cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 80 of 162
CVE-2023-5728P3HIGHCVSS 7.5fixed in 119.0≥ unspecified, < 1192023-10-25
CVE-2023-5728 [HIGH] CWE-416 CVE-2023-5728: During garbage collection extra operations were performed on a object that should not be. This could During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-37203P3HIGHCVSS 7.8fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-37203 [HIGH] CVE-2023-37203: Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have al Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have allowed an attacker to trick end-users into creating a shortcut to local system files. This could have been leveraged to execute arbitrary code. This vulnerability affects Firefox < 115.
nvdosv
CVE-2026-6776P3HIGHCVSS 7.8fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6776 [HIGH] CWE-119 CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in F Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2022-22737P3HIGHCVSS 7.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22737 [HIGH] CWE-362 CVE-2022-22737: Constructing audio sinks could have lead to a race condition when playing audio files and closing wi Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2016-2794P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-2794 [HIGH] CWE-119 CVE-2016-2794: The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
nvd
CVE-2025-3033P3HIGHCVSS 7.7fixed in 137.02025-04-01
CVE-2025-3033 [HIGH] CWE-73 CVE-2025-3033: After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file co After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
nvd
CVE-2019-9798P3HIGHCVSS 7.4fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9798 [HIGH] CWE-426 CVE-2019-9798: On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vu
nvd
CVE-2024-7652P3HIGHCVSS 7.5fixed in 115.13.0fixed in 128.0+1 more2024-09-06
CVE-2024-7652 [HIGH] CWE-476 CVE-2024-7652: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type co An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2016-2834P3HIGHCVSS 8.8≤ 46.0.12016-06-13
CVE-2016-2834 [HIGH] CVE-2016-2834: Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2024-0744P3HIGHCVSS 7.5fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0744 [HIGH] CWE-119 CVE-2024-0744: In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could ha In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox < 122.
nvdosv
CVE-2024-3858P3HIGHCVSS 7.5fixed in 125.0≥ unspecified, < 1252024-04-16
CVE-2024-3858 [HIGH] CWE-476 CVE-2024-3858: It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vul It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.
nvdosv
CVE-2023-29537P3HIGHCVSS 7.5fixed in 112.0≥ unspecified, < 1122023-06-02
CVE-2023-29537 [HIGH] CWE-362 CVE-2023-29537: Multiple race conditions in the font initialization could have led to memory corruption and executio Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvdosv
CVE-2024-4773P3HIGHCVSS 7.5fixed in 126.0≥ unspecified, < 1262024-05-14
CVE-2024-4773 [HIGH] CWE-601 CVE-2024-4773: When a network error occurred during page load, the prior content could have remained in view with a When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.
nvdosv
CVE-2024-2613P3HIGHCVSS 7.5fixed in 124.0≥ unspecified, < 1242024-03-19
CVE-2024-2613 [HIGH] CWE-1021 CVE-2024-2613: Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.
nvdosv
CVE-2024-9399P3HIGHCVSS 7.5fixed in 128.3.0≥ 129.0, < 131.0+1 more2024-10-01
CVE-2024-9399 [HIGH] CWE-404 CVE-2024-9399: A website configured to initiate a specially crafted WebTransport session could crash the Firefox pr A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2026-8945P3HIGHCVSS 7.5fixed in 151.0.02026-05-19
CVE-2026-8945 [HIGH] CWE-693 CVE-2026-8945: Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151 Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
nvdmozilla
CVE-2011-3647P3CRITICALCVSS 9.3≤ 3.6.23v0.1+123 more2011-11-09
CVE-2011-3647 [CRITICAL] CVE-2011-3647: The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properl The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.
nvd
CVE-2019-9803P3HIGHCVSS 7.4fixed in 66.0≥ unspecified, < 662019-04-26
CVE-2019-9803 [HIGH] CWE-346 CVE-2019-9803: The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Secu The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle at
nvdosv
CVE-2026-2801P3HIGHCVSS 7.5fixed in 148.02026-02-24
CVE-2026-2801 [HIGH] CWE-754 CVE-2026-2801: Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
nvd
CVE-2026-12317P3HIGHCVSS 7.5fixed in Firefox 152
CVE-2026-12317 [HIGH] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12317 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12317 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
Mozilla Firefox vulnerabilities | cvebase