VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2026-12305
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.004
CVE-2026-84138
Denial-of-service in the PDF Viewer component
Published 2026-09-01 · Modified
7.5EPSS 0.004
CVE-2026-84145
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-7324
Memory safety bugs fixed in Thunderbird 150.0.1
Published 2026-04-28 · Modified
7.5EPSS 0.004
CVE-2026-16376
Denial-of-service in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.004
CVE-2024-3853
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.
Published 2024-04-16 · Analyzed
7.5EPSS 0.004
CVE-2026-4684
Race condition, use-after-free in the Graphics: WebRender component
Published 2026-03-24 · Modified
7.5EPSS 0.004
CVE-2026-8390
Use-after-free in the JavaScript: WebAssembly component
Published 2026-05-12 · Modified
7.5EPSS 0.003
CVE-2026-16354
Information disclosure in the Graphics: ImageLib component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2025-55029
Malicious scripts could spam popups for denial of service attacks
Published 2025-08-19 · Modified
7.5EPSS 0.003
CVE-2026-16391
Information disclosure in the Storage: IndexedDB component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16374
Information disclosure in the Framework component in DevTools
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12329
Memory safety bug fixed in Thunderbird ESR 140.12
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2025-10535
Information disclosure, mitigation bypass in the Privacy component in Firefox for Android
Published 2025-09-16 · Modified
7.5EPSS 0.003
CVE-2026-16386
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16385
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16384
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12298
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16378
Other issue in the DOM: Copy & Paste and Drag & Drop component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12299
JIT miscompilation in the DOM: Core & HTML component
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-10701
Incorrect boundary conditions in the Graphics: Text component
Published 2026-06-02 · Modified
7.5EPSS 0.003
CVE-2026-16409
Invalid pointer in the Security: PSM component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12317
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2025-5270
SNI was sometimes unencrypted
Published 2025-05-27 · Modified
7.5EPSS 0.003
CVE-2025-13025
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
7.5EPSS 0.003
CVE-2026-16405
Information disclosure in the Networking: WebSockets component
Published 2026-07-21 · Modified
7.5EPSS 0.003
CVE-2026-12310
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12312
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12314
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16400
Information disclosure in the DOM: Security component
Published 2026-07-21 · Analyzed
7.5EPSS 0.002
CVE-2025-13012
Race condition in the Graphics component
Published 2025-11-11 · Modified
7.5EPSS 0.002
CVE-2025-11153
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-09-30 · Modified
7.5EPSS 0.002
CVE-2026-74934
Site isolation issue in the Graphics: CanvasWebGL component
Published 2026-08-18 · Analyzed
7.5EPSS 0.002
CVE-2026-16399
Site isolation issue in the DOM: Navigation component
Published 2026-07-21 · Analyzed
7.5EPSS 0.001
CVE-2026-16398
Site isolation issue in the Graphics component
Published 2026-07-21 · Analyzed
7.5EPSS 0.001
CVE-2016-5284
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.
Published 2016-09-22 · Modified
7.4EPSS 0.024
CVE-2016-1942
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
Published 2016-01-31 · Modified
7.4EPSS 0.018
CVE-2021-23961
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
Published 2021-02-26 · Modified
7.4EPSS 0.015
CVE-2020-15647
A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.
Published 2020-08-10 · Modified
7.4EPSS 0.011
CVE-2019-17014
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.
Published 2020-01-08 · Modified
7.4EPSS 0.011
← Prev43 / 73Next →