Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 39 of 162
CVE-2015-2716P3HIGHCVSS 7.5≤ 37.0.2v31.0+6 more2015-05-14
CVE-2015-2716 [HIGH] CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
nvdosv
CVE-2020-12390P3CRITICALCVSS 9.8fixed in 76.0≥ unspecified, < 762020-05-26
CVE-2020-12390 [CRITICAL] CWE-502 CVE-2020-12390: Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks.
Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.
nvdosv
CVE-2007-2671P4HIGHCVSS 7.1PoCv2.0.0.32007-05-14
CVE-2007-2671 [HIGH] CVE-2007-2671: Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via
Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access.
nvd
CVE-2005-4720P4MEDIUMCVSS 5.0PoCv1.0.6v1.0.72005-12-31
CVE-2005-4720 [MEDIUM] CVE-2005-4720: Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (cli
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbers, leading to an infinite loop of widget resizes and a corresponding large number of function calls on the sta
nvd
CVE-2012-3961P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-3961 [CRITICAL] CWE-416 CVE-2012-3961: Use-after-free vulnerability in the RangeData implementation in Mozilla Firefox before 15.0, Firefox
Use-after-free vulnerability in the RangeData implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2023-5173P3HIGHCVSS 7.5fixed in 118≥ unspecified, < 1182023-09-27
CVE-2023-5173 [HIGH] CWE-190 CVE-2023-5173: In a non-standard configuration of Firefox, an integer overflow could have occurred based on network
In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory.
*This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe
nvdosv
CVE-2009-2468P3CRITICALCVSS 10.0≤ 3.0.11v0.1+81 more2009-07-22
CVE-2009-2468 [CRITICAL] CVE-2009-2468: Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.1
Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-
nvd
CVE-2018-5178P3HIGHCVSS 8.1fixed in 52.8.02018-06-11
CVE-2018-5178 [HIGH] CWE-119 CVE-2018-5178: A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremel
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
nvd
CVE-2013-5597P3CRITICALCVSS 10.0v17.0v17.0.1+21 more2013-10-30
CVE-2013-5597 [CRITICAL] CVE-2013-5597: Use-after-free vulnerability in the nsDocLoader::doStopDocumentLoad function in Mozilla Firefox befo
Use-after-free vulnerability in the nsDocLoader::doStopDocumentLoad function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via
nvd
CVE-2026-6786P3HIGHCVSS 7.5fixed in 150.0≥ 140.0, < 140.10.02026-04-26
CVE-2026-6786 [HIGH] CWE-125 CVE-2026-6786: Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird
Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunder
nvdmozilla
CVE-2011-3655P3CRITICALCVSS 9.3v4.0v4.0.1+6 more2011-11-09
CVE-2011-3655 [CRITICAL] CWE-94 CVE-2011-3655: Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without check
Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which allows remote attackers to gain privileges via a crafted web site.
nvd
CVE-2018-12363P3HIGHCVSS 8.8fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-12363 [HIGH] CWE-416 CVE-2018-12363: A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between
A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60
nvd
CVE-2019-11745P3HIGHCVSS 8.8fixed in 71.0vbefore 712020-01-08
CVE-2019-11745 [HIGH] CWE-787 CVE-2019-11745: When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2009-1834P4MEDIUMCVSS 4.3PoC≤ 3.0.10v0.1+88 more2009-06-12
CVE-2009-1834 [MEDIUM] CWE-20 CVE-2009-1834: Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11
Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.
nvd
CVE-2025-1942P3CRITICALCVSS 9.8fixed in 136.02025-03-04
CVE-2025-1942 [CRITICAL] CWE-908 CVE-2025-1942: When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
nvdosv
CVE-2016-1961P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1961 [HIGH] CVE-2016-1961: Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.
nvd
CVE-2026-7323P3HIGHCVSS 7.3fixed in 140.10.1fixed in 150.0.12026-04-28
CVE-2026-7323 [HIGH] CWE-119 CVE-2026-7323: Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs s
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
nvdmozilla
CVE-2026-7322P3HIGHCVSS 7.3fixed in 115.35.1fixed in 150.0.1+1 more2026-04-28
CVE-2026-7322 [HIGH] CWE-119 CVE-2026-7322: Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs s
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and
nvdmozilla
CVE-2026-7324P3HIGHCVSS 7.3fixed in 150.0.12026-04-28
CVE-2026-7324 [HIGH] CWE-119 CVE-2026-7324: Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corr
Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.
nvdmozilla
CVE-2018-5129P3HIGHCVSS 8.6fixed in 59.0fixed in 52.7.0+1 more2018-06-11
CVE-2018-5129 [HIGH] CWE-787 CVE-2018-5129: A lack of parameter validation on IPC messages results in a potential out-of-bounds write through ma
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd