cbcvebase.

Mozilla Firefox vulnerabilities

3,257 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,257
CISA KEV
17
actively exploited
Public exploits
123
Exploited in wild
22
Severity breakdown
CRITICAL875HIGH984MEDIUM1324LOW72UNKNOWN2

Vulnerabilities

Page 20 of 163
CVE-2025-1931HIGHCVSS 7.5fixed in 115.21.0fixed in 136.0+1 more2025-03-04
CVE-2025-1931 [HIGH] CWE-416 CVE-2025-1931: It was possible to cause a use-after-free in the content process side of a WebTransport connection, It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdmozilla
CVE-2025-1933HIGHCVSS 7.6fixed in 115.21.0fixed in 136.0+1 more2025-03-04
CVE-2025-1933 [HIGH] CVE-2025-1933: On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over me On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdosvmozilla
CVE-2025-1937HIGHCVSS 7.5fixed in 115.21.0fixed in 128.8.0+1 more2025-03-04
CVE-2025-1937 [HIGH] CWE-1260 CVE-2025-1937: Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, a Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox E
nvdmozilla
CVE-2025-1936HIGHCVSS 7.3fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1936 [HIGH] CWE-158 CVE-2025-1936: jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it wa jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerabilit
nvdmozilla
CVE-2025-1932HIGHCVSS 8.1fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1932 [HIGH] CWE-125 CVE-2025-1932: An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-o An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdmozilla
CVE-2025-1930HIGHCVSS 8.8fixed in 115.21.0fixed in 136.0+1 more2025-03-04
CVE-2025-1930 [HIGH] CWE-416 CVE-2025-1930: On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a u On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdmozilla
CVE-2025-1943HIGHCVSS 8.2fixed in 136.02025-03-04
CVE-2025-1943 [HIGH] CWE-122 CVE-2025-1943: Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
nvdosvmozilla
CVE-2025-1940HIGHCVSS 7.1fixed in 136.02025-03-04
CVE-2025-1940 [HIGH] CWE-1021 CVE-2025-1940: A select option could partially obscure the confirmation prompt shown before launching external apps A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.
nvdmozilla
CVE-2025-1938MEDIUMCVSS 6.5fixed in 128.7.0fixed in 135.02025-03-04
CVE-2025-1938 [MEDIUM] CWE-787 CVE-2025-1938: Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7 Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderb
nvdmozilla
CVE-2025-27426MEDIUMCVSS 5.4fixed in 136.02025-03-04
CVE-2025-27426 [MEDIUM] CWE-601 CVE-2025-27426: Malicious websites utilizing a server-side redirect to an internal error page could result in a spoo Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.
nvdmozilla
CVE-2025-1935MEDIUMCVSS 4.3fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1935 [MEDIUM] CWE-79 CVE-2025-1935: A web page could trick a user into setting that site as the default handler for a custom URL protoco A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdmozilla
CVE-2025-1934MEDIUMCVSS 6.5fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1934 [MEDIUM] CVE-2025-1934: It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, poten It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvdmozilla
CVE-2025-27425MEDIUMCVSS 4.3fixed in 136.02025-03-04
CVE-2025-27425 [MEDIUM] CWE-287 CVE-2025-27425: Scanning certain QR codes that included text with a website URL could allow the URL to be opened wit Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.
nvdmozilla
CVE-2025-27424MEDIUMCVSS 4.3fixed in 136.02025-03-04
CVE-2025-27424 [MEDIUM] CWE-601 CVE-2025-27424: Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a mali Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.
nvdmozilla
CVE-2025-1939LOWCVSS 3.9fixed in 136.02025-03-04
CVE-2025-1939 [LOW] CWE-359 CVE-2025-1939: Android apps can load web pages using the Custom Tabs feature. This feature supports a transition an Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.
nvdmozilla
CVE-2025-1414MEDIUMCVSS 6.5fixed in 135.0.12025-02-18
CVE-2025-1414 [MEDIUM] CWE-787 CVE-2025-1414: Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135.0.1.
nvdosvmozilla
CVE-2025-1016CRITICALCVSS 9.8fixed in 115.20.0fixed in 135.0+1 more2025-02-04
CVE-2025-1016 [CRITICAL] CWE-787 CVE-2025-1016: Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, T Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135, Firefo
nvdmozilla
CVE-2025-1017CRITICALCVSS 9.8fixed in 128.7.0fixed in 135.02025-02-04
CVE-2025-1017 [CRITICAL] CWE-787 CVE-2025-1017: Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6 Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thun
nvdmozilla
CVE-2025-1009CRITICALCVSS 9.8fixed in 115.20.0fixed in 135.0+1 more2025-02-04
CVE-2025-1009 [CRITICAL] CWE-416 CVE-2025-1009: An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially explo An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvdmozilla
CVE-2025-1020CRITICALCVSS 9.8fixed in 135.02025-02-04
CVE-2025-1020 [CRITICAL] CWE-787 CVE-2025-1020: Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
nvdosvmozilla