VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2024-1553
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Analyzed
8.1EPSS 0.009
CVE-2024-3864
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Published 2024-04-16 · Analyzed
8.1EPSS 0.009
CVE-2019-9821
A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67.
Published 2019-07-23 · Modified
8.1EPSS 0.008
CVE-2021-29968
When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1.
Published 2021-06-24 · Modified
8.1EPSS 0.008
CVE-2023-25734
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Published 2023-06-02 · Modified
8.1EPSS 0.008
CVE-2024-1557
Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123.
Published 2024-02-20 · Analyzed
8.1EPSS 0.006
CVE-2026-8092
Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2
Published 2026-05-07 · Modified
8.1EPSS 0.005
CVE-2024-7529
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Analyzed
8.1EPSS 0.005
CVE-2025-4091
Memory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10
Published 2025-04-29 · Modified
8.1EPSS 0.005
CVE-2025-3030
Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9
Published 2025-04-01 · Modified
8.1EPSS 0.005
CVE-2026-12292
Incorrect boundary conditions in the Web Audio component
Published 2026-06-16 · Modified
8.1EPSS 0.005
CVE-2025-5268
Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11
Published 2025-05-27 · Modified
8.1EPSS 0.005
CVE-2024-3865
Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.
Published 2024-04-16 · Analyzed
8.1EPSS 0.005
CVE-2025-4093
Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10
Published 2025-04-29 · Modified
8.1EPSS 0.005
CVE-2026-0891
Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
Published 2026-01-13 · Modified
8.1EPSS 0.005
CVE-2026-0877
Mitigation bypass in the DOM: Security component
Published 2026-01-13 · Modified
8.1EPSS 0.005
CVE-2024-11700
Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
8.1EPSS 0.005
CVE-2026-12328
Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
Published 2026-06-16 · Modified
8.1EPSS 0.005
CVE-2025-9185
Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
8.1EPSS 0.005
CVE-2026-4718
Undefined behavior in the WebRTC: Signaling component
Published 2026-03-24 · Modified
8.1EPSS 0.005
CVE-2025-5269
Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11
Published 2025-05-27 · Modified
8.1EPSS 0.005
CVE-2025-3034
Memory safety bugs fixed in Firefox 137 and Thunderbird 137
Published 2025-04-01 · Modified
8.1EPSS 0.005
CVE-2025-6435
Save as in Devtools could download files without sanitizing the extension
Published 2025-06-24 · Modified
8.1EPSS 0.005
CVE-2025-14333
Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
Published 2025-12-09 · Modified
8.1EPSS 0.004
CVE-2026-74957
Mitigation bypass in the Safe Browsing component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2026-74983
Mitigation bypass in the Data Loss Prevention component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2025-8036
DNS rebinding circumvents CORS
Published 2025-07-22 · Modified
8.1EPSS 0.004
CVE-2025-1932
Inconsistent comparator in XSLT sorting led to out-of-bounds access
Published 2025-03-04 · Modified
8.1EPSS 0.004
CVE-2026-8093
Memory safety bugs fixed in Firefox 150.0.2
Published 2026-05-07 · Modified
8.1EPSS 0.004
CVE-2022-42927
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Published 2022-12-22 · Modified
8.1EPSS 0.004
CVE-2026-12327
Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
Published 2026-06-16 · Analyzed
8.1EPSS 0.004
CVE-2026-8962
Mitigation bypass in the DOM: Security component
Published 2026-05-19 · Analyzed
8.1EPSS 0.004
CVE-2026-12290
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
8.1EPSS 0.004
CVE-2026-8969
Mitigation bypass in the DOM: Security component
Published 2026-05-19 · Analyzed
8.1EPSS 0.004
CVE-2026-74978
Clickjacking issue in the Widget component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2025-9184
Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
8.1EPSS 0.004
CVE-2026-12326
Memory safety bugs fixed in Firefox 152 and Thunderbird 152
Published 2026-06-16 · Modified
8.1EPSS 0.004
CVE-2025-11713
Potential user-assisted code execution in “Copy as cURL” command
Published 2025-10-14 · Modified
8.1EPSS 0.004
CVE-2025-10534
Spoofing issue in the Site Permissions component
Published 2025-09-16 · Modified
8.1EPSS 0.004
CVE-2025-13027
Memory safety bugs fixed in Firefox 145 and Thunderbird 145
Published 2025-11-11 · Modified
8.1EPSS 0.003
← Prev33 / 73Next →