VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2017-5465
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
9.11 PoCEPSS 0.185
CVE-2017-5447
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
9.11 PoCEPSS 0.173
CVE-2018-12387
A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.
Published 2018-10-18 · Modified
9.1EPSS 0.096
CVE-2014-1508
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via vectors involving MathML polygon rendering.
Published 2014-03-19 · Modified
9.1EPSS 0.043
CVE-2017-7753
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Published 2018-06-11 · Modified
9.1EPSS 0.031
CVE-2017-7758
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Published 2018-06-11 · Modified
9.1EPSS 0.031
CVE-2017-5468
An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53.
Published 2018-06-11 · Modified
9.1EPSS 0.024
CVE-2017-7774
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
Published 2019-04-12 · Modified
9.1EPSS 0.014
CVE-2024-11705
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phKey` to be NULL for certain mechanisms. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
9.1EPSS 0.007
CVE-2024-7522
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.1EPSS 0.006
CVE-2024-7525
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
9.1EPSS 0.006
CVE-2026-2806
Uninitialized memory in the Graphics: Text component
Published 2026-02-24 · Modified
9.1EPSS 0.006
CVE-2026-74986
Site isolation issue in the CSS Parsing and Computation component
Published 2026-08-18 · Analyzed
9.1EPSS 0.006
CVE-2026-74956
Same-origin policy bypass in the DOM: Service Workers component
Published 2026-08-18 · Analyzed
9.1EPSS 0.005
CVE-2026-74959
Mitigation bypass in the Storage: Cache API component
Published 2026-08-18 · Analyzed
9.1EPSS 0.005
CVE-2026-8948
Same-origin policy bypass in the DOM: Networking component
Published 2026-05-19 · Modified
9.1EPSS 0.005
CVE-2025-4083
Process isolation bypass using "javascript:" URI links in cross-origin frames
Published 2025-04-29 · Modified
9.1EPSS 0.005
CVE-2026-74961
Side-channel in the Web Audio component
Published 2026-08-18 · Undergoing Analysis
9.1EPSS 0.004
CVE-2026-74938
Mitigation bypass in the JavaScript: GC component
Published 2026-08-18 · Analyzed
9.1EPSS 0.004
CVE-2026-4715
Uninitialized memory in the Graphics: Canvas2D component
Published 2026-03-24 · Modified
9.1EPSS 0.004
CVE-2026-4724
Undefined behavior in the Audio/Video component
Published 2026-03-24 · Modified
9.1EPSS 0.004
CVE-2026-4716
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component
Published 2026-03-24 · Modified
9.1EPSS 0.004
CVE-2025-54145
Scanning a malicious URL utilizing Firefox's open-text scheme with the QR code scanner could load arbitrary websites
Published 2025-08-19 · Modified
9.1EPSS 0.004
CVE-2024-10004
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
Published 2024-10-15 · Analyzed
9.1EPSS 0.004
CVE-2025-6427
connect-src Content Security Policy restriction could be bypassed
Published 2025-06-24 · Modified
9.1EPSS 0.004
CVE-2025-1941
Lock screen setting bypass in Firefox Focus for Android
Published 2025-03-04 · Modified
9.1EPSS 0.004
CVE-2026-16392
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-07-21 · Analyzed
9.1EPSS 0.004
CVE-2026-16390
Mitigation bypass in the Enterprise Policies component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16380
Mitigation bypass in the Networking component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16370
Mitigation bypass in the DOM: Networking component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16364
Incorrect boundary conditions in the Audio/Video: Playback component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-16393
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2025-11717
The password edit screen was not hidden in Android card view
Published 2025-10-14 · Modified
9.1EPSS 0.003
CVE-2026-16359
Incorrect boundary conditions in the Audio/Video: GMP component
Published 2026-07-21 · Analyzed
9.1EPSS 0.003
CVE-2026-12315
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
9.1EPSS 0.003
CVE-2026-16406
Mitigation bypass in the Networking component
Published 2026-07-21 · Modified
9.1EPSS 0.003
CVE-2026-16394
Mitigation bypass in the DOM: Security component
Published 2026-07-21 · Modified
9.1EPSS 0.003
CVE-2026-12316
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
9.1EPSS 0.002
CVE-2025-8037
Nameless cookies shadow secure cookies
Published 2025-07-22 · Modified
9.1EPSS 0.002
CVE-2026-12304
Same-origin policy bypass in the Networking: Cookies component
Published 2026-06-16 · Analyzed
9.1EPSS 0.002
← Prev25 / 84Next →