VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2025-14321
Use-after-free in the WebRTC: Signaling component
Published 2025-12-09 · Modified
9.8EPSS 0.006
CVE-2024-10467
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
9.8EPSS 0.006
CVE-2026-6748
Uninitialized memory in the Audio/Video: Web Codecs component
Published 2026-04-21 · Modified
9.8EPSS 0.006
CVE-2026-8401
Sandbox escape in the Profile Backup component
Published 2026-05-12 · Modified
9.8EPSS 0.006
CVE-2026-8091
Incorrect boundary conditions in the Audio/Video: Playback component
Published 2026-05-07 · Modified
9.8EPSS 0.006
CVE-2024-2615
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.
Published 2024-03-19 · Modified
9.8EPSS 0.006
CVE-2026-74944
Use-after-free in the DOM: Core & HTML component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-74936
Use-after-free in the JavaScript: WebAssembly component
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2025-1016
Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7
Published 2025-02-04 · Modified
9.8EPSS 0.006
CVE-2026-5734
Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
Published 2026-04-07 · Modified
9.8EPSS 0.006
CVE-2024-8387
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
Published 2024-09-03 · Modified
9.8EPSS 0.006
CVE-2026-2779
Incorrect boundary conditions in the Networking: JAR component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2022-1887
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
Published 2022-12-22 · Modified
9.8EPSS 0.006
CVE-2025-1017
Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7
Published 2025-02-04 · Modified
9.8EPSS 0.006
CVE-2024-5695
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
Published 2024-06-11 · Modified
9.8EPSS 0.006
CVE-2024-5701
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.
Published 2024-06-11 · Analyzed
9.8EPSS 0.006
CVE-2026-2800
Spoofing issue in the WebAuthn component in Firefox for Android
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2024-8385
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
Published 2024-09-03 · Modified
9.8EPSS 0.006
CVE-2026-2805
Invalid pointer in the DOM: Core & HTML component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2024-4764
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Analyzed
9.8EPSS 0.006
CVE-2026-74989
Internally found bugs fixed in Thunderbird 154
Published 2026-08-18 · Modified
9.8EPSS 0.006
CVE-2026-84134
Other issue in the Profile Backup component
Published 2026-09-01 · Analyzed
9.8EPSS 0.006
CVE-2025-9179
Sandbox escape due to invalid pointer in the Audio/Video: GMP component
Published 2025-08-19 · Modified
9.8EPSS 0.006
CVE-2026-2777
Privilege escalation in the Messaging System component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2026-2775
Mitigation bypass in the DOM: HTML Parser component
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2025-14324
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-12-09 · Modified
9.8EPSS 0.006
CVE-2026-16389
Incorrect boundary conditions, integer overflow in the Libraries component in NSS
Published 2026-07-21 · Modified
9.8EPSS 0.006
CVE-2026-84142
Internally found bugs fixed in Firefox 155
Published 2026-09-01 · Modified
9.8EPSS 0.006
CVE-2026-2781
Integer overflow in the Libraries component in NSS
Published 2026-02-24 · Modified
9.8EPSS 0.006
CVE-2025-1020
Memory safety bugs fixed in Firefox 135 and Thunderbird 135
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2026-2784
Mitigation bypass in the DOM: Security component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2791
Mitigation bypass in the Networking: Cache component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-4723
Use-after-free in the JavaScript Engine component
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2024-9392
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
9.8EPSS 0.005
CVE-2026-74985
Privilege escalation in the Enterprise Policies component
Published 2026-08-18 · Analyzed
9.8EPSS 0.005
CVE-2026-74979
Mitigation bypass in the Add-ons Manager component
Published 2026-08-18 · Analyzed
9.8EPSS 0.005
CVE-2026-6771
Mitigation bypass in the DOM: Security component
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2026-16412
Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
Published 2026-07-21 · Modified
9.8EPSS 0.005
CVE-2026-16353
Invalid pointer in the DOM: Bindings (WebIDL) component
Published 2026-07-21 · Analyzed
9.8EPSS 0.005
CVE-2024-7528
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
Published 2024-08-06 · Analyzed
9.8EPSS 0.005
← Prev14 / 84Next →