cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 53 of 162
CVE-2012-1975P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-1975 [CRITICAL] CWE-416 CVE-2012-1975: Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0, Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-1973P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-1973 [CRITICAL] CWE-416 CVE-2012-1973: Use-after-free vulnerability in the nsObjectLoadingContent::LoadObject function in Mozilla Firefox b Use-after-free vulnerability in the nsObjectLoadingContent::LoadObject function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified
nvd
CVE-2012-1974P3CRITICALCVSS 10.0fixed in 15.0≥ 10.0, < 10.0.72012-08-29
CVE-2012-1974 [CRITICAL] CWE-416 CVE-2012-1974: Use-after-free vulnerability in the gfxTextRun::CanBreakLineBefore function in Mozilla Firefox befor Use-after-free vulnerability in the gfxTextRun::CanBreakLineBefore function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vect
nvd
CVE-2026-6751P3HIGHCVSS 7.3fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6751 [HIGH] CWE-457 CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6753P3HIGHCVSS 7.3fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6753 [HIGH] CWE-119 CVE-2026-6753: Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2025-14325P3HIGHCVSS 7.3fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14325 [HIGH] CWE-843 CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvd
CVE-2012-1951P3CRITICALCVSS 10.0v4.0v4.0.1+20 more2012-07-18
CVE-2012-1951 [CRITICAL] CWE-399 CVE-2012-1951: Use-after-free vulnerability in the nsSMILTimeValueSpec::IsEventBased function in Mozilla Firefox 4. Use-after-free vulnerability in the nsSMILTimeValueSpec::IsEventBased function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary cod
nvd
CVE-2020-6806P3HIGHCVSS 8.8fixed in 74.0≥ unspecified, < 74+1 more2020-03-25
CVE-2020-6806 [HIGH] CWE-125 CVE-2020-6806: By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the en By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2011-2988P3CRITICALCVSS 10.0v4.0v4.0.1+1 more2011-08-18
CVE-2011-2988 [CRITICAL] CWE-119 CVE-2011-2988: Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long source-code block for a shader.
nvd
CVE-2026-12324P3HIGHCVSS 7.3fixed in Firefox 152
CVE-2026-12324 [HIGH] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12324 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12324 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2013-1719P3CRITICALCVSS 10.0≤ 23.0.1v19.0+7 more2013-09-18
CVE-2013-1719 [CRITICAL] CWE-119 CVE-2013-1719: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbi Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-1702P3CRITICALCVSS 10.0≤ 22.0v19.0+5 more2013-08-07
CVE-2013-1702 [CRITICAL] CVE-2013-1702: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMon Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-2998P3CRITICALCVSS 10.0v3.6v3.6.2+19 more2011-09-30
CVE-2011-2998 [CRITICAL] CWE-189 CVE-2011-2998: Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial o Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.
nvd
CVE-2018-12389P3HIGHCVSS 8.8fixed in 60.3.02019-02-28
CVE-2018-12389 [HIGH] CWE-119 CVE-2018-12389: Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. So Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.3 and Thunderbird < 60.3.
nvd
CVE-2010-0177P3CRITICALCVSS 9.3v3.6≤ 3.0.17+92 more2010-04-05
CVE-2010-0177 [CRITICAL] CWE-399 CVE-2010-0177: Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0. Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, relate
nvd
CVE-2013-5590P3CRITICALCVSS 10.0v17.0v17.0.1+21 more2013-10-30
CVE-2013-5590 [CRITICAL] CVE-2013-5590: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary co
nvd
CVE-2012-3964P3CRITICALCVSS 10.0v10.0v10.0.1+133 more2012-08-29
CVE-2012-3964 [CRITICAL] CWE-399 CVE-2012-3964: Use-after-free vulnerability in the gfxTextRun::GetUserData function in Mozilla Firefox before 15.0, Use-after-free vulnerability in the gfxTextRun::GetUserData function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2019-11752P3HIGHCVSS 8.8fixed in 60.9.0fixed in 69.0+1 more2019-09-27
CVE-2019-11752 [HIGH] CWE-416 CVE-2019-11752: It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
nvd
CVE-2017-7752P3HIGHCVSS 8.8fixed in 54.0fixed in 52.2.0+1 more2018-06-11
CVE-2017-7752 [HIGH] CWE-416 CVE-2017-7752: A use-after-free vulnerability during specific user interactions with the input method editor (IME) A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2014-1477P3CRITICALCVSS 9.8fixed in 27.0≥ 24.0, < 24.32014-02-06
CVE-2014-1477 [CRITICAL] CVE-2014-1477: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
Mozilla Firefox vulnerabilities | cvebase