Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 35 of 162
CVE-2016-2828P3HIGHCVSS 8.8≤ 46.0.1v45.1.0+1 more2016-06-13
CVE-2016-2828 [HIGH] CVE-2016-2828: Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
nvd
CVE-2025-8042P3CRITICALCVSS 9.8fixed in 141.02025-08-19
CVE-2025-8042 [CRITICAL] CWE-732 CVE-2025-8042: Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start down
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.
nvd
CVE-2022-26384P3CRITICALCVSS 9.6fixed in 98.0≥ unspecified, < 982022-12-22
CVE-2022-26384 [CRITICAL] CWE-693 CVE-2022-26384: If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but
If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd
CVE-2008-0017P3CRITICALCVSS 9.3≥ 2.0, < 2.0.0.18≥ 3.0, < 3.0.42008-11-13
CVE-2008-0017 [CRITICAL] CWE-119 CVE-2008-0017: The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x b
The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, whic
nvd
CVE-2025-3032P3HIGHCVSS 7.4fixed in 137.02025-04-01
CVE-2025-3032 [HIGH] CWE-403 CVE-2025-3032: Leaking of file descriptors from the fork server to web content processes could allow for privilege
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
nvd
CVE-2024-7519P3CRITICALCVSS 9.6fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7519 [CRITICAL] CWE-787 CVE-2024-7519: Insufficient checks when processing graphics shared memory could have led to memory corruption. This
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2016-5255P3HIGHCVSS 8.8≤ 47.0.12016-08-05
CVE-2016-5255 [HIGH] CWE-416 CVE-2016-5255: Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox be
Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.
nvdosv
CVE-2020-15659P3HIGHCVSS 8.8fixed in 79.0≥ unspecified, < 792020-08-10
CVE-2020-15659 [HIGH] CWE-787 CVE-2020-15659: Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1,
nvd
CVE-2026-16392P3UNKNOWNfixed in Firefox 153
CVE-2026-16392 Mozilla Foundation Security Advisory 2026-68: CVE-2026-16392
Mozilla Foundation Security Advisory 2026-68
CVE: CVE-2026-16392
Product: Firefox
Impact: high
Fixed in: Firefox 153
mozilla
CVE-2016-5263P3HIGHCVSS 8.8≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-5263 [HIGH] CWE-704 CVE-2016-5263: The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3
The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."
nvd
CVE-2012-3971P3CRITICALCVSS 10.0≤ 14.0v1.0+129 more2012-08-29
CVE-2012-3971 [CRITICAL] CWE-119 CVE-2012-3971: Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbir
Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the (1) Silf::readClassMap and (2) Pass::readPass functions.
nvd
CVE-2012-3970P3CRITICALCVSS 10.0v10.0v10.0.1+133 more2012-08-29
CVE-2012-3970 [CRITICAL] CWE-399 CVE-2012-3970: Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, F
Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving movemen
nvd
CVE-2020-15673P3HIGHCVSS 8.8fixed in 81.0≥ unspecified, < 812020-10-01
CVE-2020-15673 [HIGH] CWE-416 CVE-2020-15673: Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of t
Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2021-23994P3HIGHCVSS 8.8fixed in 88.0≥ unspecified, < 882021-06-24
CVE-2021-23994 [HIGH] CWE-909 CVE-2021-23994: A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of b
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvdosv
CVE-2021-43539P3HIGHCVSS 8.8fixed in 95.0≥ unspecified, < 952021-12-08
CVE-2021-43539 [HIGH] CWE-416 CVE-2021-43539: Failure to correctly record the location of live pointers across wasm instance calls resulted in a G
Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-26960P3HIGHCVSS 8.8fixed in 83.0fixed in 832020-12-09
CVE-2020-26960 [HIGH] CWE-416 CVE-2020-26960: If the Compact() method was called on an nsTArray, the array could have been reallocated without upd
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-26973P3HIGHCVSS 8.8fixed in 84.0≥ unspecified, < 842021-01-07
CVE-2020-26973 [HIGH] CVE-2020-26973: Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. Thi
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2020-6799P3HIGHCVSS 8.8fixed in 73.0≥ unspecified, < 73+1 more2020-03-02
CVE-2020-6799 [HIGH] CWE-88 CVE-2020-6799: Command line arguments could have been injected during Firefox invocation as a shell handler for cer
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a third party application that insufficiently sanitized URL data. In that situation, clicking a link
nvd
CVE-2021-23987P3HIGHCVSS 8.8fixed in 87.0≥ unspecified, < 872021-03-31
CVE-2021-23987 [HIGH] CWE-787 CVE-2021-23987: Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.
nvd
CVE-2013-0744P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0744 [CRITICAL] CWE-416 CVE-2013-0744: Use-after-free vulnerability in the TableBackgroundPainter::TableBackgroundData::Destroy function in
Use-after-free vulnerability in the TableBackgroundPainter::TableBackgroundData::Destroy function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or
nvd