Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 34 of 162
CVE-2025-5269P3HIGHCVSS 8.1fixed in 128.11.02025-05-27
CVE-2025-5269 [HIGH] CWE-787 CVE-2025-5269: Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 128.11 and Thunderbird 128.11.
nvd
CVE-2019-9796P3CRITICALCVSS 9.8fixed in 60.6.0fixed in 66.0+1 more2019-04-26
CVE-2019-9796 [CRITICAL] CWE-416 CVE-2019-9796: A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers wi
A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array.
nvd
CVE-2026-8969P3HIGHCVSS 8.1fixed in 151.0.02026-05-19
CVE-2026-8969 [HIGH] CWE-693 CVE-2026-8969: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Th
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2008-4324P4MEDIUMCVSS 5.0PoCv3.0.32008-09-29
CVE-2008-4324 [MEDIUM] CWE-399 CVE-2008-4324: The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attacke
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.
nvd
CVE-2013-0764P3CRITICALCVSS 9.3fixed in 17.0.3fixed in 19.02013-01-13
CVE-2013-0764 [CRITICAL] CWE-326 CVE-2013-0764: The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x befo
The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not ensure thread safety for SSL sessions, which allows remote attackers to execute arbitrary code via crafted data, as demonstrated by e-mail mes
nvd
CVE-2019-9790P3CRITICALCVSS 9.8≤ 60.6≤ 66.0+1 more2019-04-26
CVE-2019-9790 [CRITICAL] CWE-416 CVE-2019-9790: A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained u
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvd
CVE-2019-9795P3CRITICALCVSS 9.8fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9795 [CRITICAL] CWE-617 CVE-2019-9795: A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvd
CVE-2019-9819P3CRITICALCVSS 9.8fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9819 [CRITICAL] CWE-843 CVE-2019-9819: A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API,
A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2019-9820P3CRITICALCVSS 9.8fixed in 67.0≥ unspecified, < 672019-07-23
CVE-2019-9820 [CRITICAL] CWE-416 CVE-2019-9820: A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in
A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2012-5830P3HIGHCVSS 8.8fixed in 17.0≥ 10.0, < 10.0.112012-11-21
CVE-2012-5830 [HIGH] CWE-416 CVE-2012-5830: Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunde
Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to execute arbitrary code via an HTML document.
nvd
CVE-2014-1478P3CRITICALCVSS 10.0fixed in 27.02014-02-06
CVE-2014-1478 [CRITICAL] CWE-787 CVE-2014-1478: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMon
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the MPostWriteBarrier class in js/src/jit/MIR.h and stack alignment in js/src/jit/A
nvd
CVE-2018-5116P3CRITICALCVSS 9.8≤ 57.0.4≥ unspecified, < 582018-06-11
CVE-2018-5116 [CRITICAL] CWE-346 CVE-2018-5116: WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58
nvdosv
CVE-2015-4486P3CRITICALCVSS 10.0≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4486 [CRITICAL] CWE-119 CVE-2015-4486: The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before
The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed WebM video data.
nvd
CVE-2022-45406P3CRITICALCVSS 9.8fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45406 [CRITICAL] CWE-416 CVE-2022-45406: If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be
If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2022-31747P3CRITICALCVSS 9.8fixed in 101≥ unspecified, < 1012022-12-22
CVE-2022-31747 [CRITICAL] CWE-125 CVE-2022-31747: Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memor
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thund
nvd
CVE-2023-4057P3CRITICALCVSS 9.8fixed in 116.0≥ unspecified, < 1162023-08-01
CVE-2023-4057 [CRITICAL] CWE-787 CVE-2023-4057: Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these b
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.
nvd
CVE-2009-2478P4MEDIUMCVSS 5.0PoCv3.52009-07-16
CVE-2009-2478 [MEDIUM] CWE-189 CVE-2009-2478: Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference a
Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug."
nvd
CVE-2026-6785P3HIGHCVSS 7.5fixed in 115.35.0fixed in 150.0+1 more2026-04-26
CVE-2026-6785 [HIGH] CWE-125 CVE-2026-6785: Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox
nvdmozilla
CVE-2016-5258P3HIGHCVSS 8.8≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-5258 [HIGH] CWE-416 CVE-2016-5258: Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox
Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session.
nvd
CVE-2017-7845P3HIGHCVSS 8.8fixed in 52.5.2fixed in 57.0.2+1 more2018-06-11
CVE-2017-7845 [HIGH] CWE-119 CVE-2017-7845: A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graph
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaf
nvd