cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 8 of 162
CVE-2018-12386P3HIGHCVSS 8.1fixed in 60.2.2fixed in 62.0.3+1 more2018-10-18
CVE-2018-12386 [HIGH] CWE-704 CVE-2018-12386: A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arb A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.
nvd
CVE-2016-6354P3CRITICALCVSS 9.8≥ unspecified, < 532016-09-21
CVE-2016-6354 [CRITICAL] CWE-119 CVE-2016-6354: Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow conte Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
nvd
CVE-2021-4140P3CRITICALCVSS 10.0fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2021-4140 [CRITICAL] CWE-91 CVE-2021-4140: It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. Th It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2014-1488P3CRITICALCVSS 10.0fixed in 27.02014-02-06
CVE-2014-1488 [CRITICAL] CVE-2014-1488: The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remot The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.
nvd
CVE-2012-4188P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4188 [CRITICAL] CWE-119 CVE-2012-4188: Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 1 Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-4186P3CRITICALCVSS 9.3fixed in 10.0.8fixed in 16.02012-10-10
CVE-2012-4186 [CRITICAL] CWE-119 CVE-2012-4186: Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 1 Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2026-4689P3CRITICALCVSS 10.0fixed in 115.34.0fixed in 149.0+1 more2026-03-24
CVE-2026-4689 [CRITICAL] CWE-190 CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This v Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4725P3CRITICALCVSS 10.0fixed in 149.02026-03-24
CVE-2026-4725 [CRITICAL] CWE-416 CVE-2026-4725: Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fix Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
nvd
CVE-2020-6811P3HIGHCVSS 8.8fixed in 74.0≥ unspecified, < 74+1 more2020-03-25
CVE-2020-6811 [HIGH] CWE-77 CVE-2020-6811: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a req The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Fire
nvd
CVE-2025-14321P3CRITICALCVSS 9.8fixed in 140.6.0fixed in 146.02025-12-09
CVE-2025-14321 [CRITICAL] CWE-416 CVE-2025-14321: Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Fire Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvd
CVE-2026-4701P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4701 [CRITICAL] CWE-416 CVE-2026-4701: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4700P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4700 [CRITICAL] CWE-288 CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Fi Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-4717P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4717 [CRITICAL] CVE-2026-4717: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firef Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-16353P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16353 [CRITICAL] CWE-416 CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153 Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-16382P3CRITICALCVSS 9.8fixed in 153.0.02026-07-21
CVE-2026-16382 [CRITICAL] CWE-693 CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-16388P3CRITICALCVSS 9.8fixed in 153.0.02026-07-21
CVE-2026-16388 [CRITICAL] CWE-693 CVE-2026-16388: Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thu Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
nvdmozilla
CVE-2026-2780P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2780 [CRITICAL] CWE-269 CVE-2026-2780: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firef Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2789P3CRITICALCVSS 9.8fixed in 115.33.0fixed in 148.0+1 more2026-02-24
CVE-2026-2789 [CRITICAL] CWE-416 CVE-2026-2789: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Fir Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2786P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2786 [CRITICAL] CWE-416 CVE-2026-2786: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2782P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2782 [CRITICAL] CWE-269 CVE-2026-2782: Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firef Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
Mozilla Firefox vulnerabilities | cvebase