cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 72 of 162
CVE-2020-15684P3CRITICALCVSS 9.8fixed in 82.0≥ unspecified, < 822020-10-22
CVE-2020-15684 [CRITICAL] CWE-416 CVE-2020-15684: Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evid Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.
nvdosv
CVE-2010-3777P3CRITICALCVSS 9.3v3.6v3.6.1+10 more2010-12-10
CVE-2010-3777 [CRITICAL] CWE-119 CVE-2010-3777: Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2005-2701P3HIGHCVSS 7.5≤ 1.0.6v1.0+5 more2005-09-23
CVE-2005-2701 [HIGH] CVE-2005-2701: Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote att Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.
nvd
CVE-2011-2981P3CRITICALCVSS 9.3≤ 3.6.19v1.0+105 more2011-08-18
CVE-2011-2981 [CRITICAL] CWE-16 CVE-2011-2981: The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
nvd
CVE-2023-4055P3HIGHCVSS 7.5fixed in 116.0≥ 102.0, < 102.14+2 more2023-08-01
CVE-2023-4055 [HIGH] CWE-120 CVE-2023-4055: When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2024-1546P3HIGHCVSS 7.5fixed in 115.8.0fixed in 123.0+1 more2024-02-20
CVE-2024-1546 [HIGH] CWE-125 CVE-2024-1546: When storing and re-accessing data on a networking channel, the length of buffers may have been conf When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2022-36319P3HIGHCVSS 7.5fixed in 103.0≥ unspecified, < 1032022-12-22
CVE-2022-36319 [HIGH] CWE-1021 CVE-2022-36319: When combining CSS properties for overflow and transform, the mouse cursor could interact with diffe When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
nvd
CVE-2023-4583P3HIGHCVSS 7.5fixed in 117.0≥ unspecified, < 1172023-09-11
CVE-2023-4583 [HIGH] CWE-754 CVE-2023-4583: When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2010-1988P3CRITICALCVSS 10.0v3.6.32010-05-20
CVE-2010-1988 [CRITICAL] CVE-2010-1988: Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (NULL p Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via JavaScript code that performs certain string concatenation and substring operations, a different vulnerability than CVE-2009-1571.
nvd
CVE-2022-45407P3HIGHCVSS 7.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45407 [HIGH] CWE-416 CVE-2022-45407: If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free If an attacker loaded a font using FontFace() on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107.
nvd
CVE-2024-10458P3HIGHCVSS 7.5fixed in 115.17fixed in 132.0+2 more2024-10-29
CVE-2024-10458 [HIGH] CWE-281 CVE-2024-10458: A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `objec A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvdosv
CVE-2023-25747P3HIGHCVSS 7.5fixed in 110.12023-06-19
CVE-2023-25747 [HIGH] CWE-416 CVE-2023-25747: A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on And A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 110.1.0.
nvd
CVE-2024-11702P3HIGHCVSS 7.5fixed in 133.0≥ unspecified, < 1332024-11-26
CVE-2024-11702 [HIGH] CWE-838 CVE-2024-11702: Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have ina Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.
nvd
CVE-2026-0889P3HIGHCVSS 7.5fixed in 147.02026-01-13
CVE-2026-0889 [HIGH] CWE-400 CVE-2026-0889: Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
nvd
CVE-2025-1931P3HIGHCVSS 7.5fixed in 115.21.0fixed in 136.0+1 more2025-03-04
CVE-2025-1931 [HIGH] CWE-416 CVE-2025-1931: It was possible to cause a use-after-free in the content process side of a WebTransport connection, It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
nvd
CVE-2024-5694P3HIGHCVSS 7.5fixed in 127.0≥ unspecified, < 1272024-06-11
CVE-2024-5694 [HIGH] CWE-416 CVE-2024-5694: An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaSc An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.
nvdosv
CVE-2026-8968P3HIGHCVSS 7.5fixed in 140.11.0fixed in 151.0.02026-05-19
CVE-2026-8968 [HIGH] CWE-400 CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerabilit Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
nvdmozilla
CVE-2022-31748P3CRITICALCVSS 9.8fixed in 101≥ unspecified, < 1012022-12-22
CVE-2022-31748 [CRITICAL] CWE-119 CVE-2022-31748: Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuz Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Fi
nvdosv
CVE-2022-36320P3CRITICALCVSS 9.8fixed in 103.0≥ unspecified, < 1032022-12-22
CVE-2022-36320 [CRITICAL] CWE-787 CVE-2022-36320: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103.
nvdosv
CVE-2026-16376P3HIGHCVSS 7.5fixed in 153.0.02026-07-21
CVE-2026-16376 [HIGH] CWE-400 CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
Mozilla Firefox vulnerabilities | cvebase