Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 65 of 162
CVE-2017-5413P3CRITICALCVSS 9.8fixed in 52.0≥ unspecified, < 522018-06-11
CVE-2017-5413 [CRITICAL] CWE-119 CVE-2017-5413: A segmentation fault can occur during some bidirectional layout operations. This vulnerability affec
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.
nvdosv
CVE-2008-2811P3CRITICALCVSS 10.0≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2811 [CRITICAL] CWE-399 CVE-2008-2811: The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier
The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.
nvd
CVE-2011-0070P3CRITICALCVSS 10.0v3.6v3.6.2+33 more2011-05-07
CVE-2011-0070 [CRITICAL] CVE-2011-0070: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerabil
nvd
CVE-2011-0069P3CRITICALCVSS 10.0v3.6v3.6.2+33 more2011-05-07
CVE-2011-0069 [CRITICAL] CVE-2011-0069: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerabil
nvd
CVE-2017-7758P3CRITICALCVSS 9.1fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7758 [CRITICAL] CWE-125 CVE-2017-7758: An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio st
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2019-9802P3HIGHCVSS 7.5fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9802 [HIGH] CWE-125 CVE-2019-9802: If a Sandbox content process is compromised, it can initiate an FTP download which will then use a c
If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an attacker, bypassing sandbox protections and allow for a potential memory read of adjacent data from the p
nvdosv
CVE-2024-3857P3HIGHCVSS 7.8fixed in 115.10fixed in 125.0+1 more2024-04-16
CVE-2024-3857 [HIGH] CWE-416 CVE-2024-3857: The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2019-9805P3CRITICALCVSS 9.8fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9805 [CRITICAL] CWE-908 CVE-2019-9805: A latent vulnerability exists in the Prio library where data may be read from uninitialized memory f
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.
nvdosv
CVE-2009-2466P3CRITICALCVSS 10.0fixed in 3.0.122009-07-22
CVE-2009-2466 [CRITICAL] CWE-787 CVE-2009-2466: The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to ca
The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.
nvd
CVE-2024-5702P3HIGHCVSS 7.5fixed in 115.12fixed in 125.0+1 more2024-06-11
CVE-2024-5702 [HIGH] CWE-416 CVE-2024-5702: Memory corruption in the networking stack could have led to a potentially exploitable crash. This vu
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2026-4694P3HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4694 [HIGH] CWE-190 CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fi
Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2006-1739P3CRITICALCVSS 9.3v1.0v1.0.1+7 more2006-04-14
CVE-2006-1739 [CRITICAL] CWE-119 CVE-2006-1739: The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0
The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer ove
nvd
CVE-2021-29952P3HIGHCVSS 7.5fixed in 88.0.1fixed in 88.1.3+1 more2021-06-24
CVE-2021-29952 [HIGH] CWE-362 CVE-2021-29952: When Web Render components were destructed, a race condition could have caused undefined behavior, a
When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.
nvdosv
CVE-2026-4695P3HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4695 [HIGH] CWE-754 CVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4697P3HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4697 [HIGH] CWE-754 CVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2024-1552P3HIGHCVSS 7.5fixed in 115.8.0fixed in 123.0+1 more2024-02-20
CVE-2024-1552 [HIGH] CWE-681 CVE-2024-1552: Incorrect code generation could have led to unexpected numeric conversions and potential undefined b
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2022-26387P3HIGHCVSS 7.5fixed in 98.0≥ unspecified, < 982022-12-22
CVE-2022-26387 [HIGH] CWE-367 CVE-2022-26387: When installing an add-on, Firefox verified the signature before prompting the user; but while the u
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd
CVE-2022-22741P3HIGHCVSS 7.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22741 [HIGH] CVE-2022-22741: When resizing a popup while requesting fullscreen access, the popup would have become unable to leav
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-4051P3HIGHCVSS 7.5fixed in 116.0≥ unspecified, < 1162023-08-01
CVE-2023-4051 [HIGH] CVE-2023-4051: A website could have obscured the full screen notification by using the file open dialog. This could
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2023-25743P3HIGHCVSS 7.5≥ unspecified, < 1102023-06-02
CVE-2023-25743 [HIGH] CWE-290 CVE-2023-25743: A lack of in app notification for entering fullscreen mode could have lead to a malicious website sp
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
nvd