VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2024-11704
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.
Published 2024-11-26 · Modified
9.8EPSS 0.009
CVE-2023-4057
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.
Published 2023-08-01 · Modified
9.8EPSS 0.009
CVE-2022-31747
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Published 2022-12-22 · Modified
9.8EPSS 0.009
CVE-2023-5175
During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.
Published 2023-09-27 · Modified
9.8EPSS 0.008
CVE-2024-11693
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Published 2024-11-26 · Analyzed
9.8EPSS 0.008
CVE-2023-5172
A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.
Published 2023-09-27 · Modified
9.8EPSS 0.008
CVE-2022-31737
A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Published 2022-12-22 · Modified
9.8EPSS 0.008
CVE-2024-3863
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Published 2024-04-16 · Modified
9.8EPSS 0.008
CVE-2023-4058
Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116.
Published 2023-08-01 · Modified
9.8EPSS 0.008
CVE-2023-34417
Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.
Published 2023-06-19 · Modified
9.8EPSS 0.008
CVE-2023-32216
Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113.
Published 2023-06-19 · Modified
9.8EPSS 0.008
CVE-2024-5699
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.
Published 2024-06-11 · Analyzed
9.8EPSS 0.008
CVE-2026-4698
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-03-24 · Modified
9.8EPSS 0.008
CVE-2025-49710
Integer overflow in OrderedHashTable
Published 2025-06-11 · Modified
9.8EPSS 0.007
CVE-2024-9401
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
9.8EPSS 0.007
CVE-2024-8384
The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
Published 2024-09-03 · Modified
9.8EPSS 0.007
CVE-2026-74990
Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
Published 2026-08-18 · Modified
9.8EPSS 0.007
CVE-2026-74987
Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
Published 2026-08-18 · Modified
9.8EPSS 0.007
CVE-2022-34476
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.
Published 2022-12-22 · Modified
9.8EPSS 0.007
CVE-2026-2774
Integer overflow in the Audio/Video component
Published 2026-02-24 · Modified
9.8EPSS 0.007
CVE-2026-2762
Integer overflow in the JavaScript: Standard Library component
Published 2026-02-24 · Modified
9.8EPSS 0.007
CVE-2024-11698
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted. *This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Published 2024-11-26 · Analyzed
9.8EPSS 0.007
CVE-2023-25736
An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.
Published 2023-06-19 · Modified
9.8EPSS 0.007
CVE-2026-74964
Integer overflow in the Graphics component
Published 2026-08-18 · Analyzed
9.8EPSS 0.007
CVE-2026-4702
JIT miscompilation in the JavaScript Engine component
Published 2026-03-24 · Modified
9.8EPSS 0.007
CVE-2025-49709
Memory corruption in canvas surfaces
Published 2025-06-11 · Modified
9.8EPSS 0.007
CVE-2024-6611
Incorrect handling of SameSite cookies
Published 2024-07-09 · Analyzed
9.8EPSS 0.007
CVE-2022-36320
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103.
Published 2022-12-22 · Modified
9.8EPSS 0.007
CVE-2022-31748
Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 101.
Published 2022-12-22 · Modified
9.8EPSS 0.007
CVE-2026-2796
JIT miscompilation in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
9.8EPSS 0.007
CVE-2026-8956
Integer overflow in the Networking: JAR component
Published 2026-05-19 · Analyzed
9.8EPSS 0.006
CVE-2025-1011
A bug in WebAssembly code generation could result in a crash
Published 2025-02-04 · Modified
9.8EPSS 0.006
CVE-2026-4705
Undefined behavior in the WebRTC: Signaling component
Published 2026-03-24 · Modified
9.8EPSS 0.006
CVE-2026-84141
Integer overflow in the Graphics: ImageLib component
Published 2026-09-01 · Modified
9.8EPSS 0.006
CVE-2026-8094
Other issue in the WebRTC component
Published 2026-05-07 · Modified
9.8EPSS 0.006
CVE-2026-2793
Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2792
Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2024-7521
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.8EPSS 0.006
CVE-2024-9402
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Analyzed
9.8EPSS 0.006
CVE-2026-2773
Incorrect boundary conditions in the Web Audio component
Published 2026-02-24 · Modified
9.8EPSS 0.006
← Prev11 / 73Next →