Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 94 of 162
CVE-2025-4086P4MEDIUMCVSS 6.5fixed in 138.02025-04-29
CVE-2025-4086 [MEDIUM] CWE-451 CVE-2025-4086: A specially crafted filename containing a large number of encoded newline characters could obscure t
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.
*This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvd
CVE-2011-3661P4HIGHCVSS 7.5v4.0v4.0.1+8 more2011-12-21
CVE-2011-3661 [HIGH] CWE-399 CVE-2011-3661: YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before
YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.
nvd
CVE-2026-12302P3MEDIUMCVSS 6.5fixed in Firefox 152
CVE-2026-12302 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12302
Mozilla Foundation Security Advisory 2026-57
CVE: CVE-2026-12302
Product: Firefox
Impact: high
Fixed in: Firefox 152
mozilla
CVE-2025-14331P4MEDIUMCVSS 6.5fixed in 115.31.0fixed in 146.0+1 more2025-12-09
CVE-2025-14331 [MEDIUM] CWE-346 CVE-2025-14331: Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox
Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
nvd
CVE-2006-1733P3MEDIUMCVSS 6.8≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1733 [MEDIUM] CWE-264 CVE-2006-1733: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13,
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inse
nvd
CVE-2015-7198P4HIGHCVSS 7.5v38.0v38.0.1+7 more2015-11-05
CVE-2015-7198 [HIGH] CWE-119 CVE-2015-7198: Buffer overflow in the rx::TextureStorage11 class in ANGLE, as used in Mozilla Firefox before 42.0 a
Buffer overflow in the rx::TextureStorage11 class in ANGLE, as used in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted texture data.
nvdosv
CVE-2015-2738P4CRITICALCVSS 10.0≤ 38.1.0v31.0+7 more2015-07-06
CVE-2015-2738 [CRITICAL] CWE-17 CVE-2015-2738: The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla
The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvdosv
CVE-2015-2734P4CRITICALCVSS 10.0v31.0v31.1.0+7 more2015-07-06
CVE-2015-2734 [CRITICAL] CWE-17 CVE-2015-2734: The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Fi
The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvdosv
CVE-2017-5449P4HIGHCVSS 7.5fixed in 52.1.0fixed in 53.0+1 more2018-06-11
CVE-2017-5449 [HIGH] CWE-20 CVE-2017-5449: A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2015-7222P4MEDIUMCVSS 6.8v38.0v38.0.1+8 more2015-12-16
CVE-2015-7222 [MEDIUM] CWE-189 CVE-2015-7222: Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Fir
Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application crash) via an MP4 video file with crafted covr metadata that triggers a buffer
nvdosv
CVE-2009-3979P4CRITICALCVSS 9.3≤ 3.0.15v0.1+97 more2009-12-17
CVE-2009-3979 [CRITICAL] CVE-2009-3979: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-3982P4CRITICALCVSS 9.3v3.5.1v3.5.2+3 more2009-12-17
CVE-2009-3982 [CRITICAL] CVE-2009-3982: Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6,
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2017-5467P4HIGHCVSS 7.5fixed in 53.0≥ unspecified, < 532018-06-11
CVE-2017-5467 [HIGH] CWE-119 CVE-2017-5467: A potential memory corruption and crash when using Skia content when drawing content outside of the
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvdosv
CVE-2005-1156P3HIGHCVSS 7.5v0.8v0.9+8 more2005-05-02
CVE-2005-1156 [HIGH] CVE-2005-1156: Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execut
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."
nvd
CVE-2009-3980P4CRITICALCVSS 9.3v3.5.1v3.5.2+3 more2009-12-17
CVE-2009-3980 [CRITICAL] CWE-399 CVE-2009-3980: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, Se
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2017-7755P4HIGHCVSS 7.8fixed in 52.2.0fixed in 54.0+1 more2018-06-11
CVE-2017-7755 [HIGH] CWE-426 CVE-2017-7755: The Firefox installer on Windows can be made to load malicious DLL files stored in the same director
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged execution if the installer is run with elevated privileges. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54
nvd
CVE-2015-2717P4MEDIUMCVSS 6.8≤ 37.0.22015-05-14
CVE-2015-2717 [MEDIUM] CWE-189 CVE-2015-2717: Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute
Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and out-of-bounds read) via an MP4 video file containing invalid metadata.
nvdosv
CVE-2010-4508P4CRITICALCVSS 10.0v4.02010-12-09
CVE-2010-4508 [CRITICAL] CVE-2010-4508: The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform prox
The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impact and remote attack vectors, related to an "inherent problem" with the WebSocket specification.
nvd
CVE-2016-1942P4HIGHCVSS 7.4≤ 43.0.42016-01-31
CVE-2016-1942 [HIGH] CWE-20 CVE-2016-1942: Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in t
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
nvdosv
CVE-2008-2803P3MEDIUMCVSS 6.8≤ 2.0.0.14v2.0+13 more2008-07-07
CVE-2008-2803 [MEDIUM] CWE-264 CVE-2008-2803: The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.
The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving
nvd