Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 28 of 162
CVE-2024-11691P3HIGHCVSS 8.8fixed in 115.18.0≥ 116.0, < 128.5.0+2 more2024-11-26
CVE-2024-11691 [HIGH] CWE-787 CVE-2024-11691: Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver.
*This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunde
nvd
CVE-2024-11699P3HIGHCVSS 8.8fixed in 128.5.0fixed in 133.0+1 more2024-11-26
CVE-2024-11699 [HIGH] CWE-94 CVE-2024-11699: Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these b
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2023-25729P3HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25729 [HIGH] CWE-863 CVE-2023-25729: Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> r
Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox <
nvd
CVE-2010-2753P3HIGHCVSS 8.8≥ 3.5, < 3.5.11≥ 3.6, < 3.6.72010-07-30
CVE-2010-2753 [HIGH] CWE-190 CVE-2010-2753: Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x be
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
nvd
CVE-2023-3600P3HIGHCVSS 8.8fixed in 115.0.2≥ unspecified, < 115.0.22023-07-12
CVE-2023-3600 [HIGH] CWE-416 CVE-2023-3600: During the worker lifecycle, a use-after-free condition could have occurred, which could have led to
During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.
nvdosv
CVE-2024-0751P3HIGHCVSS 8.8fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0751 [HIGH] CWE-269 CVE-2024-0751: A malicious devtools extension could have been used to escalate privileges. This vulnerability affec
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2024-7521P3HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7521 [HIGH] CWE-755 CVE-2024-7521: Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affe
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2013-0782P3CRITICALCVSS 9.3fixed in 17.0.3fixed in 19.02013-02-19
CVE-2013-0782 [CRITICAL] CWE-787 CVE-2013-0782: Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox b
Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2024-7527P3HIGHCVSS 8.8fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7527 [HIGH] CWE-416 CVE-2024-7527: Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerabil
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2024-10467P3HIGHCVSS 8.8fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10467 [HIGH] CWE-787 CVE-2024-10467: Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these b
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2016-5274P3CRITICALCVSS 9.8≤ 48.0.2v45.1.0+3 more2016-09-22
CVE-2016-5274 [CRITICAL] CWE-416 CVE-2016-5274: Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox be
Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between restyling and the Web Animations model implementation.
nvd
CVE-2013-0771P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0771 [CRITICAL] CWE-787 CVE-2013-0771: Heap-based buffer overflow in the gfxTextRun::ShrinkToLigatureBoundaries function in Mozilla Firefox
Heap-based buffer overflow in the gfxTextRun::ShrinkToLigatureBoundaries function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted document.
nvd
CVE-2013-0760P3CRITICALCVSS 9.3fixed in 10.0.11fixed in 18.0+1 more2013-01-13
CVE-2013-0760 [CRITICAL] CWE-120 CVE-2013-0760: Buffer overflow in the CharDistributionAnalysis::HandleOneChar function in Mozilla Firefox before 18
Buffer overflow in the CharDistributionAnalysis::HandleOneChar function in Mozilla Firefox before 18.0, Thunderbird before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted document.
nvd
CVE-2011-2984P3CRITICALCVSS 10.0≤ 3.6.19v1.0+105 more2011-08-18
CVE-2011-2984 [CRITICAL] CWE-94 CVE-2011-2984: Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other prod
Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.
nvd
CVE-2023-25740P3HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25740 [HIGH] CWE-522 CVE-2023-25740: After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could su
After downloading a Windows .scf script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability
nvd
CVE-2026-6750P3HIGHCVSS 8.8fixed in 115.35.0fixed in 150.0+1 more2026-04-21
CVE-2026-6750 [HIGH] CWE-269 CVE-2026-6750: Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-8952P3HIGHCVSS 8.8fixed in 151.0.02026-05-19
CVE-2026-8952 [HIGH] CWE-269 CVE-2026-8952: Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 15
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-16379P3HIGHCVSS 8.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16379 [HIGH] CWE-269 CVE-2026-16379: Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefo
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-6769P3HIGHCVSS 8.8fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6769 [HIGH] CWE-269 CVE-2026-6769: Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox
Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6761P3HIGHCVSS 8.8fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6761 [HIGH] CWE-269 CVE-2026-6761: Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firef
Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla