Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 36 of 162
CVE-2021-29989P3HIGHCVSS 8.8fixed in 91.0≥ unspecified, < 912021-08-17
CVE-2021-29989 [HIGH] CWE-787 CVE-2021-29989: Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of
Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.13, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2021-29976P3HIGHCVSS 8.8fixed in 90.0≥ unspecified, < 902021-08-05
CVE-2021-29976 [HIGH] CWE-787 CVE-2021-29976: Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbir
Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
nvd
CVE-2021-38493P3HIGHCVSS 8.8fixed in 92.0≥ unspecified, < 922021-11-03
CVE-2021-38493 [HIGH] CWE-787 CVE-2021-38493: Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of
Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.
nvd
CVE-2017-5469P3CRITICALCVSS 9.8fixed in 45.9.0fixed in 53.0+1 more2018-06-11
CVE-2017-5469 [CRITICAL] CVE-2017-5469: Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2023-6863P3HIGHCVSS 8.8fixed in 121.0≥ unspecified, < 1212023-12-19
CVE-2023-6863 [HIGH] CVE-2023-6863: The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2010-2765P3CRITICALCVSS 9.3v3.6v3.6.2+86 more2010-09-09
CVE-2010-2765 [CRITICAL] CWE-189 CVE-2010-2765: Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x b
Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading to a heap-based buffer overflow.
nvd
CVE-2025-8037P3CRITICALCVSS 9.1fixed in 140.1fixed in 141.02025-07-22
CVE-2025-8037 [CRITICAL] CWE-614 CVE-2025-8037: Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the namel
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
nvd
CVE-2022-46874P3HIGHCVSS 8.8fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46874 [HIGH] CWE-94 CVE-2022-46874: A file with a long filename could have had its filename truncated to remove the valid extension, lea
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitte
nvd
CVE-2022-22751P3HIGHCVSS 8.8fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22751 [HIGH] CWE-787 CVE-2022-22751: Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto,
Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memory safety bugs present in Firefox 95 and Firefox ESR 91.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t
nvd
CVE-2021-29973P3HIGHCVSS 8.8fixed in 90.0≥ unspecified, < 902021-08-05
CVE-2021-29973 [HIGH] CVE-2021-29973: Password autofill was enabled without user interaction on insecure websites on Firefox for Android.
Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be entered by the browser's autofill functionality *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefo
nvd
CVE-2009-0733P3CRITICALCVSS 9.3v3.12009-03-23
CVE-2009-0733 [CRITICAL] CWE-787 CVE-2009-0733: Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or libl
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the Re
nvd
CVE-2023-4585P3HIGHCVSS 8.8fixed in 117.0≥ unspecified, < 1172023-09-11
CVE-2023-4585 [HIGH] CWE-787 CVE-2023-4585: Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these b
Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2023-32215P3HIGHCVSS 8.8fixed in 113.0≥ unspecified, < 1132023-06-02
CVE-2023-32215 [HIGH] CWE-787 CVE-2023-32215: Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian
Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112 and Firefox ESR 102.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been
nvd
CVE-2023-28176P3HIGHCVSS 8.8fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28176 [HIGH] CWE-787 CVE-2023-28176: Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2023-25737P3HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25737 [HIGH] CWE-704 CVE-2023-25737: An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undef
An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2023-23605P3HIGHCVSS 8.8fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23605 [HIGH] CWE-787 CVE-2023-23605: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 a
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunde
nvd
CVE-2023-29550P3HIGHCVSS 8.8fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29550 [HIGH] CVE-2023-29550: Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence
Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.1
nvd
CVE-2023-28162P3HIGHCVSS 8.8fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-28162 [HIGH] CWE-704 CVE-2023-28162: While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic ty
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2023-29536P3HIGHCVSS 8.8fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29536 [HIGH] CWE-416 CVE-2023-29536: An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-con
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvd
CVE-2023-25739P3HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25739 [HIGH] CWE-416 CVE-2023-25739: Module load requests that failed were not being checked as to whether or not they were cancelled cau
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in ScriptLoadContext. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd