VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2026-6768
Mitigation bypass in the Networking: Cookies component
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2026-6760
Mitigation bypass in the Networking: Cookies component
Published 2026-04-21 · Analyzed
9.8EPSS 0.005
CVE-2025-11708
Use-after-free in MediaTrackGraphImpl::GetInstance()
Published 2025-10-14 · Modified
9.8EPSS 0.005
CVE-2025-8028
Large branch table could lead to truncated instruction
Published 2025-07-22 · Modified
9.8EPSS 0.005
CVE-2025-14330
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-12-09 · Modified
9.8EPSS 0.005
CVE-2026-16411
Memory safety bugs fixed in Firefox 153
Published 2026-07-21 · Modified
9.8EPSS 0.005
CVE-2024-8389
Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130.
Published 2024-09-03 · Analyzed
9.8EPSS 0.005
CVE-2026-4691
Use-after-free in the CSS Parsing and Computation component
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2026-4696
Use-after-free in the Layout: Text and Fonts component
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2026-2807
Memory safety bugs fixed in Firefox 148 and Thunderbird 148
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-54143
Sandboxed iframes could allow local downloads despite sandbox restrictions
Published 2025-08-19 · Modified
9.8EPSS 0.005
CVE-2025-8042
Sandboxed iframe could start downloads
Published 2025-08-19 · Modified
9.8EPSS 0.005
CVE-2026-2787
Use-after-free in the DOM: Window and Location component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2789
Use-after-free in the Graphics: ImageLib component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-0884
Use-after-free in the JavaScript Engine component
Published 2026-01-13 · Modified
9.8EPSS 0.005
CVE-2026-2795
Use-after-free in the JavaScript: GC component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2797
Use-after-free in the JavaScript: GC component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2799
Use-after-free in the DOM: Core & HTML component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-1942
Disclosure of uninitialized memory when .toUpperCase() causes string to get longer
Published 2025-03-04 · Modified
9.8EPSS 0.005
CVE-2026-16360
Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
Published 2026-07-21 · Analyzed
9.8EPSS 0.005
CVE-2026-2634
Spoofed web content presented under trusted domains using scripted navigation on Firefox iOS
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2026-2785
Invalid pointer in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-8031
Incorrect URL stripping in CSP reports
Published 2025-07-22 · Modified
9.8EPSS 0.005
CVE-2025-1010
Use-after-free in Custom Highlight
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2026-4729
Memory safety bugs fixed in Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2025-14326
Use-after-free in the Audio/Video: GMP component
Published 2025-12-09 · Modified
9.8EPSS 0.005
CVE-2026-4701
Use-after-free in the JavaScript Engine component
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2026-5735
Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2
Published 2026-04-07 · Modified
9.8EPSS 0.005
CVE-2026-0892
Memory safety bugs fixed in Firefox 147 and Thunderbird 147
Published 2026-01-13 · Modified
9.8EPSS 0.005
CVE-2026-4700
Mitigation bypass in the Networking: HTTP component
Published 2026-03-24 · Modified
9.8EPSS 0.005
CVE-2026-2786
Use-after-free in the JavaScript Engine component
Published 2026-02-24 · Modified
9.8EPSS 0.005
CVE-2025-1012
Use-after-free during concurrent delazification
Published 2025-02-04 · Modified
9.8EPSS 0.005
CVE-2025-9187
Memory safety bugs fixed in Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
9.8EPSS 0.005
CVE-2025-8044
Memory safety bugs fixed in Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
9.8EPSS 0.004
CVE-2024-4778
Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Analyzed
9.8EPSS 0.004
CVE-2026-2782
Privilege escalation in the Netmonitor component
Published 2026-02-24 · Modified
9.8EPSS 0.004
CVE-2026-16369
Integer overflow in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16363
JIT miscompilation in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16408
Integer overflow in the Audio/Video: Playback component
Published 2026-07-21 · Modified
9.8EPSS 0.004
CVE-2026-2780
Privilege escalation in the Netmonitor component
Published 2026-02-24 · Modified
9.8EPSS 0.004
← Prev15 / 84Next →