Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 20 of 162
CVE-2014-1543P3HIGHCVSS 7.5≤ 29.0.12014-06-11
CVE-2014-1543 [HIGH] CWE-119 CVE-2014-1543: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Moz
Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers to execute arbitrary code by using non-contiguous axes with a (1) physical or (2) virtual Gamepad device.
nvd
CVE-2010-0176P3CRITICALCVSS 9.3v3.6≤ 3.5.7+92 more2010-04-05
CVE-2010-0176 [CRITICAL] CWE-399 CVE-2010-0176: Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4;
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a
nvd
CVE-2026-3845P3HIGHCVSS 8.8fixed in 148.0.22026-03-10
CVE-2026-3845 [HIGH] CWE-122 CVE-2026-3845: Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerabili
Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Firefox 148.0.2.
nvd
CVE-2017-5390P3CRITICALCVSS 9.8fixed in 51.0fixed in 45.7.0+1 more2018-06-11
CVE-2017-5390 [CRITICAL] CVE-2017-5390: The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for c
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2026-8975P3HIGHCVSS 8.8fixed in 115.36.0fixed in 151.0.0+1 more2026-05-19
CVE-2026-8975 [HIGH] CWE-119 CVE-2026-8975: Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunde
nvdmozilla
CVE-2026-12289P3HIGHCVSS 8.8fixed in 115.37.0fixed in 152.0+1 more2026-06-16
CVE-2026-12289 [HIGH] CWE-269 CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2026-8957P3HIGHCVSS 8.8fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8957 [HIGH] CWE-269 CVE-2026-8957: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2025-14328P3HIGHCVSS 8.8fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14328 [HIGH] CVE-2025-14328: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firef
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvd
CVE-2025-14329P3HIGHCVSS 8.8fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14329 [HIGH] CVE-2025-14329: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firef
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvd
CVE-2026-8973P3HIGHCVSS 8.8fixed in 151.0.02026-05-19
CVE-2026-8973 [HIGH] CWE-119 CVE-2026-8973: Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-4722P3HIGHCVSS 8.8fixed in 149.02026-03-24
CVE-2026-4722 [HIGH] CVE-2026-4722: Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbi
Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-3847P3HIGHCVSS 8.8fixed in 148.0.22026-03-10
CVE-2026-3847 [HIGH] CWE-119 CVE-2026-3847: Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corrupti
Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148.0.2.
nvd
CVE-2025-8040P3HIGHCVSS 8.8fixed in 140.1fixed in 141.02025-07-22
CVE-2025-8040 [HIGH] CWE-119 CVE-2025-8040: Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird
Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderb
nvd
CVE-2026-16362P3HIGHCVSS 8.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16362 [HIGH] CWE-416 CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Fi
Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16372P3HIGHCVSS 8.8fixed in 153.0.02026-07-21
CVE-2026-16372 [HIGH] CWE-269 CVE-2026-16372: Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefo
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2025-14861P3HIGHCVSS 8.8fixed in 146.0.12025-12-18
CVE-2025-14861 [HIGH] CWE-119 CVE-2025-14861: Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146.0.1.
nvd
CVE-2010-3768P3CRITICALCVSS 9.3v3.6v3.6.2+94 more2010-12-10
CVE-2010-3768 [CRITICAL] CWE-20 CVE-2010-3768: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (
nvd
CVE-2013-1721P3CRITICALCVSS 9.3≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1721 [CRITICAL] CWE-119 CVE-2013-1721: Integer overflow in the drawLineLoop function in the libGLESv2 library in Almost Native Graphics Lay
Integer overflow in the drawLineLoop function in the libGLESv2 library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 24.0 and SeaMonkey before 2.21, allows remote attackers to execute arbitrary code via a crafted web site.
nvd
CVE-2016-9901P3CRITICALCVSS 9.8fixed in 45.6.0fixed in 50.1+1 more2018-06-11
CVE-2016-9901 [CRITICAL] CWE-20 CVE-2016-9901: HTML tags received from the Pocket server will be processed without sanitization and any JavaScript
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
nvd
CVE-2024-2607P3HIGHCVSS 8.1fixed in 115.9.0fixed in 124.0+1 more2024-03-19
CVE-2024-2607 [HIGH] CWE-123 CVE-2024-2607: Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *N
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd