24002 [HIGH] CWE-74 CVE-2021-24002: When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2026-4715P3CRITICALCVSS 9.1fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4715 [CRITICAL] CWE-908 CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 14
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4716P3CRITICALCVSS 9.1fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4716 [CRITICAL] CWE-908 CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnera
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2025-4083P3CRITICALCVSS 9.1fixed in 115.23fixed in 138.0+1 more2025-04-29
CVE-2025-4083 [CRITICAL] CWE-653 CVE-2025-4083: A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs,
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and T
nvd
CVE-2026-4724P3CRITICALCVSS 9.1fixed in 149.02026-03-24
CVE-2026-4724 [CRITICAL] CWE-758 CVE-2026-4724: Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thu
Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-16364P3CRITICALCVSS 9.1fixed in 153.0.02026-07-21
CVE-2026-16364 [CRITICAL] CWE-119 CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed i
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16393P3CRITICALCVSS 9.1fixed in 153.0.02026-07-21
CVE-2026-16393 [CRITICAL] CWE-119 CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Fir
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2022-22756P3HIGHCVSS 8.8fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22756 [HIGH] CWE-94 CVE-2022-22756: If a user was convinced to drag and drop an image to their desktop or other folder, the resulting ob
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2023-0767P3HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-0767 [HIGH] CVE-2023-0767: An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memor
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvdosv
CVE-2010-2766P3CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2766 [CRITICAL] CWE-94 CVE-2010-2766: The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird
The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.
nvd
CVE-2026-2447P3HIGHCVSS 8.8fixed in 115.32.1fixed in 147.0.4+1 more2026-02-16
CVE-2026-2447 [HIGH] CWE-122 CVE-2026-2447: Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
nvd