VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2024-4777
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Published 2024-05-14 · Modified
8.8EPSS 0.005
CVE-2022-29918
Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 100.
Published 2022-12-22 · Modified
8.8EPSS 0.005
CVE-2023-25740
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.
Published 2023-06-02 · Modified
8.8EPSS 0.005
CVE-2022-28288
Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 98. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 99.
Published 2022-12-22 · Modified
8.8EPSS 0.005
CVE-2022-0511
Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97.
Published 2022-12-22 · Modified
8.8EPSS 0.005
CVE-2023-29543
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Published 2023-06-02 · Modified
8.8EPSS 0.005
CVE-2023-29551
Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Published 2023-06-02 · Modified
8.8EPSS 0.005
CVE-2023-23606
Memory safety bugs fixed in Firefox 109
Published 2023-06-02 · Modified
8.8EPSS 0.005
CVE-2022-22752
Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 96.
Published 2022-12-22 · Modified
8.8EPSS 0.005
CVE-2024-9400
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Analyzed
8.8EPSS 0.005
CVE-2022-46885
Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106.
Published 2022-12-22 · Modified
8.8EPSS 0.005
CVE-2026-74946
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74941
Privilege escalation in the Graphics: CanvasWebGL component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2022-46884
A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune time. This could have lead to memory corruption or a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106.
Published 2023-08-24 · Modified
8.8EPSS 0.005
CVE-2026-74969
Use-after-free in the Layout: Text and Fonts component
Published 2026-08-18 · Modified
8.8EPSS 0.005
CVE-2026-0882
Use-after-free in the IPC component
Published 2026-01-13 · Modified
8.8EPSS 0.005
CVE-2026-7322
Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1
Published 2026-04-28 · Modified
8.8EPSS 0.005
CVE-2026-74949
Privilege escalation due to use-after-free in the Graphics: Canvas2D component
Published 2026-08-18 · Modified
8.8EPSS 0.005
CVE-2026-5733
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2026-04-07 · Modified
8.8EPSS 0.005
CVE-2026-2798
Use-after-free in the DOM: Core & HTML component
Published 2026-02-24 · Modified
8.8EPSS 0.005
CVE-2026-8973
Memory safety bugs fixed in Firefox 151
Published 2026-05-19 · Modified
8.8EPSS 0.005
CVE-2026-8389
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-05-12 · Modified
8.8EPSS 0.005
CVE-2026-74939
Privilege escalation in the DOM: Navigation component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74942
Privilege escalation in the Remote Settings Client component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74935
Privilege escalation in the DOM: Networking component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74947
Privilege escalation due to invalid pointer in the Graphics component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-8974
Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2024-6615
Memory safety bugs fixed in Firefox 128 and Thunderbird 128
Published 2024-07-09 · Analyzed
8.8EPSS 0.004
CVE-2026-74953
Privilege escalation in the Networking: Cookies component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-74965
Privilege escalation in the Shell Integration component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-84128
Privilege escalation in the WebDriver BiDi component
Published 2026-09-01 · Analyzed
8.8EPSS 0.004
CVE-2026-8972
Privilege escalation in the WebRTC: Audio/Video component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2026-84123
Privilege escalation due to use-after-free in the Graphics: WebGPU component
Published 2026-09-01 · Analyzed
8.8EPSS 0.004
CVE-2026-74937
Use-after-free in the JavaScript: GC component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-4722
Privilege escalation in the IPC component
Published 2026-03-24 · Modified
8.8EPSS 0.004
CVE-2026-8955
Privilege escalation in the DOM: Workers component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2026-74955
Privilege escalation in the Request Handling component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-74952
Privilege escalation in the Application Update component
Published 2026-08-18 · Modified
8.8EPSS 0.004
CVE-2026-74950
Privilege escalation in the Downloads API component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-8970
Privilege escalation in the Security component
Published 2026-05-19 · Analyzed
8.8EPSS 0.004
← Prev30 / 73Next →