VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2026-12328
Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
Published 2026-06-16 · Modified
8.1EPSS 0.005
CVE-2026-4718
Undefined behavior in the WebRTC: Signaling component
Published 2026-03-24 · Modified
8.1EPSS 0.005
CVE-2025-5269
Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11
Published 2025-05-27 · Modified
8.1EPSS 0.005
CVE-2025-3034
Memory safety bugs fixed in Firefox 137 and Thunderbird 137
Published 2025-04-01 · Modified
8.1EPSS 0.005
CVE-2025-6435
Save as in Devtools could download files without sanitizing the extension
Published 2025-06-24 · Modified
8.1EPSS 0.005
CVE-2025-14333
Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
Published 2025-12-09 · Modified
8.1EPSS 0.004
CVE-2026-74957
Mitigation bypass in the Safe Browsing component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2026-74983
Mitigation bypass in the Data Loss Prevention component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2025-8036
DNS rebinding circumvents CORS
Published 2025-07-22 · Modified
8.1EPSS 0.004
CVE-2025-1932
Inconsistent comparator in XSLT sorting led to out-of-bounds access
Published 2025-03-04 · Modified
8.1EPSS 0.004
CVE-2026-8093
Memory safety bugs fixed in Firefox 150.0.2
Published 2026-05-07 · Modified
8.1EPSS 0.004
CVE-2022-42927
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Published 2022-12-22 · Modified
8.1EPSS 0.004
CVE-2026-12327
Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
Published 2026-06-16 · Analyzed
8.1EPSS 0.004
CVE-2026-8962
Mitigation bypass in the DOM: Security component
Published 2026-05-19 · Analyzed
8.1EPSS 0.004
CVE-2026-12290
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
8.1EPSS 0.004
CVE-2026-8969
Mitigation bypass in the DOM: Security component
Published 2026-05-19 · Analyzed
8.1EPSS 0.004
CVE-2026-74978
Clickjacking issue in the Widget component
Published 2026-08-18 · Analyzed
8.1EPSS 0.004
CVE-2025-9184
Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Published 2025-08-19 · Modified
8.1EPSS 0.004
CVE-2026-12326
Memory safety bugs fixed in Firefox 152 and Thunderbird 152
Published 2026-06-16 · Modified
8.1EPSS 0.004
CVE-2025-11713
Potential user-assisted code execution in “Copy as cURL” command
Published 2025-10-14 · Modified
8.1EPSS 0.004
CVE-2025-10534
Spoofing issue in the Site Permissions component
Published 2025-09-16 · Modified
8.1EPSS 0.004
CVE-2025-13027
Memory safety bugs fixed in Firefox 145 and Thunderbird 145
Published 2025-11-11 · Modified
8.1EPSS 0.003
CVE-2025-8030
Potential user-assisted code execution in “Copy as cURL” command
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8029
javascript: URLs executed on object and embed tags
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8032
XSLT documents could bypass CSP
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2025-8039
Search terms persisted in URL bar
Published 2025-07-22 · Modified
8.1EPSS 0.003
CVE-2024-4765
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
Published 2024-05-14 · Analyzed
8.1EPSS 0.003
CVE-2025-11720
Spoofing risk in Android custom tabs
Published 2025-10-14 · Modified
8.1EPSS 0.003
CVE-2025-13018
Mitigation bypass in the DOM: Security component
Published 2025-11-11 · Modified
8.1EPSS 0.003
CVE-2025-13017
Same-origin policy bypass in the DOM: Notifications component
Published 2025-11-11 · Modified
8.1EPSS 0.003
CVE-2025-13019
Same-origin policy bypass in the DOM: Workers component
Published 2025-11-11 · Modified
8.1EPSS 0.003
CVE-2025-9180
Same-origin policy bypass in the Graphics: Canvas2D component
Published 2025-08-19 · Modified
8.1EPSS 0.002
CVE-2026-74960
Site isolation issue in the WebExtensions component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2026-74962
Site isolation issue in the Networking: Cookies component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2026-74981
Site isolation issue in the Audio/Video: Web Codecs component
Published 2026-08-18 · Analyzed
8.1EPSS 0.002
CVE-2016-9070
A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulnerability affects Firefox < 50.
Published 2018-06-11 · Modified
8.0EPSS 0.019
CVE-2026-0878
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2026-01-13 · Modified
8.0EPSS 0.005
CVE-2025-14322
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2025-12-09 · Modified
8.0EPSS 0.003
CVE-2009-2479
Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occurs in an operating-system library, not in Firefox.
Published 2009-07-16 · Modified
7.81 PoCEPSS 0.121
CVE-2008-4068
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.
Published 2008-09-24 · Modified
7.8EPSS 0.042
← Prev37 / 84Next →