cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 67 of 162
CVE-2026-16398P3HIGHCVSS 7.5fixed in 153.0.02026-07-21
CVE-2026-16398 [HIGH] CWE-200 CVE-2026-16398: Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thun Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2008-5014P3CRITICALCVSS 10.0≥ 2.0, < 2.0.0.18≥ 3.0, < 3.0.22008-11-13
CVE-2008-5014 [CRITICAL] CWE-20 CVE-2008-5014: jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which trigg
nvd
CVE-2022-22759P3CRITICALCVSS 9.6fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22759 [CRITICAL] CWE-693 CVE-2022-22759: If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently append If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2025-1936P3HIGHCVSS 7.3fixed in 128.8.0fixed in 136.02025-03-04
CVE-2025-1936 [HIGH] CWE-158 CVE-2025-1936: jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it wa jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerabilit
nvd
CVE-2006-5159P3HIGHCVSS 7.5v0.8v0.9+25 more2006-10-05
CVE-2006-5159 [HIGH] CVE-2006-5159: Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE: the vendor and original researchers have released a follow-up comment disputing the severity of this issue, in which the researcher states that "we mentioned that there was a previously known Firefox vulnerability
nvd
CVE-2014-1547P3CRITICALCVSS 10.0≤ 30.0v24.0+4 more2014-07-23
CVE-2014-1547 [CRITICAL] CVE-2014-1547: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2025-10528P3HIGHCVSS 7.3fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10528 [HIGH] CWE-693 CVE-2025-10528: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvd
CVE-2026-12318P3HIGHCVSS 7.3fixed in Firefox 152
CVE-2026-12318 [HIGH] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12318 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12318 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2011-2375P3CRITICALCVSS 10.0≤ 4.0.1v1.0+105 more2011-06-30
CVE-2011-2375 [CRITICAL] CVE-2011-2375: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunder Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2018-5125P3HIGHCVSS 8.8fixed in 52.7.0fixed in 59.0+1 more2018-06-11
CVE-2018-5125 [HIGH] CWE-119 CVE-2018-5125: Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evide Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvdosv
CVE-2013-1679P3CRITICALCVSS 10.0≤ 20.0.1v19.0+9 more2013-05-16
CVE-2013-1679 [CRITICAL] CWE-399 CVE-2013-1679: Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firef Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2013-5603P3CRITICALCVSS 10.0v24.0v24.0.1+11 more2013-10-30
CVE-2013-5603 [CRITICAL] CVE-2013-5603: Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in M Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.
nvd
CVE-2009-2462P3CRITICALCVSS 10.0v0.1v0.2+88 more2009-07-22
CVE-2009-2462 [CRITICAL] CWE-399 CVE-2009-2462: The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame,
nvd
CVE-2011-2997P3CRITICALCVSS 10.0v6.02011-09-29
CVE-2011-2997 [CRITICAL] CVE-2011-2997: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-2985P3CRITICALCVSS 10.0v4.0v4.0.1+1 more2011-08-18
CVE-2011-2985 [CRITICAL] CVE-2011-2985: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 5, Thunder Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-3983P3CRITICALCVSS 10.0fixed in 16.02012-10-10
CVE-2012-3983 [CRITICAL] CWE-119 CVE-2012-3983: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbi Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2016-2790P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2790 [HIGH] CWE-19 CVE-2016-2790: The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
nvd
CVE-2016-2795P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2795 [HIGH] CWE-19 CVE-2016-2795: The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefo The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
nvd
CVE-2011-2982P3CRITICALCVSS 10.0≤ 3.6.19v1.0+105 more2011-08-18
CVE-2011-2982 [CRITICAL] CVE-2011-2982: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.20, Thunder Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-3075P3CRITICALCVSS 10.0≤ 3.0.13v0.1+93 more2009-09-10
CVE-2009-3075 [CRITICAL] CVE-2009-3075: Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3 Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the j
nvd