VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2026-8389
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-05-12 · Modified
8.8EPSS 0.005
CVE-2026-8973
Memory safety bugs fixed in Firefox 151
Published 2026-05-19 · Modified
8.8EPSS 0.005
CVE-2026-74942
Privilege escalation in the Remote Settings Client component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74935
Privilege escalation in the DOM: Networking component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74939
Privilege escalation in the DOM: Navigation component
Published 2026-08-18 · Analyzed
8.8EPSS 0.005
CVE-2026-74947
Privilege escalation due to invalid pointer in the Graphics component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-8974
Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2024-6615
Memory safety bugs fixed in Firefox 128 and Thunderbird 128
Published 2024-07-09 · Analyzed
8.8EPSS 0.004
CVE-2026-74965
Privilege escalation in the Shell Integration component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-74953
Privilege escalation in the Networking: Cookies component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-84128
Privilege escalation in the WebDriver BiDi component
Published 2026-09-01 · Analyzed
8.8EPSS 0.004
CVE-2026-8972
Privilege escalation in the WebRTC: Audio/Video component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2026-74937
Use-after-free in the JavaScript: GC component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-84123
Privilege escalation due to use-after-free in the Graphics: WebGPU component
Published 2026-09-01 · Analyzed
8.8EPSS 0.004
CVE-2026-4722
Privilege escalation in the IPC component
Published 2026-03-24 · Modified
8.8EPSS 0.004
CVE-2026-74950
Privilege escalation in the Downloads API component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-6761
Privilege escalation in the Networking component
Published 2026-04-21 · Analyzed
8.8EPSS 0.004
CVE-2026-74952
Privilege escalation in the Application Update component
Published 2026-08-18 · Modified
8.8EPSS 0.004
CVE-2026-6769
Privilege escalation in the Debugger component
Published 2026-04-21 · Analyzed
8.8EPSS 0.004
CVE-2026-8955
Privilege escalation in the DOM: Workers component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2026-74955
Privilege escalation in the Request Handling component
Published 2026-08-18 · Analyzed
8.8EPSS 0.004
CVE-2026-8970
Privilege escalation in the Security component
Published 2026-05-19 · Analyzed
8.8EPSS 0.004
CVE-2026-8957
Privilege escalation in the Enterprise Policies component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2025-14323
Privilege escalation in the DOM: Notifications component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2025-8034
Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.004
CVE-2025-14328
Privilege escalation in the Netmonitor component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2025-14329
Privilege escalation in the Netmonitor component
Published 2025-12-09 · Modified
8.8EPSS 0.004
CVE-2026-8952
Privilege escalation in the Application Update component
Published 2026-05-19 · Modified
8.8EPSS 0.004
CVE-2025-1930
AudioIPC StreamData could trigger a use-after-free in the Browser process
Published 2025-03-04 · Modified
8.8EPSS 0.004
CVE-2026-3845
Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android
Published 2026-03-10 · Modified
8.8EPSS 0.004
CVE-2026-12289
Privilege escalation in the Graphics: WebRender component
Published 2026-06-16 · Modified
8.8EPSS 0.004
CVE-2025-1014
Certificate length was not properly checked
Published 2025-02-04 · Modified
8.8EPSS 0.004
CVE-2026-12291
Use-after-free in the Networking: HTTP component
Published 2026-06-16 · Modified
8.8EPSS 0.004
CVE-2026-3847
Memory safety bugs fixed in Firefox 148.0.2
Published 2026-03-10 · Modified
8.8EPSS 0.004
CVE-2022-34469
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.
Published 2022-12-22 · Modified
8.8EPSS 0.004
CVE-2022-22758
When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.
Published 2022-12-22 · Modified
8.8EPSS 0.004
CVE-2024-6605
Firefox Android missed activation delay to prevent tapjacking
Published 2024-07-09 · Analyzed
8.8EPSS 0.004
CVE-2025-8035
Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.004
CVE-2026-84131
Privilege escalation due to invalid pointer in the Graphics component
Published 2026-09-01 · Analyzed
8.8EPSS 0.003
CVE-2025-11714
Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
8.8EPSS 0.003
← Prev34 / 84Next →