VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2026-2759
Incorrect boundary conditions in the Graphics: ImageLib component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2773
Incorrect boundary conditions in the Web Audio component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2771
Undefined behavior in the DOM: Core & HTML component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-0879
Sandbox escape due to incorrect boundary conditions in the Graphics component
Published 2026-01-13 · Modified
9.8EPSS 0.006
CVE-2026-74988
Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-2788
Incorrect boundary conditions in the Audio/Video: GMP component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-74943
Use-after-free in the Graphics: ImageLib component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-74940
Use-after-free in the Graphics: Text component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-2772
Use-after-free in the Audio/Video: Playback component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2763
Use-after-free in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2766
Use-after-free in the JavaScript Engine: JIT component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2765
Use-after-free in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2758
Use-after-free in the JavaScript: GC component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2764
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2770
Use-after-free in the DOM: Bindings (WebIDL) component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2767
Use-after-free in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-8401
Sandbox escape in the Profile Backup component
Published 2026-05-12 · Modified
9.8EPSS 0.006
CVE-2026-6748
Uninitialized memory in the Audio/Video: Web Codecs component
Published 2026-04-21 · Modified
9.8EPSS 0.006
CVE-2024-10467
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
9.8EPSS 0.006
CVE-2025-14321
Use-after-free in the WebRTC: Signaling component
Published 2025-12-09 · Modified
9.8EPSS 0.006
CVE-2026-8091
Incorrect boundary conditions in the Audio/Video: Playback component
Published 2026-05-07 · Modified
9.8EPSS 0.006
CVE-2024-2615
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.
Published 2024-03-19 · Modified
9.8EPSS 0.006
CVE-2025-1016
Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7
Published 2025-02-04 · Modified
9.8EPSS 0.006
CVE-2026-74944
Use-after-free in the DOM: Core & HTML component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-74936
Use-after-free in the JavaScript: WebAssembly component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-5734
Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
Published 2026-04-07 · Modified
9.8EPSS 0.006
CVE-2026-2779
Incorrect boundary conditions in the Networking: JAR component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2022-1887
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
Published 2022-12-22 · Modified
9.8EPSS 0.006
CVE-2025-1017
Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7
Published 2025-02-04 · Modified
9.8EPSS 0.006
CVE-2024-5695
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
Published 2024-06-11 · Modified
9.8EPSS 0.006
CVE-2024-5701
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.
Published 2024-06-11 · Analyzed
9.8EPSS 0.006
CVE-2026-2800
Spoofing issue in the WebAuthn component in Firefox for Android
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2024-8385
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
Published 2024-09-03 · Modified
9.8EPSS 0.006
CVE-2026-2805
Invalid pointer in the DOM: Core & HTML component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2024-4764
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Analyzed
9.8EPSS 0.006
CVE-2026-84134
Other issue in the Profile Backup component
Published 2026-09-01 · Analyzed
9.8EPSS 0.006
CVE-2026-74989
Internally found bugs fixed in Thunderbird 154
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-2777
Privilege escalation in the Messaging System component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2025-9179
Sandbox escape due to invalid pointer in the Audio/Video: GMP component
Published 2025-08-19 · Modified
9.8EPSS 0.006
CVE-2026-2775
Mitigation bypass in the DOM: HTML Parser component
Published 2026-02-24 · Modified
9.8EPSS 0.006
← Prev12 / 73Next →