Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 29 of 162
CVE-2014-1555P3CRITICALCVSS 9.3≤ 30.0v24.0+4 more2014-07-23
CVE-2014-1555 [CRITICAL] CVE-2014-1555: Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0,
Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.
nvdosv
CVE-2011-1300P3CRITICALCVSS 10.0v4.02011-04-15
CVE-2011-1300 [CRITICAL] CWE-189 CVE-2011-1300: The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the Web
The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecifi
nvd
CVE-2018-12392P3CRITICALCVSS 9.8fixed in 60.3.0fixed in 63.0+1 more2019-02-28
CVE-2018-12392 [CRITICAL] CVE-2018-12392: When manipulating user events in nested loops while opening a document through script, it is possibl
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
nvd
CVE-2017-5428P3CRITICALCVSS 9.8fixed in 52.0.1≥ unspecified, < 52.0.12018-06-11
CVE-2017-5428 [CRITICAL] CWE-190 CVE-2017-5428: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for t
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Fir
nvdosv
CVE-2025-11152P3HIGHCVSS 8.6fixed in 143.0.32025-09-30
CVE-2025-11152 [HIGH] CWE-190 CVE-2025-11152: Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was f
Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3.
nvd
CVE-2012-1953P3CRITICALCVSS 9.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1953 [CRITICAL] CWE-119 CVE-2012-1953: The ElementAnimations::EnsureStyleRuleFor function in Mozilla Firefox 4.x through 13.0, Firefox ESR
The ElementAnimations::EnsureStyleRuleFor function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (buffer over-read, incorrect pointer dereference, and heap-based buffer overflow) or po
nvd
CVE-2009-3372P3CRITICALCVSS 9.3v3.0v3.0.1+15 more2009-10-29
CVE-2009-3372 [CRITICAL] CVE-2009-3372: Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attack
Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.
nvd
CVE-2024-2612P3HIGHCVSS 8.1fixed in 115.9fixed in 124.0+1 more2024-03-19
CVE-2024-2612 [HIGH] CWE-416 CVE-2024-2612: If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have tri
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2024-3864P3HIGHCVSS 8.1fixed in 115.10.0fixed in 125.0+1 more2024-04-16
CVE-2024-3864 [HIGH] CWE-119 CVE-2024-3864: Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2018-12369P3CRITICALCVSS 9.8fixed in 60.1.0fixed in 61.0+1 more2018-10-18
CVE-2018-12369 [CRITICAL] CWE-863 CVE-2018-12369: WebExtensions bundled with embedded experiments were not correctly checked for proper authorization.
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.
nvdosv
CVE-2025-4091P3HIGHCVSS 8.1fixed in 128.10fixed in 138.02025-04-29
CVE-2025-4091 [HIGH] CWE-119 CVE-2025-4091: Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Thunderbird 138, and Thunderbi
nvd
CVE-2025-4093P3HIGHCVSS 8.1fixed in 128.102025-04-29
CVE-2025-4093 [HIGH] CWE-119 CVE-2025-4093: Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of m
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 128.10 and Thunderbird 128.10.
nvd
CVE-2025-6435P3HIGHCVSS 8.1fixed in 140.02025-06-24
CVE-2025-6435 [HIGH] CWE-434 CVE-2025-6435: If a user saved a response from the Network tab in Devtools using the Save As context menu option, t
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
nvd
CVE-2017-7821P3CRITICALCVSS 9.8≤ 55.0.3≥ unspecified, < 562018-06-11
CVE-2017-7821 [CRITICAL] CWE-732 CVE-2017-7821: A vulnerability where WebExtensions can download and attempt to open a file of some non-executable f
A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific user interaction for the file download and open actions. This could be used to trigger known vulnerabilities in the programs that handle those document types. This vulnerability affects Firefox < 56.
nvdosv
CVE-2017-5392P3CRITICALCVSS 9.8fixed in 51.0≥ unspecified, < 512018-06-11
CVE-2017-5392 [CRITICAL] CWE-119 CVE-2017-5392: Weak proxy objects have weak references on multiple threads when they should only have them on one,
Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.
nvd
CVE-2019-11714P3CRITICALCVSS 9.8fixed in 68.0≥ unspecified, < 682019-07-23
CVE-2019-11714 [CRITICAL] CWE-20 CVE-2019-11714: Necko can access a child on the wrong thread during UDP connections, resulting in a potentially expl
Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.
nvdosv
CVE-2023-4050P3HIGHCVSS 7.5fixed in 116.0≥ 102.0, < 102.14+2 more2023-08-01
CVE-2023-4050 [HIGH] CWE-787 CVE-2023-4050: In some cases, an untrusted input stream was copied to a stack buffer without checking its size. Thi
In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2008-4582P4MEDIUMCVSS 4.3PoCv3.0.1v3.0.2+11 more2008-10-15
CVE-2008-4582 [MEDIUM] CWE-264 CVE-2008-4582: Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, w
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible t
nvd
CVE-2020-6815P3CRITICALCVSS 9.8fixed in 74.0≥ unspecified, < 742020-03-25
CVE-2020-6815 [CRITICAL] CWE-787 CVE-2020-6815: Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of thes
Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or escalation of privilege and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 74.
nvdosv
CVE-2013-1688P3CRITICALCVSS 9.3≤ 21.0v19.0+4 more2013-06-26
CVE-2013-1688 [CRITICAL] CWE-94 CVE-2013-1688: The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering
The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to execute arbitrary JavaScript code via a crafted web site.
nvd