Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 45 of 162
CVE-2016-9066P3HIGHCVSS 7.5fixed in 45.5.0fixed in 50.0+1 more2018-06-11
CVE-2016-9066 [HIGH] CWE-119 CVE-2016-9066: A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2026-6784P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6784 [HIGH] CWE-125 CVE-2026-6784: Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-16354P3HIGHCVSS 7.5fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16354 [HIGH] CWE-200 CVE-2026-16354: Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2024-2615P3CRITICALCVSS 9.8fixed in 124.0≥ unspecified, < 1242024-03-19
CVE-2024-2615 [CRITICAL] CWE-787 CVE-2024-2615: Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.
nvdosv
CVE-2024-5701P3CRITICALCVSS 9.8fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5701 [CRITICAL] CWE-787 CVE-2024-5701: Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.
nvdosv
CVE-2026-7320P3HIGHCVSS 7.5fixed in 115.35.1fixed in 150.0.1+1 more2026-04-28
CVE-2026-7320 [HIGH] CWE-119 CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulne
Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
nvdmozilla
CVE-2026-6772P3HIGHCVSS 7.5fixed in 115.35.0fixed in 150.0+1 more2026-04-21
CVE-2026-6772 [HIGH] CWE-754 CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Fir
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6766P3HIGHCVSS 7.5fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6766 [HIGH] CWE-754 CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Fir
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-12312P3HIGHCVSS 7.5fixed in Firefox 152
CVE-2026-12312 [HIGH] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12312
Mozilla Foundation Security Advisory 2026-57
CVE: CVE-2026-12312
Product: Firefox
Impact: high
Fixed in: Firefox 152
mozilla
CVE-2026-12310P3HIGHCVSS 7.5fixed in Firefox 152
CVE-2026-12310 [HIGH] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12310
Mozilla Foundation Security Advisory 2026-57
CVE: CVE-2026-12310
Product: Firefox
Impact: high
Fixed in: Firefox 152
mozilla
CVE-2026-12314P3HIGHCVSS 7.5fixed in Firefox 152
CVE-2026-12314 [HIGH] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12314
Mozilla Foundation Security Advisory 2026-57
CVE: CVE-2026-12314
Product: Firefox
Impact: high
Fixed in: Firefox 152
mozilla
CVE-2024-8389P3CRITICALCVSS 9.8v129.0≥ unspecified, < 1302024-09-03
CVE-2024-8389 [CRITICAL] CWE-787 CVE-2024-8389: Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130.
nvdosv
CVE-2016-1959P3HIGHCVSS 8.8≤ 44.0.22016-03-13
CVE-2016-1959 [HIGH] CWE-119 CVE-2016-1959: The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arb
The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.
nvd
CVE-2015-4509P3HIGHCVSS 7.5v38.0v38.0.1+6 more2015-09-24
CVE-2015-4509 [HIGH] CVE-2015-4509: Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41.0 and Fi
Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via crafted JavaScript code that modifies the URI table of a media element, aka ZDI-CAN-3176.
nvdosv
CVE-2026-8390P3HIGHCVSS 7.3fixed in 150.0.32026-05-12
CVE-2026-8390 [HIGH] CWE-416 CVE-2026-8390: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
nvdmozilla
CVE-2013-1676P3CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1676 [CRITICAL] CWE-119 CVE-2013-1676: The SelectionIterator::GetNextSegment function in Mozilla Firefox before 21.0, Firefox ESR 17.x befo
The SelectionIterator::GetNextSegment function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-1976P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-1976 [CRITICAL] CWE-416 CVE-2012-1976: Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firef
Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecif
nvd
CVE-2012-1972P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-1972 [CRITICAL] CWE-416 CVE-2012-1972: Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Fire
Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspeci
nvd
CVE-2015-2740P3CRITICALCVSS 10.0v31.0v31.1.0+7 more2015-07-06
CVE-2015-2740 [CRITICAL] CWE-119 CVE-2015-2740: Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.
Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
nvdosv
CVE-2006-5633P4MEDIUMCVSS 5.0PoCv1.5.0.7v2.02006-10-31
CVE-2006-5633 [MEDIUM] CVE-2006-5633: Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (c
Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution w
nvd