VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2025-10537
Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143
Published 2025-09-16 · Modified
8.8EPSS 0.003
CVE-2025-11715
Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Published 2025-10-14 · Modified
8.8EPSS 0.003
CVE-2025-8040
Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Published 2025-07-22 · Modified
8.8EPSS 0.003
CVE-2026-16371
Privilege escalation in the DOM: Navigation component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16372
Privilege escalation in the DOM: Content Processes component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2025-13014
Use-after-free in the Audio/Video component
Published 2025-11-11 · Modified
8.8EPSS 0.003
CVE-2026-16362
Use-after-free in the WebRTC: Audio/Video component
Published 2026-07-21 · Analyzed
8.8EPSS 0.003
CVE-2025-13020
Use-after-free in the WebRTC: Audio/Video component
Published 2025-11-11 · Modified
8.8EPSS 0.003
CVE-2026-16379
Privilege escalation in the DOM: Content Processes component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-16365
Privilege escalation in the DOM: Workers component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2026-24869
Use-after-free in the Layout: Scrolling and Overflow component
Published 2026-01-27 · Modified
8.8EPSS 0.003
CVE-2026-16366
Privilege escalation in the DOM: Navigation component
Published 2026-07-21 · Modified
8.8EPSS 0.003
CVE-2025-14861
Memory safety bugs fixed in Firefox 146.0.1
Published 2025-12-18 · Modified
8.8EPSS 0.003
CVE-2026-16396
Privilege escalation in WebExtensions
Published 2026-07-21 · Modified
8.8EPSS 0.002
CVE-2026-16401
Privilege escalation in the Data Loss Prevention component
Published 2026-07-21 · Modified
8.8EPSS 0.002
CVE-2025-6426
No warning when opening executable terminal files on macOS
Published 2025-06-24 · Modified
8.8EPSS 0.002
CVE-2018-5129
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Published 2018-06-11 · Modified
8.6EPSS 0.030
CVE-2017-5448
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
8.6EPSS 0.021
CVE-2023-4576
Integer Overflow in RecordedSourceSurfaceCreation
Published 2023-09-11 · Modified
8.6EPSS 0.008
CVE-2024-5696
By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
8.6EPSS 0.008
CVE-2022-46872
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
Published 2022-12-22 · Modified
8.6EPSS 0.008
CVE-2024-4771
A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Analyzed
8.6EPSS 0.005
CVE-2026-8958
Information disclosure, sandbox escape in the Security: Process Sandboxing component
Published 2026-05-19 · Analyzed
8.6EPSS 0.004
CVE-2025-6432
DNS Requests leaked outside of a configured SOCKS proxy
Published 2025-06-24 · Modified
8.6EPSS 0.004
CVE-2025-11152
Sandbox escape due to integer overflow in the Graphics: Canvas2D component
Published 2025-09-30 · Modified
8.6EPSS 0.003
CVE-2024-29944
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.
Published 2024-03-22 · Analyzed
8.4EPSS 0.047
CVE-2024-2608
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Published 2024-03-19 · Analyzed
8.4EPSS 0.004
CVE-2026-45173
Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure
Published 2026-06-11 · Analyzed
8.4EPSS 0.002
CVE-2013-5598
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
Published 2013-10-30 · Modified
8.3EPSS 0.029
CVE-2019-9811
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Published 2019-07-23 · Modified
8.3EPSS 0.026
CVE-2019-11716
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.
Published 2019-07-23 · Modified
8.3EPSS 0.014
CVE-2019-9818
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulnerability only affects Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Published 2019-07-23 · Modified
8.3EPSS 0.010
CVE-2024-1555
When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.
Published 2024-02-20 · Analyzed
8.3EPSS 0.005
CVE-2017-7813
Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.
Published 2018-06-11 · Modified
8.2EPSS 0.016
CVE-2018-5141
A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction. This could be used to open new tabs in a denial of service (DOS) attack or to display unwanted content from arbitrary URLs to users. This vulnerability affects Firefox < 59.
Published 2018-06-11 · Modified
8.2EPSS 0.016
CVE-2022-4066
davidmoreno onion Log response.c onion_response_flush allocation of resources
Published 2022-11-19 · Modified
8.2EPSS 0.011
CVE-2025-1943
Memory safety bugs fixed in Firefox 136 and Thunderbird 136
Published 2025-03-04 · Modified
8.2EPSS 0.004
CVE-2024-4776
A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Analyzed
8.2EPSS 0.004
CVE-2024-6606
Out-of-bounds read in clipboard component
Published 2024-07-09 · Analyzed
8.2EPSS 0.004
CVE-2018-12386
A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.
Published 2018-10-18 · Modified
8.1EPSS 0.134
← Prev35 / 84Next →