Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 37 of 162
CVE-2024-0745P3HIGHCVSS 8.8fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0745 [HIGH] CWE-787 CVE-2024-0745: The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led
The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.
nvdosv
CVE-2024-3856P3HIGHCVSS 8.8fixed in 125.0≥ unspecified, < 1252024-04-16
CVE-2024-3856 [HIGH] CWE-416 CVE-2024-3856: A use-after-free could occur during WASM execution if garbage collection ran during the creation of
A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.
nvdosv
CVE-2023-37209P3HIGHCVSS 8.8fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37209 [HIGH] CWE-416 CVE-2023-37209: A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` o
A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` object was freed and a reference to that object remained. This resulted in a potentially exploitable condition when the reference to that object was later reused. This vulnerability affects Firefox < 115.
nvdosv
CVE-2022-22755P3HIGHCVSS 8.8fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22755 [HIGH] CWE-672 CVE-2022-22755: By using XSL Transforms, a malicious webserver could have served a user an XSL document that would c
By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.
nvdosv
CVE-2023-25731P3HIGHCVSS 8.8fixed in 110.0≥ unspecified, < 1102023-06-02
CVE-2023-25731 [HIGH] CWE-1284 CVE-2023-25731: Due to URL previews in the network panel of developer tools improperly storing URLs, query parameter
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
nvdosv
CVE-2024-9396P3HIGHCVSS 8.8fixed in 128.3.0fixed in 131.0+1 more2024-10-01
CVE-2024-9396 [HIGH] CWE-119 CVE-2024-9396: It is currently unknown if this issue is exploitable but a condition may arise where the structured
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2008-2785P3CRITICALCVSS 9.3≤ 2.0.0.15v2.0+15 more2008-06-19
CVE-2008-2785 [CRITICAL] CWE-189 CVE-2008-2785: Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey bef
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS objec
nvd
CVE-2018-5188P3CRITICALCVSS 9.8fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-5188 [CRITICAL] CWE-119 CVE-2018-5188: Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs s
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefo
nvd
CVE-2025-1930P3HIGHCVSS 8.8fixed in 115.21.0fixed in 136.0+1 more2025-03-04
CVE-2025-1930 [HIGH] CWE-416 CVE-2025-1930: On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a u
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvd
CVE-2026-5732P3HIGHCVSS 8.8fixed in 140.9.1fixed in 149.0.22026-04-07
CVE-2026-5732 [HIGH] CWE-190 CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
nvd
CVE-2026-8389P3HIGHCVSS 8.8fixed in 150.0.32026-05-12
CVE-2026-8389 [HIGH] CWE-119 CVE-2026-8389: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
nvdmozilla
CVE-2026-2798P3HIGHCVSS 8.8fixed in 148.02026-02-24
CVE-2026-2798 [HIGH] CWE-416 CVE-2026-2798: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Th
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2025-6426P3HIGHCVSS 8.8fixed in 128.12.0fixed in 140.02025-06-24
CVE-2025-6426 [HIGH] CWE-345 CVE-2025-6426: The executable file warning did not warn users before opening files with the `terminal` extension.
The executable file warning did not warn users before opening files with the `terminal` extension.
*This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
nvd
CVE-2010-1196P3CRITICALCVSS 9.3v3.5v3.5.1+10 more2010-06-24
CVE-2010-1196 [CRITICAL] CWE-189 CVE-2010-1196: Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x befo
Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.
nvd
CVE-2009-2953P4MEDIUMCVSS 5.0PoCv3.0.6v3.0.7+11 more2009-08-24
CVE-2009-2953 [MEDIUM] CVE-2009-2953: Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of servic
Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.
nvd
CVE-2017-5438P3CRITICALCVSS 9.8fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5438 [CRITICAL] CWE-416 CVE-2017-5438: A use-after-free vulnerability during XSLT processing due to the result handler being held by a free
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2008-7244P4MEDIUMCVSS 5.0PoC≤ 3.0.1v0.1+56 more2009-09-18
CVE-2008-7244 [MEDIUM] CWE-399 CVE-2008-7244: Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang
Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.
nvd
CVE-2013-0762P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0762 [CRITICAL] CWE-416 CVE-2013-0762: Use-after-free vulnerability in the imgRequest::OnStopFrame function in Mozilla Firefox before 18.0,
Use-after-free vulnerability in the imgRequest::OnStopFrame function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (h
nvd
CVE-2013-0766P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0766 [CRITICAL] CWE-416 CVE-2013-0766: Use-after-free vulnerability in the ~nsHTMLEditRules implementation in Mozilla Firefox before 18.0,
Use-after-free vulnerability in the ~nsHTMLEditRules implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (hea
nvd
CVE-2017-7818P3CRITICALCVSS 9.8fixed in 52.4.0fixed in 56.0+1 more2018-06-11
CVE-2017-7818 [CRITICAL] CWE-416 CVE-2017-7818: A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applic
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd