cbcvebase.

Mozilla Firefox vulnerabilities

3,248 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,248
CISA KEV
17
actively exploited
Public exploits
122
Exploited in wild
22
Severity breakdown
CRITICAL875HIGH978MEDIUM1321LOW72UNKNOWN2

Vulnerabilities

Page 3 of 163
CVE-2026-8388MEDIUMCVSS 6.5fixed in 150.0.32026-05-12
CVE-2026-8388 [MEDIUM] CWE-119 CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
nvdmozillaredhat
CVE-2026-8391MEDIUMCVSS 5.3fixed in 150.0.32026-05-12
CVE-2026-8391 [MEDIUM] CWE-20 CVE-2026-8391: Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Fir Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
nvdmozillaredhat
CVE-2026-8094CRITICALCVSS 9.8fixed in 140.10.22026-05-07
CVE-2026-8094 [CRITICAL] CWE-94 CVE-2026-8094: Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunde Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
nvdredhat
CVE-2026-8091CRITICALCVSS 9.8fixed in 115.35.2≥ 140.0, < 140.10.12026-05-07
CVE-2026-8091 [CRITICAL] CWE-754 CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed i Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.
nvd
CVE-2026-8092HIGHCVSS 8.1fixed in 115.35.2≥ 140.0, < 140.10.2+1 more2026-05-07
CVE-2026-8092 [HIGH] CWE-125 CVE-2026-8092: Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some o Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbir
nvdmozillaredhat
CVE-2026-8090HIGHCVSS 7.3fixed in 115.35.2fixed in 150.0.2+1 more2026-05-07
CVE-2026-8090 [HIGH] CWE-416 CVE-2026-8090: Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Fi Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
nvdmozillaredhat
CVE-2026-8093HIGHCVSS 8.1fixed in 150.0.22026-05-07
CVE-2026-8093 [HIGH] CWE-119 CVE-2026-8093: Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corrupti Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.
nvdmozillaredhat
CVE-2026-7321CRITICALCVSS 9.6fixed in 140.10.1fixed in 150.02026-04-28
CVE-2026-7321 [CRITICAL] CWE-120 CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulner Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.
nvdredhat
CVE-2026-7324HIGHCVSS 7.3fixed in 150.0.12026-04-28
CVE-2026-7324 [HIGH] CWE-119 CVE-2026-7324: Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corr Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.
nvdmozillaredhat
CVE-2026-7322HIGHCVSS 7.3fixed in 115.35.1fixed in 150.0.1+1 more2026-04-28
CVE-2026-7322 [HIGH] CWE-119 CVE-2026-7322: Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs s Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and
nvdmozillaredhat
CVE-2026-7320HIGHCVSS 7.5fixed in 115.35.1fixed in 150.0.1+1 more2026-04-28
CVE-2026-7320 [HIGH] CWE-119 CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulne Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
nvdmozillaredhat
CVE-2026-7323HIGHCVSS 7.3fixed in 140.10.1fixed in 150.0.12026-04-28
CVE-2026-7323 [HIGH] CWE-119 CVE-2026-7323: Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs s Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
nvdmozillaredhat
CVE-2026-6785HIGHCVSS 7.5fixed in 115.35.0fixed in 150.0+1 more2026-04-26
CVE-2026-6785 [HIGH] CWE-125 CVE-2026-6785: Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox
nvdmozilla
CVE-2026-6786HIGHCVSS 7.5fixed in 150.0≥ 140.0, < 140.10.02026-04-26
CVE-2026-6786 [HIGH] CWE-125 CVE-2026-6786: Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunder
nvdmozilla
CVE-2026-41907HIGHCVSS 8.12026-04-24
CVE-2026-41907 [HIGH] CWE-787 uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality A flaw was found in uuid. The library's versions v3, v5, and v6 do not adequately check the size of external memory buffers provided by applications. This oversight allows the library to write data beyond the designated buffer limits without signaling an error. Such out-of-bounds writes can
redhat
CVE-2026-41305MEDIUMCVSS 6.12026-04-24
CVE-2026-41305 [MEDIUM] CWE-79 postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags A flaw was found in PostCSS. This vulnerability allows a remote attacker to perform Cross-Site Scripting (XSS) by submitting specially crafted CSS. When PostCSS processes and re-stringifies this CSS for embedding within HTML `` tags, it fails to properly escape `` sequences. This oversight
redhat
CVE-2026-41988LOWCVSS 3.22026-04-23
CVE-2026-41988 [LOW] CWE-787 uuid: uuid: Unexpected data writes when using external output buffers with specific UUID versions uuid: uuid: Unexpected data writes when using external output buffers with specific UUID versions A flaw was found in uuid. When external output buffers are used with UUID versions 3, 5, or 6, an attacker with local access may be able to cause unexpected data writes. This vulnerability could lead to low impact data integrity issues. UUID version 4 is not affected. Pack
redhat
CVE-2026-6771CRITICALCVSS 9.8fixed in 150.0≥ 140.0, < 140.10.02026-04-21
CVE-2026-6771 [CRITICAL] CWE-288 CVE-2026-6771: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firef Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozillaredhat
CVE-2026-6748CRITICALCVSS 9.8fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6748 [CRITICAL] CWE-457 CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozillaredhat
CVE-2026-6768CRITICALCVSS 9.8fixed in 150.02026-04-21
CVE-2026-6768 [CRITICAL] CWE-288 CVE-2026-6768: Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla