VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2026-8970
Privilege escalation in the Security component
Published 2026-05-19 · Analyzed
8.8EPSS 0.004
CVE-2025-14323
Privilege escalation in the DOM: Notifications component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2026-8957
Privilege escalation in the Enterprise Policies component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2026-6769
Privilege escalation in the Debugger component
Published 2026-04-21 · Analyzed
8.8EPSS 0.004
CVE-2025-8034
Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.004
CVE-2025-14329
Privilege escalation in the Netmonitor component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2025-14328
Privilege escalation in the Netmonitor component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2026-8952
Privilege escalation in the Application Update component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2025-1930
AudioIPC StreamData could trigger a use-after-free in the Browser process
Published 2025-03-04 · Modified
8.8EPSS 0.004
CVE-2026-12289
Privilege escalation in the Graphics: WebRender component
Published 2026-06-16 · Modified
8.8EPSS 0.004
CVE-2026-3845
Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android
Published 2026-03-10 · Modified
8.8EPSS 0.004
CVE-2025-1014
Certificate length was not properly checked
Published 2025-02-04 · Modified
8.8EPSS 0.004
CVE-2026-12291
Use-after-free in the Networking: HTTP component
Published 2026-06-16 · Modified
8.8EPSS 0.004
CVE-2026-3847
Memory safety bugs fixed in Firefox 148.0.2
Published 2026-03-10 · Modified
8.8EPSS 0.004
CVE-2022-34469
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.
Published 2022-12-22 · Modified
8.8EPSS 0.004
CVE-2022-22758
When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.
Published 2022-12-22 · Modified
8.8EPSS 0.004
CVE-2024-6605
Firefox Android missed activation delay to prevent tapjacking
Published 2024-07-09 · Analyzed
8.8EPSS 0.004
CVE-2025-8035
Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.004
CVE-2026-84131
Privilege escalation due to invalid pointer in the Graphics component
Published 2026-09-01 · Analyzed
8.8EPSS 0.003
CVE-2025-11714
Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
8.8EPSS 0.003
CVE-2025-11715
Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
8.8EPSS 0.003
CVE-2025-10537
Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143
Published 2025-09-16 · Modified
8.8EPSS 0.003
CVE-2025-8040
Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.003
CVE-2026-16371
Privilege escalation in the DOM: Navigation component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16372
Privilege escalation in the DOM: Content Processes component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2025-13014
Use-after-free in the Audio/Video component
Published 2025-11-11 · Modified
8.8EPSS 0.003
CVE-2026-16362
Use-after-free in the WebRTC: Audio/Video component
Published 2026-07-21 · Analyzed
8.8EPSS 0.003
CVE-2025-13020
Use-after-free in the WebRTC: Audio/Video component
Published 2025-11-11 · Modified
8.8EPSS 0.003
CVE-2026-16379
Privilege escalation in the DOM: Content Processes component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16365
Privilege escalation in the DOM: Workers component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-24869
Use-after-free in the Layout: Scrolling and Overflow component
Published 2026-01-27 · Modified
8.8EPSS 0.003
CVE-2026-16366
Privilege escalation in the DOM: Navigation component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2025-14861
Memory safety bugs fixed in Firefox 146.0.1
Published 2025-12-18 · Modified
8.8EPSS 0.003
CVE-2026-16396
Privilege escalation in WebExtensions
Published 2026-07-21 · Modified
8.8EPSS 0.002
CVE-2026-16401
Privilege escalation in the Data Loss Prevention component
Published 2026-07-21 · Modified
8.8EPSS 0.002
CVE-2025-6426
No warning when opening executable terminal files on macOS
Published 2025-06-24 · Modified
8.8EPSS 0.002
CVE-2018-5129
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Published 2018-06-11 · Modified
8.6EPSS 0.030
CVE-2017-5448
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
8.6EPSS 0.021
CVE-2023-4576
Integer Overflow in RecordedSourceSurfaceCreation
Published 2023-09-11 · Modified
8.6EPSS 0.008
CVE-2024-5696
By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
8.6EPSS 0.008
← Prev31 / 73Next →