VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2026-7320
Information disclosure due to incorrect boundary conditions in the Audio/Video component
Published 2026-04-28 · Modified
7.5EPSS 0.006
CVE-2024-10464
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.006
CVE-2026-8949
Integer overflow in the Widget: Win32 component
Published 2026-05-19 · Analyzed
7.5EPSS 0.006
CVE-2026-74977
Integer overflow in the Graphics component
Published 2026-08-18 · Analyzed
7.5EPSS 0.006
CVE-2024-10459
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.006
CVE-2026-6773
Denial-of-service due to integer overflow in the Graphics: WebGPU component
Published 2026-04-21 · Analyzed
7.5EPSS 0.006
CVE-2024-7526
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Published 2024-08-06 · Modified
7.5EPSS 0.006
CVE-2026-6754
Use-after-free in the JavaScript Engine component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2026-6746
Use-after-free in the DOM: Core & HTML component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2026-6747
Use-after-free in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.006
CVE-2026-4707
Incorrect boundary conditions in the Graphics: Canvas2D component
Published 2026-03-24 · Modified
7.5EPSS 0.006
CVE-2024-3858
It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.
Published 2024-04-16 · Analyzed
7.5EPSS 0.006
CVE-2025-1937
Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
Published 2025-03-04 · Modified
7.5EPSS 0.006
CVE-2026-8391
Other issue in the JavaScript Engine component
Published 2026-05-12 · Modified
7.5EPSS 0.006
CVE-2023-29537
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Published 2023-06-02 · Modified
7.5EPSS 0.006
CVE-2022-34477
The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.
Published 2022-12-22 · Modified
7.5EPSS 0.006
CVE-2024-4773
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Analyzed
7.5EPSS 0.005
CVE-2024-6604
Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13
Published 2024-07-09 · Analyzed
7.5EPSS 0.005
CVE-2025-1931
Use-after-free in WebTransportChild
Published 2025-03-04 · Modified
7.5EPSS 0.005
CVE-2026-2801
Incorrect boundary conditions in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
7.5EPSS 0.005
CVE-2026-8968
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
Published 2026-05-19 · Analyzed
7.5EPSS 0.005
CVE-2026-74982
Denial-of-service in the Widget component
Published 2026-08-18 · Analyzed
7.5EPSS 0.005
CVE-2024-10462
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.005
CVE-2024-10465
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Published 2024-10-29 · Modified
7.5EPSS 0.005
CVE-2026-6786
Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-6785
Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2024-11702
Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
7.5EPSS 0.005
CVE-2024-9394
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.005
CVE-2026-6759
Use-after-free in the Widget: Cocoa component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-4727
Denial-of-service in the Libraries component in NSS
Published 2026-03-24 · Modified
7.5EPSS 0.005
CVE-2026-6780
Denial-of-service in the Audio/Video: Playback component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-6781
Denial-of-service in the Audio/Video: Playback component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-4726
Denial-of-service in the XML component
Published 2026-03-24 · Modified
7.5EPSS 0.005
CVE-2026-6758
Use-after-free in the JavaScript: WebAssembly component
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2024-2613
Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.
Published 2024-03-19 · Analyzed
7.5EPSS 0.005
CVE-2023-47131
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
Published 2024-02-08 · Modified
7.5EPSS 0.005
CVE-2024-9399
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.005
CVE-2026-2794
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
Published 2026-02-24 · Modified
7.5EPSS 0.005
CVE-2024-5694
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.
Published 2024-06-11 · Modified
7.5EPSS 0.005
CVE-2026-8388
Incorrect boundary conditions in the JavaScript Engine: JIT component
Published 2026-05-12 · Modified
7.5EPSS 0.005
← Prev41 / 73Next →