Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 66 of 162
CVE-2024-8383P3HIGHCVSS 7.5fixed in 130.0≥ unspecified, < 1302024-09-03
CVE-2024-8383 [HIGH] CWE-1188 CVE-2024-8383: Firefox normally asks for confirmation before asking the operating system to find an application to
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user dow
nvd
CVE-2026-4727P3HIGHCVSS 7.5fixed in 149.02026-03-24
CVE-2026-4727 [HIGH] CWE-400 CVE-2026-4727: Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and
Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2026-4726P3HIGHCVSS 7.5fixed in 149.02026-03-24
CVE-2026-4726 [HIGH] CWE-400 CVE-2026-4726: Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird
Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2016-1953P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1953 [HIGH] CWE-119 CVE-2016-1953: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.
nvd
CVE-2016-5264P3HIGHCVSS 8.8≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-5264 [HIGH] CWE-416 CVE-2016-5264: Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla
Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG element that is mishandled during effect application.
nvd
CVE-2025-1012P3HIGHCVSS 7.5fixed in 115.20.0fixed in 135.0+1 more2025-02-04
CVE-2025-1012 [HIGH] CWE-416 CVE-2025-1012: A race during concurrent delazification could have led to a use-after-free. This vulnerability was f
A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
nvd
CVE-2026-4719P3HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4719 [HIGH] CWE-754 CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firef
Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4713P3HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4713 [HIGH] CWE-754 CVE-2026-4713: Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4714P3HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4714 [HIGH] CWE-754 CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4708P3HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4708 [HIGH] CWE-754 CVE-2026-4708: Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4704P3HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4704 [HIGH] CWE-400 CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, F
Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2024-31392P3HIGHCVSS 7.5fixed in 124.02024-04-03
CVE-2024-31392 [HIGH] CVE-2024-31392: If an insecure element was added to a page after a delay, Firefox would not replace the secure icon
If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.
nvd
CVE-2026-8960P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8960 [HIGH] CWE-290 CVE-2026-8960: Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2024-3853P3HIGHCVSS 7.5fixed in 125.0≥ unspecified, < 1252024-04-16
CVE-2024-3853 [HIGH] CWE-416 CVE-2024-3853: A use-after-free could result if a JavaScript realm was in the process of being initialized when a g
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.
nvdosv
CVE-2025-13025P3HIGHCVSS 7.5fixed in 145.02025-11-11
CVE-2025-13025 [HIGH] CWE-276 CVE-2025-13025: Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Fir
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
nvd
CVE-2010-0160P3CRITICALCVSS 10.0≤ 3.0.17v3.0+24 more2010-02-22
CVE-2010-0160 [CRITICAL] CWE-399 CVE-2010-0160: The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaM
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2026-6782P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6782 [HIGH] CWE-200 CVE-2026-6782: Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 a
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2026-2794P3HIGHCVSS 7.5fixed in 148.02026-02-24
CVE-2026-2794 [HIGH] CWE-908 CVE-2026-2794: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vu
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.
nvd
CVE-2026-6756P3HIGHCVSS 7.5fixed in 150.02026-04-21
CVE-2026-6756 [HIGH] CWE-200 CVE-2026-6756: Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
nvdmozilla
CVE-2026-16399P3HIGHCVSS 7.5fixed in 153.0.02026-07-21
CVE-2026-16399 [HIGH] CWE-346 CVE-2026-16399: Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 a
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla