cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 81 of 162
CVE-2025-5270P3HIGHCVSS 7.5fixed in 139.02025-05-27
CVE-2025-5270 [HIGH] CWE-319 CVE-2025-5270: In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vul In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
nvd
CVE-2016-2836P3HIGHCVSS 8.8≤ 47.0.1v45.1.0+3 more2016-08-05
CVE-2016-2836 [HIGH] CWE-119 CVE-2016-2836: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to Http2Session::Shutdown and SpdySession31::Shutdown, and other vectors.
nvd
CVE-2016-2835P3HIGHCVSS 8.8≤ 47.0.12016-08-05
CVE-2016-2835 [HIGH] CVE-2016-2835: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvdosv
CVE-2016-1964P3HIGHCVSS 8.8≤ 44.0.2v38.0+12 more2016-03-13
CVE-2016-1964 [HIGH] CVE-2016-1964: Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Fir Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.
nvd
CVE-2024-9403P3HIGHCVSS 7.3fixed in 131.0≥ unspecified, < 1312024-10-01
CVE-2024-9403 [HIGH] CWE-119 CVE-2024-9403: Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption a Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.
nvdosv
CVE-2008-2799P3CRITICALCVSS 10.0≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2799 [CRITICAL] CWE-399 CVE-2008-2799: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and ea Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.
nvd
CVE-2019-9812P3CRITICALCVSS 9.3fixed in 60.9fixed in 69.0+2 more2020-01-08
CVE-2019-9812 [CRITICAL] CVE-2019-9812: Given a compromised sandboxed content process due to a separate vulnerability, it is possible to esc Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart withou
nvd
CVE-2022-22753P3HIGHCVSS 7.1fixed in 97.0≥ unspecified, < 972022-12-22
CVE-2022-22753 [HIGH] CWE-367 CVE-2022-22753: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6,
nvd
CVE-2009-3379P3CRITICALCVSS 10.0v3.5.1v3.5.2+1 more2009-10-29
CVE-2009-3379 [CRITICAL] CVE-2009-3379: Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, al Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overlap CVE-2009-2663.
nvd
CVE-2010-0175P3CRITICALCVSS 9.3≤ 3.0.17v0.1+91 more2010-04-05
CVE-2010-0175 [CRITICAL] CWE-399 CVE-2010-0175: Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select ev
nvd
CVE-2011-0075P3CRITICALCVSS 10.0v3.6v3.6.2+32 more2011-05-07
CVE-2011-0075 [CRITICAL] CVE-2011-0075: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2011-0072P3CRITICALCVSS 10.0v3.6v3.6.2+32 more2011-05-07
CVE-2011-0072 [CRITICAL] CVE-2011-0072: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2011-0077P3CRITICALCVSS 10.0v3.6v3.6.2+32 more2011-05-07
CVE-2011-0077 [CRITICAL] CVE-2011-0077: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2011-0074P3CRITICALCVSS 10.0v3.6v3.6.2+32 more2011-05-07
CVE-2011-0074 [CRITICAL] CVE-2011-0074: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2011-0078P3CRITICALCVSS 10.0v3.6v3.6.2+32 more2011-05-07
CVE-2011-0078 [CRITICAL] CVE-2011-0078: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x bef Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0
nvd
CVE-2026-16373P3UNKNOWNfixed in Firefox 153
CVE-2026-16373 Mozilla Foundation Security Advisory 2026-68: CVE-2026-16373 Mozilla Foundation Security Advisory 2026-68 CVE: CVE-2026-16373 Product: Firefox Impact: high Fixed in: Firefox 153
mozilla
CVE-2017-7774P3CRITICALCVSS 9.1fixed in 54.0vAll versions prior to Firefox 542019-04-15
CVE-2017-7774 [CRITICAL] CWE-125 CVE-2017-7774: Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite functi Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
nvd
CVE-2021-29951P3MEDIUMCVSS 6.5fixed in 87.0≥ unspecified, < 872021-06-24
CVE-2021-29951 [MEDIUM] CWE-269 CVE-2021-29951: The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain net The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Not
nvd
CVE-2011-0081P3CRITICALCVSS 10.0v3.6.1v3.6.2+14 more2011-05-07
CVE-2011-0081 [CRITICAL] CVE-2011-0081: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.17 and 4.x befor Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.17 and 4.x before 4.0.1, and Thunderbird 3.1.x before 3.1.10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-3381P3CRITICALCVSS 10.0v3.5.1v3.5.2+1 more2009-10-29
CVE-2009-3381 [CRITICAL] CVE-2009-3381: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 all Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd