Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 7 of 162
CVE-2025-0247P3CRITICALCVSS 9.8fixed in 134.02025-01-07
CVE-2025-0247 [CRITICAL] CWE-787 CVE-2025-0247: Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134 and Thunderbird 134.
nvdosv
CVE-2025-6424P3CRITICALCVSS 9.8fixed in 115.25.0fixed in 140.0+1 more2025-06-24
CVE-2025-6424 [CRITICAL] CWE-416 CVE-2025-6424: A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
nvd
CVE-2019-9804P3CRITICALCVSS 9.8fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9804 [CRITICAL] CWE-78 CVE-2019-9804: In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into
In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously crafted. This is the result of an issue with the native version of Bash on macOS. *Note: This issue only affects macOS. Other op
nvd
CVE-2016-0718P3CRITICALCVSS 9.8fixed in 48.02016-05-26
CVE-2016-0718 [CRITICAL] CWE-119 CVE-2016-0718: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute ar
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
nvdosv
CVE-2026-2778P3CRITICALCVSS 10.0fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2778 [CRITICAL] CWE-119 CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerab
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2023-29542P3CRITICALCVSS 9.8fixed in 112.0≥ unspecified, < 1122023-06-19
CVE-2023-29542 [CRITICAL] CVE-2023-29542: A newline in a filename could have been used to bypass the file extension security mechanisms that r
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerab
nvd
CVE-2026-16363P3CRITICALCVSS 9.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16363 [CRITICAL] CWE-682 CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-2784P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2784 [CRITICAL] CWE-288 CVE-2026-2784: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firef
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-16355P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16355 [CRITICAL] CWE-843 CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16350P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16350 [CRITICAL] CWE-119 CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in F
Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16357P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16357 [CRITICAL] CWE-119 CVE-2026-16357: Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16368P3CRITICALCVSS 9.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16368 [CRITICAL] CWE-119 CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-6771P3CRITICALCVSS 9.8fixed in 150.0≥ 140.0, < 140.10.02026-04-21
CVE-2026-6771 [CRITICAL] CWE-288 CVE-2026-6771: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firef
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-16387P3CRITICALCVSS 9.8fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16387 [CRITICAL] CWE-200 CVE-2026-16387: Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firef
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2013-6167P4MEDIUMCVSS 6.8PoC≤ 27.02014-02-15
CVE-2013-6167 [MEDIUM] CWE-352 CVE-2013-6167: Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the req
Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.
nvd
CVE-2026-16390P3CRITICALCVSS 9.1fixed in 140.13.0fixed in 153.0.02026-07-21
CVE-2026-16390 [CRITICAL] CWE-693 CVE-2026-16390: Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153,
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16394P3CRITICALCVSS 9.1fixed in 153.0.02026-07-21
CVE-2026-16394 [CRITICAL] CWE-693 CVE-2026-16394: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Th
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2025-4919P3HIGHCVSS 8.8fixed in 115.23.1fixed in 138.0.4+1 more2025-05-17
CVE-2025-4919 [HIGH] CWE-125 CVE-2025-4919: An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing a
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.
nvd
CVE-2015-4479P3CRITICALCVSS 10.0≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4479 [CRITICAL] CWE-189 CVE-2015-4479: Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x bef
Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video data.
nvdosv
CVE-2010-3769P3CRITICALCVSS 9.3≤ 3.5.15v0.1+113 more2010-12-10
CVE-2010-3769 [CRITICAL] CWE-119 CVE-2010-3769: The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbi
The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.
nvd