cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 25 of 162
CVE-2025-13027P3HIGHCVSS 8.1fixed in 145.02025-11-11
CVE-2025-13027 [HIGH] CWE-119 CVE-2025-13027: Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
nvd
CVE-2026-8093P3HIGHCVSS 8.1fixed in 150.0.22026-05-07
CVE-2026-8093 [HIGH] CWE-119 CVE-2026-8093: Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corrupti Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.
nvdmozilla
CVE-2016-2838P3HIGHCVSS 8.8≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-2838 [HIGH] CWE-119 CVE-2016-2838: Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document.
nvd
CVE-2016-5278P3HIGHCVSS 8.8≤ 48.0.2v45.1.0+3 more2016-09-22
CVE-2016-5278 [HIGH] CWE-119 CVE-2016-5278: Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49. Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image.
nvd
CVE-2016-1968P3HIGHCVSS 8.8≤ 44.0.22016-03-13
CVE-2016-1968 [HIGH] CWE-189 CVE-2016-1968: Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to exec Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.
nvd
CVE-2019-11692P3CRITICALCVSS 9.8fixed in 60.7.0fixed in 67.0+1 more2019-07-23
CVE-2019-11692 [CRITICAL] CWE-416 CVE-2019-11692: A use-after-free vulnerability can occur when listeners are removed from the event listener manager A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2010-1028P3CRITICALCVSS 9.3v3.6v3.6.1+1 more2010-03-19
CVE-2010-1028 [CRITICAL] CWE-189 CVE-2010-1028: Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in M Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.
nvd
CVE-2008-5715P4MEDIUMCVSS 5.0PoCv3.0.52008-12-24
CVE-2008-5715 [MEDIUM] CWE-20 CVE-2008-5715: Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (applica Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash). NOTE: it was later reported that earlier versions are also affected, and that the impact is CPU consumption and application hang in unspecified circumstan
nvd
CVE-2023-5730P3CRITICALCVSS 9.8fixed in 119.0≥ unspecified, < 1192023-10-25
CVE-2023-5730 [CRITICAL] CWE-787 CVE-2023-5730: Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these b Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2018-5104P3CRITICALCVSS 9.8fixed in 58.0fixed in 52.6.0+1 more2018-06-11
CVE-2018-5104 [CRITICAL] CWE-416 CVE-2018-5104: A use-after-free vulnerability can occur during font face manipulation when a font face is freed whi A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2018-5102P3CRITICALCVSS 9.8fixed in 58.0fixed in 52.6.0+1 more2018-06-11
CVE-2018-5102 [CRITICAL] CWE-416 CVE-2018-5102: A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, r A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2022-34470P3CRITICALCVSS 9.8fixed in 102.0≥ unspecified, < 1022022-12-22
CVE-2022-34470 [CRITICAL] CWE-416 CVE-2022-34470: Session history navigations may have led to a use-after-free and potentially exploitable crash. This Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2022-31736P3CRITICALCVSS 9.8fixed in 101≥ unspecified, < 1012022-12-22
CVE-2022-31736 [CRITICAL] CWE-942 CVE-2022-31736: A malicious website could have learned the size of a cross-origin resource that supported Range requ A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2023-29531P3CRITICALCVSS 9.8fixed in 112.0≥ unspecified, < 1122023-06-19
CVE-2023-29531 [CRITICAL] CWE-787 CVE-2023-29531: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory cor An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
nvd
CVE-2023-4056P3CRITICALCVSS 9.8fixed in 116.0≥ 102.0, < 102.14+2 more2023-08-01
CVE-2023-4056 [CRITICAL] CWE-787 CVE-2023-4056: Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and
nvd
CVE-2022-46882P3CRITICALCVSS 9.8fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-46882 [CRITICAL] CWE-416 CVE-2022-46882: A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnera A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2024-3863P3CRITICALCVSS 9.8fixed in 115.10.0fixed in 125.0+1 more2024-04-16
CVE-2024-3863 [CRITICAL] CWE-434 CVE-2024-3863: The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue on The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-5699P3CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5699 [CRITICAL] CWE-178 CVE-2024-5699: In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correct In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.
nvdosv
CVE-2024-9394P3HIGHCVSS 7.5fixed in 131.0≥ unspecified, < 1312024-10-01
CVE-2024-9394 [HIGH] CWE-79 CVE-2024-9394: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under th An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This
nvd
CVE-2025-49710P3CRITICALCVSS 9.8fixed in 139.0.42025-06-11
CVE-2025-49710 [CRITICAL] CWE-190 CVE-2025-49710: An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerabil An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.
nvd
Mozilla Firefox vulnerabilities | cvebase