VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2026-5735
Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2
Published 2026-04-07 · Modified
9.8EPSS 0.005
CVE-2026-4701
Use-after-free in the JavaScript Engine component
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2026-4700
Mitigation bypass in the Networking: HTTP component
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2026-0892
Memory safety bugs fixed in Firefox 147 and Thunderbird 147
Published 2026-01-13 · Modified
9.8EPSS 0.005
CVE-2026-2786
Use-after-free in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-1012
Use-after-free during concurrent delazification
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2025-9187
Memory safety bugs fixed in Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
9.8EPSS 0.005
CVE-2025-8044
Memory safety bugs fixed in Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
9.8EPSS 0.004
CVE-2024-4778
Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Analyzed
9.8EPSS 0.004
CVE-2026-2782
Privilege escalation in the Netmonitor component
Published 2026-02-24 · Modified
9.8EPSS 0.004
CVE-2026-16369
Integer overflow in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16363
JIT miscompilation in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16408
Integer overflow in the Audio/Video: Playback component
Published 2026-07-21 · Modified
9.8EPSS 0.004
CVE-2026-2780
Privilege escalation in the Netmonitor component
Published 2026-02-24 · Modified
9.8EPSS 0.004
CVE-2026-4721
Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2026-4720
Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2025-11710
Cross-process information leaked due to malicious IPC messages
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2025-11709
Out of bounds read/write in a privileged process triggered by WebGL textures
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2026-4717
Privilege escalation in the Netmonitor component
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2025-55031
Passkey phishing within Bluetooth range
Published 2025-08-19 · Modified
9.8EPSS 0.004
CVE-2026-4710
Incorrect boundary conditions in the Audio/Video component
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2026-16350
Incorrect boundary conditions in the Audio/Video: cubeb component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16357
Incorrect boundary conditions in the Graphics component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16355
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-4711
Use-after-free in the Widget: Cocoa component
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2026-16356
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16351
Sandbox escape due to use-after-free in the DOM: Navigation component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16352
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2024-10468
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.
Published 2024-10-29 · Analyzed
9.8EPSS 0.004
CVE-2026-16368
Incorrect boundary conditions in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16383
Mitigation bypass in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16377
Mitigation bypass in the PDF Viewer component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2024-1554
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.
Published 2024-02-20 · Analyzed
9.8EPSS 0.004
CVE-2024-7530
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
Published 2024-08-06 · Analyzed
9.8EPSS 0.004
CVE-2025-8043
Incorrect URL truncation
Published 2025-07-22 · Modified
9.8EPSS 0.004
CVE-2026-84136
Other issue in the DOM: Navigation component
Published 2026-09-01 · Modified
9.8EPSS 0.004
CVE-2026-84143
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
Published 2026-09-01 · Modified
9.8EPSS 0.004
CVE-2026-16382
Mitigation bypass in the DOM: Service Workers component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16388
Sandbox escape in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2025-11721
Memory safety bug fixed in Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
9.8EPSS 0.004
← Prev14 / 73Next →