cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 33 of 162
CVE-2026-24869P3HIGHCVSS 8.8fixed in 147.0.22026-01-27
CVE-2026-24869 [HIGH] CWE-416 CVE-2026-24869: Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Fire Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
nvd
CVE-2018-5094P3HIGHCVSS 7.5≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5094 [HIGH] CWE-119 CVE-2018-5094: A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called follow A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collection on memory that is now uninitialized. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.
nvdosv
CVE-2014-1567P3CRITICALCVSS 9.3≤ 31.1.0v30.0+6 more2014-09-03
CVE-2014-1567 [CRITICAL] CVE-2014-1567: Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.
nvdosv
CVE-2023-4576P3HIGHCVSS 8.6fixed in 117.0≥ 115.0, < 115.2+1 more2023-09-11
CVE-2023-4576 [HIGH] CWE-190 CVE-2023-4576: On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a h On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR
nvd
CVE-2012-3969P3CRITICALCVSS 9.3v10.0v10.0.1+133 more2012-08-29
CVE-2012-3969 [CRITICAL] CWE-189 CVE-2012-3969: Integer overflow in the nsSVGFEMorphologyElement::Filter function in Mozilla Firefox before 15.0, Fi Integer overflow in the nsSVGFEMorphologyElement::Filter function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via a crafted SVG filter that triggers an incorrect sum calculation, leading to a he
nvd
CVE-2009-1841P3CRITICALCVSS 9.3≤ 3.0.10v0.1+89 more2009-06-12
CVE-2009-1841 [CRITICAL] CWE-94 CVE-2009-1841: js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0. js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.
nvd
CVE-2026-4687P3HIGHCVSS 8.6fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4687 [HIGH] CWE-754 CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability w Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2012-1958P3CRITICALCVSS 9.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1958 [CRITICAL] CWE-399 CVE-2012-1958: Use-after-free vulnerability in the nsGlobalWindow::PageHidden function in Mozilla Firefox 4.x throu Use-after-free vulnerability in the nsGlobalWindow::PageHidden function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 might allow remote attackers to execute arbitrary code via vectors related to focused content.
nvd
CVE-2010-3180P3CRITICALCVSS 9.3v3.6v3.6.2+90 more2010-10-21
CVE-2010-3180 [CRITICAL] CWE-399 CVE-2010-3180: Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x be Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code by accessing the locationbar property of a closed window.
nvd
CVE-2025-6432P3HIGHCVSS 8.6fixed in 140.02025-06-24
CVE-2025-6432 [HIGH] CWE-200 CVE-2025-6432: When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the d When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
nvd
CVE-2013-0745P3CRITICALCVSS 9.3fixed in 17.0.2fixed in 18.02013-01-13
CVE-2013-0745 [CRITICAL] CWE-94 CVE-2013-0745: The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunder The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not properly interact with garbage collection, which allows remote attackers to execute arbitrary code via a crafted HTML document referencing JavaScript objects.
nvd
CVE-2012-1946P3CRITICALCVSS 9.3v4.0v4.0.1+18 more2012-06-05
CVE-2012-1946 [CRITICAL] CWE-399 CVE-2012-1946: Use-after-free vulnerability in the nsINode::ReplaceOrInsertBefore function in Mozilla Firefox 4.x t Use-after-free vulnerability in the nsINode::ReplaceOrInsertBefore function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 might allow remote attackers to execute arbitrary code via document changes involving replacement or insertion of
nvd
CVE-2017-5460P3CRITICALCVSS 9.8fixed in 53.0v52.0+2 more2018-06-11
CVE-2017-5460 [CRITICAL] CWE-416 CVE-2017-5460: A use-after-free vulnerability in frame selection triggered by a combination of malicious script con A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2014-1564P4MEDIUMCVSS 4.3PoC≤ 31.1.0v30.0+1 more2014-09-03
CVE-2014-1564 [MEDIUM] CWE-824 CVE-2014-1564: Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not p Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.
nvdosv
CVE-2010-2760P3CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2760 [CRITICAL] CVE-2010-2760: Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3. Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling pointer vulnerability." NOTE: this issue ex
nvd
CVE-2024-1553P3HIGHCVSS 8.1fixed in 115.8.0fixed in 123.0+1 more2024-02-20
CVE-2024-1553 [HIGH] CWE-119 CVE-2024-1553: Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these b Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2016-5287P3CRITICALCVSS 9.8fixed in 49.0.2≥ unspecified, < 49.0.22018-06-11
CVE-2016-5287 [CRITICAL] CWE-416 CVE-2016-5287: A potentially exploitable use-after-free crash during actor destruction with service workers. This i A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.
nvdosv
CVE-2012-1952P3CRITICALCVSS 9.3v4.0v4.0.1+20 more2012-07-18
CVE-2012-1952 [CRITICAL] CWE-399 CVE-2012-1952: The nsTableFrame::InsertFrames function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before The nsTableFrame::InsertFrames function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly perform a cast of a frame variable during processing of mixed row-group and column-group frames, which might allow remote attackers
nvd
CVE-2012-0478P3CRITICALCVSS 9.3v4.0v4.0.1+16 more2012-04-25
CVE-2012-0478 [CRITICAL] CWE-264 CVE-2012-0478: The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ES The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.
nvd
CVE-2009-2535P4MEDIUMCVSS 5.0PoC≤ 2.0.0.18v0.1+71 more2009-07-20
CVE-2009-2535 [MEDIUM] CVE-2009-2535: Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attack Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
nvd