Mozilla Firefox vulnerabilities
3,257 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,257
CISA KEV
17
actively exploited
Public exploits
123
Exploited in wild
22
Severity breakdown
CRITICAL875HIGH984MEDIUM1324LOW72UNKNOWN2
Vulnerabilities
Page 7 of 163
CVE-2026-4711CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4711 [CRITICAL] CWE-416 CVE-2026-4711: Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox
Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4692CRITICALCVSS 10.0fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4692 [CRITICAL] CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149,
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4710CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4710 [CRITICAL] CWE-119 CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4721CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4721 [CRITICAL] CWE-120 CVE-2026-4721: Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox
Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Fire
nvdmozilla
CVE-2026-4729CRITICALCVSS 9.8fixed in 149.02026-03-24
CVE-2026-4729 [CRITICAL] CWE-120 CVE-2026-4729: Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvdmozilla
CVE-2026-4716CRITICALCVSS 9.1fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4716 [CRITICAL] CWE-908 CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnera
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4696CRITICALCVSS 9.8fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4696 [CRITICAL] CWE-416 CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149,
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4720CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4720 [CRITICAL] CWE-120 CVE-2026-4720: Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun
nvdmozilla
CVE-2026-4715CRITICALCVSS 9.1fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4715 [CRITICAL] CWE-908 CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 14
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4724CRITICALCVSS 9.1fixed in 149.02026-03-24
CVE-2026-4724 [CRITICAL] CWE-758 CVE-2026-4724: Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thu
Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvdmozilla
CVE-2026-4723CRITICALCVSS 9.8fixed in 149.02026-03-24
CVE-2026-4723 [CRITICAL] CWE-416 CVE-2026-4723: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and T
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvdmozilla
CVE-2026-4705CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4705 [CRITICAL] CWE-758 CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149,
Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4690HIGHCVSS 8.6fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4690 [HIGH] CWE-190 CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This v
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4714HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4714 [HIGH] CWE-754 CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4684HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4684 [HIGH] CWE-362 CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in
Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4694HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4694 [HIGH] CWE-190 CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fi
Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4719HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4719 [HIGH] CWE-754 CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firef
Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4686HIGHCVSS 7.5fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4686 [HIGH] CWE-754 CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in F
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4712HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4712 [HIGH] CWE-200 CVE-2026-4712: Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149,
Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla
CVE-2026-4713HIGHCVSS 7.5fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4713 [HIGH] CWE-754 CVE-2026-4713: Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvdmozilla