Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 22 of 162
CVE-2022-1887P3CRITICALCVSS 9.8fixed in 1012022-12-22
CVE-2022-1887 [CRITICAL] CWE-89 CVE-2022-1887: The search term could have been specified externally to trigger SQL injection. This vulnerability af
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
nvd
CVE-2024-4764P3CRITICALCVSS 9.8fixed in 126.0≥ unspecified, < 1262024-05-14
CVE-2024-4764 [CRITICAL] CWE-416 CVE-2024-4764: Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free.
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.
nvdosv
CVE-2025-1017P3CRITICALCVSS 9.8fixed in 128.7.0fixed in 135.02025-02-04
CVE-2025-1017 [CRITICAL] CWE-787 CVE-2025-1017: Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thun
nvd
CVE-2025-54143P3CRITICALCVSS 9.8fixed in 141.02025-08-19
CVE-2025-54143 [CRITICAL] CWE-693 CVE-2025-54143: Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expecte
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
nvd
CVE-2025-8028P3CRITICALCVSS 9.8fixed in 115.26.0fixed in 141.0+2 more2025-07-22
CVE-2025-8028 [CRITICAL] CWE-1332 CVE-2025-8028: On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1
nvd
CVE-2026-4723P3CRITICALCVSS 9.8fixed in 149.02026-03-24
CVE-2026-4723 [CRITICAL] CWE-416 CVE-2026-4723: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and T
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2025-11710P3CRITICALCVSS 9.8fixed in 115.29.0fixed in 144.0+1 more2025-10-14
CVE-2025-11710 [CRITICAL] CWE-200 CVE-2025-11710: A compromised web process using malicious IPC messages could have caused the privileged browser proc
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
nvd
CVE-2013-0768P3CRITICALCVSS 9.3fixed in 17.0.2fixed in 18.02013-01-13
CVE-2013-0768 [CRITICAL] CWE-787 CVE-2013-0768: Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR
Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via an HTML document that specifies invalid width and height values.
nvd
CVE-2014-1514P3CRITICALCVSS 9.8fixed in 28.0≥ 24.0, < 24.42014-03-19
CVE-2014-1514 [CRITICAL] CWE-787 CVE-2014-1514: vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird bef
vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by trig
nvd
CVE-2011-0058P3CRITICALCVSS 10.0v3.6v3.6.2+96 more2011-03-02
CVE-2011-0058 [CRITICAL] CWE-119 CVE-2011-0058: Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.1
Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run.
nvd
CVE-2008-0418P4MEDIUMCVSS 4.3PoC≤ 2.0.0.112008-02-08
CVE-2008-0418 [MEDIUM] CWE-22 CVE-2008-0418: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, a
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.
nvd
CVE-2004-1381P4MEDIUMCVSS 5.0PoCv0.8v0.9+5 more2004-10-20
CVE-2004-1381 [MEDIUM] CVE-2004-1381: Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being
Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.
nvd
CVE-2020-6831P3CRITICALCVSS 9.8fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-6831 [CRITICAL] CWE-787 CVE-2020-6831: A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
nvdosv
CVE-2018-5127P3HIGHCVSS 8.8fixed in 52.7.0fixed in 59.0+1 more2018-06-11
CVE-2018-5127 [HIGH] CWE-119 CVE-2018-5127: A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This res
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd
CVE-2017-7778P3CRITICALCVSS 9.8fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7778 [CRITICAL] CWE-119 CVE-2017-7778: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2013-0750P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0750 [CRITICAL] CWE-190 CVE-2013-0750: Integer overflow in the JavaScript implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x b
Integer overflow in the JavaScript implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted string concatenation, leading to imp
nvd
CVE-2016-5281P3CRITICALCVSS 9.8≤ 48.0.2v45.0+5 more2016-09-22
CVE-2016-5281 [CRITICAL] CWE-416 CVE-2016-5281: Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 4
Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.
nvd
CVE-2026-8950P3CRITICALCVSS 9.3fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8950 [CRITICAL] CWE-346 CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2012-0470P3CRITICALCVSS 10.0v4.0v4.0.1+16 more2012-04-25
CVE-2012-0470 [CRITICAL] CWE-119 CVE-2012-0470: Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Fire
Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly
nvd
CVE-2026-2806P3CRITICALCVSS 9.1fixed in 148.02026-02-24
CVE-2026-2806 [CRITICAL] CWE-908 CVE-2026-2806: Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 an
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd