cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 58 of 162
CVE-2017-7753P3CRITICALCVSS 9.1fixed in 55.0fixed in 52.3.0+1 more2018-06-11
CVE-2017-7753 [CRITICAL] CWE-125 CVE-2017-7753: An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, usi An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvdosv
CVE-2012-3980P3CRITICALCVSS 9.3v10.0v10.0.1+133 more2012-08-29
CVE-2012-3980 [CRITICAL] CWE-94 CVE-2012-3980: The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 1 The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.
nvd
CVE-2026-4699P3HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4699 [HIGH] CWE-754 CVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability was fixed Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4693P3HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4693 [HIGH] CWE-754 CVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed i Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2024-3852P3HIGHCVSS 7.5fixed in 115.10fixed in 125.0+1 more2024-04-16
CVE-2024-3852 [HIGH] CWE-386 CVE-2024-3852: GetBoundName could return the wrong version of an object when JIT optimizations were applied. This v GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvdosv
CVE-2024-10459P3HIGHCVSS 7.5fixed in 115.17fixed in 132.0+2 more2024-10-29
CVE-2024-10459 [HIGH] CWE-416 CVE-2024-10459: An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentia An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2023-32216P3CRITICALCVSS 9.8fixed in 113.0≥ unspecified, < 1132023-06-19
CVE-2023-32216 [CRITICAL] CWE-787 CVE-2023-32216: Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozil Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affe
nvdosv
CVE-2023-34417P3CRITICALCVSS 9.8fixed in 114.0≥ unspecified, < 1142023-06-19
CVE-2023-34417 [CRITICAL] CWE-787 CVE-2023-34417: Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.
nvdosv
CVE-2026-6758P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6758 [HIGH] CWE-416 CVE-2026-6758: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-4709P3HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4709 [HIGH] CWE-754 CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Fir Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4706P3HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4706 [HIGH] CWE-754 CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in F Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2025-13016P3HIGHCVSS 7.5fixed in 140.5.0fixed in 145.02025-11-11
CVE-2025-13016 [HIGH] CWE-703 CVE-2025-13016: Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
nvd
CVE-2013-5616P3CRITICALCVSS 9.8fixed in 26.0≥ 24.0, < 24.22013-12-11
CVE-2013-5616 [CRITICAL] CWE-416 CVE-2013-5616: Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla F Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listen
nvd
CVE-2026-6747P3HIGHCVSS 7.5fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6747 [HIGH] CWE-416 CVE-2026-6747: Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140 Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-6754P3HIGHCVSS 7.5fixed in 115.35.0fixed in 150.0+1 more2026-04-21
CVE-2026-6754 [HIGH] CWE-416 CVE-2026-6754: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-4712P3HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4712 [HIGH] CWE-200 CVE-2026-4712: Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2023-4058P3CRITICALCVSS 9.8fixed in 116.0≥ unspecified, < 1162023-08-01
CVE-2023-4058 [CRITICAL] CWE-787 CVE-2023-4058: Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116.
nvd
CVE-2026-12305P3HIGHCVSS 7.5fixed in Firefox 152
CVE-2026-12305 [HIGH] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12305 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12305 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2026-8966P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8966 [HIGH] CWE-200 CVE-2026-8966: Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 a Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-8967P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8967 [HIGH] CWE-200 CVE-2026-8967: Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 15 Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
Mozilla Firefox vulnerabilities | cvebase