VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2004-0765
The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.
Published 2004-08-03 · Modified
7.5EPSS 0.010
CVE-2023-4048
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
7.5EPSS 0.009
CVE-2023-32214
Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
Published 2023-06-19 · Modified
7.5EPSS 0.009
CVE-2023-5173
In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.
Published 2023-09-27 · Modified
7.5EPSS 0.009
CVE-2024-5702
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
7.5EPSS 0.009
CVE-2026-10702
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-06-02 · Modified
7.5EPSS 0.009
CVE-2024-10466
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.008
CVE-2019-11723
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.
Published 2019-07-23 · Modified
7.5EPSS 0.008
CVE-2017-7797
Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin. This vulnerability affects Firefox < 55.
Published 2018-06-11 · Modified
7.5EPSS 0.008
CVE-2026-4694
Incorrect boundary conditions, integer overflow in the Graphics component
Published 2026-03-24 · Modified
7.5EPSS 0.008
CVE-2023-32209
A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.
Published 2023-06-19 · Modified
7.5EPSS 0.008
CVE-2022-22737
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Published 2022-12-22 · Modified
7.5EPSS 0.007
CVE-2021-29952
When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.
Published 2021-06-24 · Modified
7.5EPSS 0.007
CVE-2023-4055
When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Published 2023-08-01 · Modified
7.5EPSS 0.007
CVE-2024-1546
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Analyzed
7.5EPSS 0.007
CVE-2026-4686
Incorrect boundary conditions in the Graphics: Canvas2D component
Published 2026-03-24 · Modified
7.5EPSS 0.007
CVE-2022-36319
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
Published 2022-12-22 · Modified
7.5EPSS 0.007
CVE-2024-10463
Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.007
CVE-2026-4695
Incorrect boundary conditions in the Audio/Video: Web Codecs component
Published 2026-03-24 · Modified
7.5EPSS 0.007
CVE-2026-4699
Incorrect boundary conditions in the Layout: Text and Fonts component
Published 2026-03-24 · Modified
7.5EPSS 0.007
CVE-2026-4693
Incorrect boundary conditions in the Audio/Video: Playback component
Published 2026-03-24 · Modified
7.5EPSS 0.007
CVE-2026-4685
Incorrect boundary conditions in the Graphics: Canvas2D component
Published 2026-03-24 · Modified
7.5EPSS 0.007
CVE-2026-4697
Incorrect boundary conditions in the Audio/Video: Web Codecs component
Published 2026-03-24 · Modified
7.5EPSS 0.007
CVE-2023-4583
Browsing Context potentially not cleared when closing Private Window
Published 2023-09-11 · Modified
7.5EPSS 0.007
CVE-2024-1552
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Published 2024-02-20 · Modified
7.5EPSS 0.007
CVE-2017-7759
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.
Published 2018-06-11 · Modified
7.5EPSS 0.007
CVE-2023-4051
Full screen notification obscured by file open dialog
Published 2023-08-01 · Modified
7.5EPSS 0.007
CVE-2022-26387
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
Published 2022-12-22 · Modified
7.5EPSS 0.007
CVE-2024-7652
Type Confusion in Async Generators in Javascript Engine
Published 2024-09-06 · Analyzed
7.5EPSS 0.007
CVE-2022-22741
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Published 2022-12-22 · Modified
7.5EPSS 0.007
CVE-2024-8383
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
Published 2024-09-03 · Modified
7.5EPSS 0.006
CVE-2022-45407
If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107.
Published 2022-12-22 · Modified
7.5EPSS 0.006
CVE-2026-4704
Denial-of-service in the WebRTC: Signaling component
Published 2026-03-24 · Modified
7.5EPSS 0.006
CVE-2024-3852
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Published 2024-04-16 · Analyzed
7.5EPSS 0.006
CVE-2023-25733
The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null pointer dereference. This vulnerability affects Firefox < 110.
Published 2023-06-19 · Modified
7.5EPSS 0.006
CVE-2024-0744
In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox < 122.
Published 2024-01-23 · Modified
7.5EPSS 0.006
CVE-2026-0889
Denial-of-service in the DOM: Service Workers component
Published 2026-01-13 · Modified
7.5EPSS 0.006
CVE-2026-8946
Incorrect boundary conditions in the Audio/Video: Web Codecs component
Published 2026-05-19 · Modified
7.5EPSS 0.006
CVE-2026-6749
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2024-10458
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.006
← Prev40 / 73Next →