Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 38 of 162
CVE-2018-5091P3CRITICALCVSS 9.8fixed in 58.0fixed in 52.6.0+1 more2018-06-11
CVE-2018-5091 [CRITICAL] CWE-416 CVE-2018-5091: A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF ti
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
nvd
CVE-2007-3737P3CRITICALCVSS 9.3v2.0v2.0.0.1+3 more2007-07-18
CVE-2007-3737 [CRITICAL] CVE-2007-3737: Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privile
Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecified "element outside of a document."
nvd
CVE-2013-0746P3CRITICALCVSS 9.3fixed in 18.0≥ 10.0, < 10.0.12+1 more2013-01-13
CVE-2013-0746 [CRITICAL] CVE-2013-0746: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 do not properly implement quickstubs that use the jsval data type for their return values, which allows remote attackers to execute arbitrary code or cause a den
nvd
CVE-2014-1525P3CRITICALCVSS 9.3fixed in 29.02014-04-30
CVE-2014-1525 [CRITICAL] CWE-416 CVE-2014-1525: The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.2
The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) via a crafted VIDEO element in an HTML do
nvdosv
CVE-2017-5443P3CRITICALCVSS 9.8fixed in 45.9.0fixed in 53.0+2 more2018-06-11
CVE-2017-5443 [CRITICAL] CWE-787 CVE-2017-5443: An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This v
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2015-4496P3CRITICALCVSS 9.3≤ 37.0.22015-08-16
CVE-2015-4496 [CRITICAL] CVE-2015-4496: Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers t
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
nvdosv
CVE-2020-15683P3CRITICALCVSS 9.8fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15683 [CRITICAL] CWE-416 CVE-2020-15683: Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird <
nvd
CVE-2014-1556P3CRITICALCVSS 9.3≤ 30.0v24.0+4 more2014-07-23
CVE-2014-1556 [CRITICAL] CWE-94 CVE-2014-1556: Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote
Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
nvdosv
CVE-2005-1477P4MEDIUMCVSS 5.1PoCv1.0.32005-05-09
CVE-2005-1477 [MEDIUM] CVE-2005-1477: The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as up
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package ico
nvd
CVE-2008-2798P3CRITICALCVSS 10.0≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2798 [CRITICAL] CWE-399 CVE-2008-2798: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and ea
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the layout engine.
nvd
CVE-2016-2799P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2799 [HIGH] CWE-119 CVE-2016-2799: Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as u
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
nvd
CVE-2017-7788P3CRITICALCVSS 9.8fixed in 55.0≥ unspecified, < 552018-06-11
CVE-2017-7788 [CRITICAL] CWE-74 CVE-2017-7788: When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.
nvdosv
CVE-2026-12292P3HIGHCVSS 8.1fixed in 140.12.0fixed in 152.0.02026-06-16
CVE-2026-12292 [HIGH] CWE-119 CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 15
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
nvdmozilla
CVE-2015-4516P3CRITICALCVSS 9.3≤ 40.0.32015-09-24
CVE-2015-4516 [CRITICAL] CWE-254 CVE-2015-4516: Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API pro
Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.
nvdosv
CVE-2025-3034P3HIGHCVSS 8.1fixed in 137.02025-04-01
CVE-2025-3034 [HIGH] CWE-787 CVE-2025-3034: Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
nvd
CVE-2018-12359P3HIGHCVSS 8.8fixed in 61.0≥ unspecified, < 612018-10-18
CVE-2018-12359 [HIGH] CWE-119 CVE-2018-12359: A buffer overflow can occur when rendering canvas content while adjusting the height and width of th
A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundaries. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52
nvd
CVE-2015-7181P3HIGHCVSS 7.5≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-7181 [HIGH] CWE-119 CVE-2015-7181: The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.2
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly
nvd
CVE-2010-3770P4MEDIUMCVSS 4.3PoCv3.6v3.6.2+112 more2010-12-10
CVE-2010-3770 [MEDIUM] CWE-79 CVE-2010-3770: Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox befor
Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3) x-mac-hebrew characters that may be converted to angle brackets during rendering.
nvd
CVE-2013-1727P4MEDIUMCVSS 4.0PoC≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1727 [MEDIUM] CWE-79 CVE-2013-1727: Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and conseq
Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.
nvd
CVE-2016-5261P3HIGHCVSS 8.8≤ 47.0.12016-08-05
CVE-2016-5261 [HIGH] CWE-190 CVE-2016-5261: Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before
Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before 48.0 and Firefox ESR < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets that trigger incorrect buffer-resize operations during buffering.
nvd