VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2026-14241
Memory safety bugs fixed in Firefox 152.0.4
Published 2026-06-30 · Modified
9.8EPSS 0.004
CVE-2026-4721
Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2026-4720
Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2025-11710
Cross-process information leaked due to malicious IPC messages
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2025-11709
Out of bounds read/write in a privileged process triggered by WebGL textures
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2026-4717
Privilege escalation in the Netmonitor component
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2025-55031
Passkey phishing within Bluetooth range
Published 2025-08-19 · Modified
9.8EPSS 0.004
CVE-2026-4710
Incorrect boundary conditions in the Audio/Video component
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2026-16357
Incorrect boundary conditions in the Graphics component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16355
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16350
Incorrect boundary conditions in the Audio/Video: cubeb component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-4711
Use-after-free in the Widget: Cocoa component
Published 2026-03-24 · Modified
9.8EPSS 0.004
CVE-2026-16351
Sandbox escape due to use-after-free in the DOM: Navigation component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16356
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16352
Sandbox escape due to use-after-free in the Disability Access APIs component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2024-10468
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.
Published 2024-10-29 · Analyzed
9.8EPSS 0.004
CVE-2026-16368
Incorrect boundary conditions in the JavaScript: WebAssembly component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16383
Mitigation bypass in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-16377
Mitigation bypass in the PDF Viewer component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2024-1554
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.
Published 2024-02-20 · Analyzed
9.8EPSS 0.004
CVE-2024-7530
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
Published 2024-08-06 · Analyzed
9.8EPSS 0.004
CVE-2025-8043
Incorrect URL truncation
Published 2025-07-22 · Modified
9.8EPSS 0.004
CVE-2026-84136
Other issue in the DOM: Navigation component
Published 2026-09-01 · Modified
9.8EPSS 0.004
CVE-2026-16382
Mitigation bypass in the DOM: Service Workers component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2026-84143
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
Published 2026-09-01 · Modified
9.8EPSS 0.004
CVE-2026-16388
Sandbox escape in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.8EPSS 0.004
CVE-2025-11721
Memory safety bug fixed in Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2025-13021
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-13022
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-13026
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-13023
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-13024
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-11-11 · Modified
9.8EPSS 0.004
CVE-2025-11719
Use-after-free caused by the native messaging web extension API on Windows
Published 2025-10-14 · Modified
9.8EPSS 0.004
CVE-2026-84139
Clickjacking issue in the DOM: Events component
Published 2026-09-01 · Modified
9.8EPSS 0.003
CVE-2026-16395
Integer overflow in the Audio/Video component
Published 2026-07-21 · Modified
9.8EPSS 0.003
CVE-2026-16402
Integer overflow in the Graphics: ImageLib component
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2025-14860
Use-after-free in the Disability Access APIs component
Published 2025-12-18 · Modified
9.8EPSS 0.003
CVE-2026-16361
Memory safety bugs fixed in Thunderbird ESR 140.13
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
CVE-2025-12380
Use-after-free in WebGPU internals triggered from a compromised child process
Published 2025-10-28 · Modified
9.8EPSS 0.003
CVE-2026-16410
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.8EPSS 0.003
← Prev16 / 84Next →