Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 51 of 162
CVE-2016-1521P3HIGHCVSS 8.8≤ 42.0v38.0.1+11 more2016-02-13
CVE-2016-1521 [HIGH] CWE-119 CVE-2016-1521: The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla F
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application cras
nvd
CVE-2013-0765P3CRITICALCVSS 9.3fixed in 19.02013-02-19
CVE-2013-0765 [CRITICAL] CVE-2013-0765: Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent mul
Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2025-0241P3HIGHCVSS 7.7fixed in 128.6.0fixed in 134.02025-01-07
CVE-2025-0241 [HIGH] CWE-401 CVE-2025-0241: When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially e
When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
nvd
CVE-2010-3776P3CRITICALCVSS 9.3v3.6v3.6.2+94 more2010-12-10
CVE-2010-3776 [CRITICAL] CWE-119 CVE-2010-3776: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2018-12362P3HIGHCVSS 8.8fixed in 61.0≥ 53.0, < 60.1.0+1 more2018-10-18
CVE-2018-12362 [HIGH] CWE-190 CVE-2018-12362: An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Ext
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2011-0079P3CRITICALCVSS 10.0v4.02011-05-07
CVE-2011-0079 [CRITICAL] CVE-2011-0079: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x before 4.0.1 allow
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x before 4.0.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to gfx/layers/d3d10/ReadbackManagerD3D10.cpp and unknown other vectors.
nvd
CVE-2024-10466P3HIGHCVSS 7.5fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10466 [HIGH] CWE-400 CVE-2024-10466: By sending a specially crafted push message, a remote server could have hung the parent process, cau
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2023-5731P3CRITICALCVSS 9.8fixed in 119.0≥ unspecified, < 1192023-10-25
CVE-2023-5731 [CRITICAL] CWE-787 CVE-2023-5731: Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119.
nvdosv
CVE-2026-4686P3HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4686 [HIGH] CWE-754 CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in F
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4685P3HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4685 [HIGH] CWE-754 CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in F
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2015-4474P3CRITICALCVSS 10.0≤ 39.0.32015-08-16
CVE-2015-4474 [CRITICAL] CVE-2015-4474: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2009-2463P3CRITICALCVSS 10.0v0.1v0.2+88 more2009-07-22
CVE-2009-2463 [CRITICAL] CWE-189 CVE-2009-2463: Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/l
Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspec
nvd
CVE-2026-6746P3HIGHCVSS 7.5fixed in 115.35.0fixed in 150.0+1 more2026-04-21
CVE-2026-6746 [HIGH] CWE-416 CVE-2026-6746: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firef
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-8949P3HIGHCVSS 7.5fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8949 [HIGH] CWE-190 CVE-2026-8949: Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefo
Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2026-4707P3HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4707 [HIGH] CWE-754 CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in F
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2010-3778P3CRITICALCVSS 9.3v3.5v3.5.1+14 more2010-12-10
CVE-2010-3778 [CRITICAL] CWE-119 CVE-2010-3778: Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and Sea
Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and SeaMonkey before 2.0.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2026-8946P3HIGHCVSS 7.5fixed in 115.36.0fixed in 151.0.0+1 more2026-05-19
CVE-2026-8946 [HIGH] CWE-119 CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2026-8954P3HIGHCVSS 7.5fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8954 [HIGH] CWE-119 CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was
Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2026-6749P3HIGHCVSS 7.5fixed in 115.35.0fixed in 150.0+1 more2026-04-21
CVE-2026-6749 [HIGH] CWE-908 CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnera
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2014-1533P3CRITICALCVSS 10.0v24.0v24.0.1+4 more2014-06-11
CVE-2014-1533 [CRITICAL] CVE-2014-1533: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv