Mozilla Firefox vulnerabilities
3,257 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,257
CISA KEV
17
actively exploited
Public exploits
123
Exploited in wild
22
Severity breakdown
CRITICAL875HIGH984MEDIUM1324LOW72UNKNOWN2
Vulnerabilities
Page 6 of 163
CVE-2026-6774MEDIUMCVSS 5.4fixed in 150.02026-04-21
CVE-2026-6774 [MEDIUM] CWE-693 CVE-2026-6774: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Th
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-6777MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6777 [MEDIUM] CWE-20 CVE-2026-6777: Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunde
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-6779MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6779 [MEDIUM] CWE-20 CVE-2026-6779: Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thun
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-6783MEDIUMCVSS 5.3fixed in 150.02026-04-21
CVE-2026-6783 [MEDIUM] CWE-190 CVE-2026-6783: Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnera
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-6765MEDIUMCVSS 5.3fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6765 [MEDIUM] CWE-359 CVE-2026-6765: Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150,
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozillaredhat
CVE-2026-6764MEDIUMCVSS 6.5fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6764 [MEDIUM] CWE-119 CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed
Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozillaredhat
CVE-2026-6654MEDIUMCVSS 5.12026-04-20
CVE-2026-6654 [MEDIUM] CWE-1341 thin-vec: mozilla/thin-vec: Memory corruption vulnerability via Double-Free/Use-After-Free
thin-vec: mozilla/thin-vec: Memory corruption vulnerability via Double-Free/Use-After-Free
A flaw was found in the `thin_vec` component of `mozilla/thin-vec`. This vulnerability involves a memory management error known as a Double-Free/Use-After-Free (UAF), which occurs in the `IntoIter::drop` and `ThinVec::clear` functions. When a specific error condition (a panic in `ptr:
redhat
CVE-2026-5734CRITICALCVSS 9.8fixed in 140.9.1fixed in 149.0.22026-04-07
CVE-2026-5734 [CRITICAL] CWE-787 CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thun
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunde
nvdmozilla
CVE-2026-5735CRITICALCVSS 9.8fixed in 149.0.22026-04-07
CVE-2026-5735 [CRITICAL] CWE-787 CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evi
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
nvdmozilla
CVE-2026-5732HIGHCVSS 8.8fixed in 140.9.1fixed in 149.0.22026-04-07
CVE-2026-5732 [HIGH] CWE-190 CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
nvdmozilla
CVE-2026-5733HIGHCVSS 8.8fixed in 149.0.22026-04-07
CVE-2026-5733 [HIGH] CWE-119 CVE-2026-5733: Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Fir
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
nvdmozilla
CVE-2026-4691CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4691 [CRITICAL] CWE-416 CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4698CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4698 [CRITICAL] CWE-843 CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4700CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4700 [CRITICAL] CWE-288 CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Fi
Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4701CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4701 [CRITICAL] CWE-416 CVE-2026-4701: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Fire
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4725CRITICALCVSS 10.0fixed in 149.02026-03-24
CVE-2026-4725 [CRITICAL] CWE-416 CVE-2026-4725: Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fix
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvdmozilla
CVE-2026-4689CRITICALCVSS 10.0fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4689 [CRITICAL] CWE-190 CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This v
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4717CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4717 [CRITICAL] CVE-2026-4717: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firef
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4702CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4702 [CRITICAL] CWE-843 CVE-2026-4702: JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149,
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4688CRITICALCVSS 10.0fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4688 [CRITICAL] CWE-416 CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla