Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 21 of 162
CVE-2024-5688P3HIGHCVSS 8.1fixed in 115.12fixed in 127.0+1 more2024-06-11
CVE-2024-5688 [HIGH] CWE-416 CVE-2024-5688: If a garbage collection was triggered at the right time, a use-after-free could have occurred during
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2020-15254P3CRITICALCVSS 9.8≥ 0, < 82.0+build2-0ubuntu0.16.04.5≥ 0, < 82.0+build2-0ubuntu0.18.04.1+1 more2020-10-22
CVE-2020-15254 [CRITICAL] CVE-2020-15254: Crossbeam is a set of tools for concurrent programming
Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements. `Vec::from_iter` does not actually guarantee that and may allocate extra memory. The destructor of the `bounded` channel reconstructs `Vec` from the raw pointer based on the
osv
CVE-2016-1935P3HIGHCVSS 8.8≤ 43.0.4v38.0+5 more2016-01-31
CVE-2016-1935 [HIGH] CWE-119 CVE-2016-1935: Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x be
Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
nvdosv
CVE-2016-9075P3CRITICALCVSS 9.8fixed in 50.0≥ unspecified, < 502018-06-11
CVE-2016-9075 [CRITICAL] CWE-264 CVE-2016-9075: An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.
nvdosv
CVE-2025-9184P3HIGHCVSS 8.1fixed in 140.2.0fixed in 142.02025-08-19
CVE-2025-9184 [HIGH] CWE-119 CVE-2025-9184: Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird
Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderb
nvd
CVE-2018-5158P3HIGHCVSS 8.8fixed in 52.8.0fixed in 60.0+1 more2018-06-11
CVE-2018-5158 [HIGH] CWE-94 CVE-2018-5158: The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious Ja
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
nvd
CVE-2009-1828P4MEDIUMCVSS 5.0PoCv3.0.102009-05-29
CVE-2009-1828 [MEDIUM] CWE-399 CVE-2009-1828: Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, applicat
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element. NOTE: it was later reported that earlier versions are also affec
nvd
CVE-2014-1524P3CRITICALCVSS 9.8fixed in 29.0≥ 24.0, < 24.52014-04-30
CVE-2014-1524 [CRITICAL] CWE-120 CVE-2014-1524: The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x
The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted JavaScript code
nvdosv
CVE-2017-7828P3CRITICALCVSS 9.8fixed in 57.0fixed in 52.5.0+1 more2018-06-11
CVE-2017-7828 [CRITICAL] CWE-416 CVE-2017-7828: A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell"
A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This results in a potentially exploitable crash during these operations. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvd
CVE-2012-4185P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4185 [CRITICAL] CWE-119 CVE-2012-4185: Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.
Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2020-26972P3CRITICALCVSS 9.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26972 [CRITICAL] CWE-416 CVE-2020-26972: The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former mu
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 84.
nvdosv
CVE-2016-2814P3HIGHCVSS 8.8≤ 45.0.2v38.0+15 more2016-04-30
CVE-2016-2814 [HIGH] CWE-119 CVE-2016-2814: Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstage
Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table.
nvd
CVE-2018-5097P3CRITICALCVSS 9.8fixed in 58.0fixed in 52.6.0+1 more2018-06-11
CVE-2018-5097 [CRITICAL] CWE-416 CVE-2018-5097: A use-after-free vulnerability can occur during XSL transformations when the source document for the
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2023-5174P3CRITICALCVSS 9.8fixed in 118≥ unspecified, < 1182023-09-27
CVE-2023-5174 [CRITICAL] CWE-416 CVE-2023-5174: If Windows failed to duplicate a handle during process creation, the sandbox code may have inadverte
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash.
*This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vul
nvd
CVE-2024-6602P3CRITICALCVSS 9.8fixed in 115.13fixed in 128.0+1 more2024-07-09
CVE-2024-6602 [CRITICAL] CWE-94 CVE-2024-6602: A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2023-34416P3CRITICALCVSS 9.8fixed in 114.0≥ unspecified, < 1142023-06-19
CVE-2023-34416 [CRITICAL] CWE-787 CVE-2023-34416: Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.
nvd
CVE-2023-5175P3CRITICALCVSS 9.8fixed in 118≥ unspecified, < 1182023-09-27
CVE-2023-5175 [CRITICAL] CWE-416 CVE-2023-5175: During process shutdown, it was possible that an `ImageBitmap` was created that would later be used
During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.
nvdosv
CVE-2024-9401P3CRITICALCVSS 9.8fixed in 115.16.0fixed in 131.0+2 more2024-10-01
CVE-2024-9401 [CRITICAL] CWE-119 CVE-2024-9401: Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 12
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thu
nvd
CVE-2024-8384P3CRITICALCVSS 9.8fixed in 130.0≥ unspecified, < 1302024-09-03
CVE-2024-8384 [CRITICAL] CWE-787 CVE-2024-8384: The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were de
The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
nvd
CVE-2020-6463P3MEDIUMCVSS 6.5≥ 0, < 79.0+build1-0ubuntu0.16.04.2≥ 0, < 79.0+build1-0ubuntu0.18.04.1+1 more2020-07-29
CVE-2020-6463 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass iframe sandbox restrictions, confuse the user, or
execute arbitrary code. (CVE-2020-6463, CVE-2020-6514, CVE-2020-15652,
CVE-2020-15653, CVE-2020-15654, CVE-2020-15656, CVE-2020-15658,
CVE-2020-1565
osv