Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 6 of 162
CVE-2026-16412P3CRITICALCVSS 9.8fixed in 153.0.0≥ 140.1.0, < 140.13.02026-07-21
CVE-2026-16412 [CRITICAL] CWE-119 CVE-2026-16412: Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2024-8381P3CRITICALCVSS 9.8fixed in 130.0≥ unspecified, < 1302024-09-03
CVE-2024-8381 [CRITICAL] CWE-843 CVE-2024-8381: A potentially exploitable type confusion could be triggered when looking up a property name on an ob
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
nvd
CVE-2021-38503P3CRITICALCVSS 10.0fixed in 94.0≥ unspecified, < 942021-12-08
CVE-2021-38503 [CRITICAL] CWE-863 CVE-2021-38503: The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypas
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvdosv
CVE-2019-25136P3CRITICALCVSS 10.0fixed in 70.0≥ unspecified, < 702023-06-19
CVE-2019-25136 [CRITICAL] CVE-2019-25136: A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.
nvd
CVE-2026-4688P3CRITICALCVSS 10.0fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4688 [CRITICAL] CWE-416 CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-2768P3CRITICALCVSS 10.0fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2768 [CRITICAL] CWE-284 CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Fir
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-0881P3CRITICALCVSS 10.0fixed in 147.02026-01-13
CVE-2026-0881 [CRITICAL] CWE-284 CVE-2026-0881: Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Th
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
nvd
CVE-2026-16383P3CRITICALCVSS 9.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16383 [CRITICAL] CWE-693 CVE-2026-16383: Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Fir
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16360P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16360 [CRITICAL] CWE-119 CVE-2026-16360: Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these
Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and
nvdmozilla
CVE-2026-16361P3CRITICALCVSS 9.8fixed in 115.38.0≥ 128.1.0, < 140.13.02026-07-21
CVE-2026-16361 [CRITICAL] CWE-119 CVE-2026-16361: Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory c
Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
nvd
CVE-2026-16349P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16349 [CRITICAL] CWE-346 CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-4692P3CRITICALCVSS 10.0fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4692 [CRITICAL] CWE-653 CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149,
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-2776P3CRITICALCVSS 10.0fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2776 [CRITICAL] CWE-119 CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software.
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2761P3CRITICALCVSS 10.0fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2761 [CRITICAL] CWE-693 CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Fi
Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2760P3CRITICALCVSS 10.0fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2760 [CRITICAL] CWE-1384 CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulne
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-16356P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16356 [CRITICAL] CWE-416 CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16352P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16352 [CRITICAL] CWE-416 CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16351P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16351 [CRITICAL] CWE-416 CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16377P3CRITICALCVSS 9.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16377 [CRITICAL] CWE-693 CVE-2026-16377: Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2025-2817P3HIGHCVSS 8.8fixed in 115.23.0fixed in 138.0+1 more2025-04-29
CVE-2025-2817 [HIGH] CWE-22 CVE-2025-2817: Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling
nvd