cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 9 of 162
CVE-2026-16358P3CRITICALCVSS 9.8fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16358 [CRITICAL] CWE-346 CVE-2026-16358: Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1 Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2009-0253P4MEDIUMCVSS 6.8PoCv3.0.52009-01-22
CVE-2009-0253 [MEDIUM] CVE-2009-0253: Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.
nvd
CVE-2010-3171P4MEDIUMCVSS 5.8PoCv3.5.10v3.5.11+5 more2010-09-15
CVE-2010-3171 [MEDIUM] CWE-310 CVE-2010-3171: The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed
nvd
CVE-2013-6671P3CRITICALCVSS 9.8fixed in 26.0≥ 24.0, < 24.22013-12-11
CVE-2013-6671 [CRITICAL] CWE-94 CVE-2013-6671: The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24 The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.
nvd
CVE-2026-16359P3CRITICALCVSS 9.1fixed in 115.38.0fixed in 153.0.0+1 more2026-07-21
CVE-2026-16359 [CRITICAL] CWE-119 CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Fir Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
nvdmozilla
CVE-2026-12315P3CRITICALCVSS 9.1fixed in Firefox 152
CVE-2026-12315 [CRITICAL] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12315 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12315 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2026-12304P3CRITICALCVSS 9.1fixed in Firefox 152
CVE-2026-12304 [CRITICAL] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12304 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12304 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2007-5341P3CRITICALCVSS 9.8≤ 2.0.0.72017-08-18
CVE-2007-5341 [CRITICAL] CWE-119 CVE-2007-5341: Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8. Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
nvd
CVE-2015-4485P3CRITICALCVSS 10.0≤ 39.0.3v38.0+3 more2015-08-16
CVE-2015-4485 [CRITICAL] CWE-119 CVE-2015-4485: Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox befor Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data.
nvd
CVE-2019-9794P3CRITICALCVSS 9.8fixed in 60.6.0fixed in 66.0+1 more2019-04-26
CVE-2019-9794 [CRITICAL] CWE-88 CVE-2019-9794: A vulnerability was discovered where specific command line arguments are not properly discarded duri A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third part
nvd
CVE-2015-4477P3CRITICALCVSS 10.0≤ 39.0.32015-08-16
CVE-2015-4477 [CRITICAL] CVE-2015-4477: Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allo Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via unspecified use of the Web Audio API.
nvdosv
CVE-2026-2779P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2779 [CRITICAL] CWE-119 CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Fire Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2766P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2766 [CRITICAL] CWE-416 CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-2765P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2765 [CRITICAL] CWE-416 CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-8094P3CRITICALCVSS 9.8fixed in 140.10.22026-05-07
CVE-2026-8094 [CRITICAL] CWE-94 CVE-2026-8094: Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunde Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
nvd
CVE-2026-0884P3CRITICALCVSS 9.8fixed in 140.7.0fixed in 147.02026-01-13
CVE-2026-0884 [CRITICAL] CWE-416 CVE-2026-0884: Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Fire Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
nvd
CVE-2025-55031P3CRITICALCVSS 9.8fixed in 142.02025-08-19
CVE-2025-55031 [CRITICAL] CWE-601 CVE-2025-55031: Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passk Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability was fixed in Firefox for iOS 142 and Focus for iOS 142.
nvd
CVE-2026-2791P3CRITICALCVSS 9.8fixed in 140.8.0fixed in 148.02026-02-24
CVE-2026-2791 [CRITICAL] CWE-288 CVE-2026-2791: Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, F Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
nvd
CVE-2026-4711P3CRITICALCVSS 9.8fixed in 140.9.0fixed in 149.02026-03-24
CVE-2026-4711 [CRITICAL] CWE-416 CVE-2026-4711: Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
nvd
CVE-2026-5731P3CRITICALCVSS 9.8v115.34.0v140.9.0+1 more2026-04-07
CVE-2026-5731 [CRITICAL] CWE-119 CVE-2026-5731: Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fi Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firef
nvd
Mozilla Firefox vulnerabilities | cvebase