cbcvebase.

Mozilla Firefox vulnerabilities

3,233 known vulnerabilities affecting mozilla/firefox.

Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3

Vulnerabilities

Page 96 of 162
CVE-2025-4092P4MEDIUMCVSS 6.5fixed in 138.02025-04-29
CVE-2025-4092 [MEDIUM] CWE-119 CVE-2025-4092: Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
nvd
CVE-2025-3031P4MEDIUMCVSS 6.5fixed in 137.02025-04-01
CVE-2025-3031 [MEDIUM] CWE-200 CVE-2025-3031: An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vul An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
nvd
CVE-2024-9391P4MEDIUMCVSS 6.5fixed in 131.0≥ unspecified, < 1312024-10-01
CVE-2024-9391 [MEDIUM] CWE-290 CVE-2024-9391: A user who enables full-screen mode on a specially crafted web page could potentially be prevented f A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
nvd
CVE-2025-10529P4MEDIUMCVSS 6.5fixed in 140.3.0fixed in 143.02025-09-16
CVE-2025-10529 [MEDIUM] CWE-942 CVE-2025-10529: Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Fire Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
nvd
CVE-2026-12309P4MEDIUMCVSS 6.5fixed in Firefox 152
CVE-2026-12309 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12309 Mozilla Foundation Security Advisory 2026-57 CVE: CVE-2026-12309 Product: Firefox Impact: high Fixed in: Firefox 152
mozilla
CVE-2026-6764P4MEDIUMCVSS 6.5fixed in 140.10.0fixed in 150.02026-04-21
CVE-2026-6764 [MEDIUM] CWE-119 CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
nvdmozilla
CVE-2026-8971P4MEDIUMCVSS 6.5fixed in 151.0.02026-05-19
CVE-2026-8971 [MEDIUM] CWE-346 CVE-2026-8971: Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
nvdmozilla
CVE-2026-8706P4MEDIUMCVSS 6.5fixed in 151.02026-05-19
CVE-2026-8706 [MEDIUM] CWE-200 CVE-2026-8706: Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another applicat Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.
nvd
CVE-2015-0797P4MEDIUMCVSS 6.8fixed in 38.0≥ 31.0, < 31.72015-05-14
CVE-2015-0797 [MEDIUM] CVE-2015-0797: GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Th GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
nvd
CVE-2026-6755P4MEDIUMCVSS 6.5fixed in 150.02026-04-21
CVE-2026-6755 [MEDIUM] CWE-352 CVE-2026-6755: Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
nvdmozilla
CVE-2024-8897P4MEDIUMCVSS 6.1fixed in 130.0.12024-09-17
CVE-2024-8897 [MEDIUM] CWE-601 CVE-2024-8897: Under certain conditions, an attacker with the ability to redirect users to a malicious site via an Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* T
nvd
CVE-2012-0461P4HIGHCVSS 7.5≤ 3.6.27≥ 4.0, ≤ 10.0+3 more2012-03-14
CVE-2012-0461 [HIGH] CVE-2012-0461: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.28 and 4.x Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe
nvd
CVE-2015-7188P4HIGHCVSS 7.5≤ 41.0.2v38.0+7 more2015-11-05
CVE-2015-7188 [HIGH] CWE-254 CVE-2015-7188: Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Sa Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string.
nvdosv
CVE-2010-1122P4CRITICALCVSS 10.0v3.5v3.5.1+4 more2010-03-25
CVE-2010-1122 [CRITICAL] CVE-2010-1122: Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a different vulnerability than CVE-2010-1028.
nvd
CVE-2015-2739P4CRITICALCVSS 10.0≤ 38.1.0v31.0+7 more2015-07-06
CVE-2015-2739 [CRITICAL] CWE-119 CVE-2015-2739: The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
nvdosv
CVE-2008-3198P4HIGHCVSS 7.5v3.02008-07-17
CVE-2008-3198 [HIGH] CVE-2008-3198: Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrom Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.
nvd
CVE-2015-2737P4CRITICALCVSS 10.0v31.0v31.1.0+7 more2015-07-06
CVE-2015-2737 [CRITICAL] CWE-17 CVE-2015-2737: The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39 The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvdosv
CVE-2006-5463P4HIGHCVSS 7.5v1.5v1.5.0.1+6 more2006-11-08
CVE-2006-5463 [HIGH] CVE-2006-5463: Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonk Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing.
nvd
CVE-2008-5504P4HIGHCVSS 7.5≤ 2.0.0.18v2.0+17 more2008-12-17
CVE-2008-5504 [HIGH] CVE-2008-5504: Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.
nvd
CVE-2015-0831P4MEDIUMCVSS 6.8≤ 35.0.1v0.1+214 more2015-02-25
CVE-2015-0831 [MEDIUM] CVE-2015-0831: Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index
nvdosv
Mozilla Firefox vulnerabilities | cvebase