VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2025-13021
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-13022
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-13023
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-13024
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-13026
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-11719
Use-after-free caused by the native messaging web extension API on Windows
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2026-84139
Clickjacking issue in the DOM: Events component
Published 2026-09-01 · Modified
9.8EPSS 0.003
CVE-2026-16402
Integer overflow in the Graphics: ImageLib component
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2026-16395
Integer overflow in the Audio/Video component
Published 2026-07-21 · Modified
9.8EPSS 0.003
CVE-2025-14860
Use-after-free in the Disability Access APIs component
Published 2025-12-18 · Modified
9.8EPSS 0.003
CVE-2026-16361
Memory safety bugs fixed in Thunderbird ESR 140.13
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2025-12380
Use-after-free in WebGPU internals triggered from a compromised child process
Published 2025-10-28 · Modified
9.8EPSS 0.003
CVE-2026-16410
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2026-12293
Use-after-free in the Graphics: WebGPU component
Published 2026-06-16 · Modified
9.8EPSS 0.003
CVE-2025-6433
WebAuthn would allow a user to sign a challenge on a webpage with an invalid TLS certificate
Published 2025-06-24 · Modified
9.8EPSS 0.003
CVE-2026-84133
Site isolation issue in the DOM: Push Subscriptions component
Published 2026-09-01 · Analyzed
9.8EPSS 0.003
CVE-2026-84129
Site isolation issue in the DOM: Navigation component
Published 2026-09-01 · Analyzed
9.8EPSS 0.003
CVE-2026-84140
Site isolation issue in the DOM: Navigation component
Published 2026-09-01 · Modified
9.8EPSS 0.003
CVE-2026-16407
Mitigation bypass in the DOM: Service Workers component
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2025-8038
CSP frame-src was not correctly enforced for paths
Published 2025-07-22 · Modified
9.8EPSS 0.002
CVE-2026-2790
Same-origin policy bypass in the Networking: JAR component
Published 2026-02-24 · Modified
9.8EPSS 0.002
CVE-2026-16358
Site isolation issue in the Graphics: WebRender component
Published 2026-07-21 · Analyzed
9.8EPSS 0.002
CVE-2026-16349
Same-origin policy bypass in the DOM: Navigation component
Published 2026-07-21 · Analyzed
9.8EPSS 0.002
CVE-2026-16375
Site isolation issue in the Networking: HTTP component
Published 2026-07-21 · Analyzed
9.8EPSS 0.002
CVE-2026-84137
Spoofing issue in the DOM: Core & HTML component
Published 2026-09-01 · Modified
9.8EPSS 0.002
CVE-2026-16387
Site isolation issue in the Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.002
CVE-2022-26486
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Published 2022-12-22 · Analyzed
9.6KEVEPSS 0.023
CVE-2022-26384
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
Published 2022-12-22 · Modified
9.6EPSS 0.009
CVE-2026-4690
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
Published 2026-03-24 · Modified
9.6EPSS 0.008
CVE-2022-22759
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Published 2022-12-22 · Modified
9.6EPSS 0.007
CVE-2024-7519
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.6EPSS 0.006
CVE-2026-4687
Sandbox escape due to incorrect boundary conditions in the Telemetry component
Published 2026-03-24 · Modified
9.6EPSS 0.005
CVE-2026-8953
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-05-19 · Analyzed
9.6EPSS 0.005
CVE-2026-7321
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component
Published 2026-04-28 · Analyzed
9.6EPSS 0.004
CVE-2026-8959
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Published 2026-05-19 · Analyzed
9.6EPSS 0.004
CVE-2026-12296
Sandbox escape in the Security: Process Sandboxing component
Published 2026-06-16 · Modified
9.6EPSS 0.004
CVE-2026-12295
Sandbox escape in the DOM: Navigation component
Published 2026-06-16 · Modified
9.6EPSS 0.004
CVE-2026-12297
Sandbox escape due to incorrect boundary conditions in the Networking component
Published 2026-06-16 · Modified
9.6EPSS 0.004
CVE-2026-12294
Sandbox escape in the DOM: Workers component
Published 2026-06-16 · Modified
9.6EPSS 0.004
CVE-2026-84121
Sandbox escape due to use-after-free in the DOM: Security component
Published 2026-09-01 · Analyzed
9.6EPSS 0.003
← Prev15 / 73Next →