VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2019-9798
On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.
Published 2019-04-26 · Modified
7.4EPSS 0.009
CVE-2021-23957
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Published 2021-02-26 · Modified
7.4EPSS 0.008
CVE-2023-5170
In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.
Published 2023-09-27 · Modified
7.4EPSS 0.007
CVE-2019-9803
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources. This vulnerability affects Firefox < 66.
Published 2019-04-26 · Modified
7.4EPSS 0.006
CVE-2024-6603
Memory corruption in thread creation
Published 2024-07-09 · Analyzed
7.4EPSS 0.005
CVE-2025-3032
Leaking file descriptors from the fork server
Published 2025-04-01 · Modified
7.4EPSS 0.004
CVE-2016-1963
The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.
Published 2016-03-13 · Modified
7.4EPSS 0.003
CVE-2025-1936
Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents
Published 2025-03-04 · Modified
7.3EPSS 0.004
CVE-2024-9403
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.
Published 2024-10-01 · Analyzed
7.3EPSS 0.004
CVE-2025-1018
Fullscreen notification is not displayed when fullscreen is re-requested
Published 2025-02-04 · Modified
7.3EPSS 0.004
CVE-2025-10528
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component
Published 2025-09-16 · Modified
7.3EPSS 0.004
CVE-2025-14325
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-12-09 · Modified
7.3EPSS 0.003
CVE-2025-3029
URL Bar Spoofing via non-BMP Unicode characters
Published 2025-04-01 · Modified
7.3EPSS 0.003
CVE-2025-5272
Memory safety bugs fixed in Firefox 139 and Thunderbird 139
Published 2025-05-27 · Modified
7.3EPSS 0.003
CVE-2025-14332
Memory safety bugs fixed in Firefox 146 and Thunderbird 146
Published 2025-12-09 · Modified
7.3EPSS 0.003
CVE-2026-12318
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-06-16 · Analyzed
7.3EPSS 0.003
CVE-2026-12324
Incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2026-06-16 · Analyzed
7.3EPSS 0.002
CVE-2013-0799
Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and Thunderbird ESR 17.x before 17.0.5 on Windows allows local users to gain privileges via crafted arguments.
Published 2013-04-03 · Modified
7.2EPSS 0.004
CVE-2013-1700
The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location.
Published 2013-06-26 · Modified
7.2EPSS 0.004
CVE-2013-1706
Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.
Published 2013-08-07 · Modified
7.2EPSS 0.003
CVE-2013-1707
Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.
Published 2013-08-07 · Modified
7.2EPSS 0.003
CVE-2011-2980
Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows local users to gain privileges by leveraging write access in an unspecified directory to place a Trojan horse DLL that is loaded into the running Firefox process.
Published 2011-08-18 · Modified
7.2EPSS 0.003
CVE-2016-1956
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
Published 2016-03-13 · Modified
7.1EPSS 0.024
CVE-2009-0776
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
Published 2009-03-05 · Modified
7.1EPSS 0.016
CVE-2014-8643
Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.
Published 2015-01-14 · Modified
7.1EPSS 0.015
CVE-2021-29964
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Published 2021-06-24 · Modified
7.1EPSS 0.008
CVE-2022-22753
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Published 2022-12-22 · Modified
7.1EPSS 0.006
CVE-2022-42930
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.
Published 2022-12-22 · Modified
7.1EPSS 0.004
CVE-2018-12397
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
Published 2019-02-28 · Modified
7.1EPSS 0.004
CVE-2024-26282
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.
Published 2024-02-22 · Analyzed
7.1EPSS 0.003
CVE-2025-4085
Potential information leakage and privilege escalation in UITour actor
Published 2025-04-29 · Modified
7.1EPSS 0.003
CVE-2025-10527
Sandbox escape due to use-after-free in the Graphics: Canvas2D component
Published 2025-09-16 · Modified
7.1EPSS 0.003
CVE-2025-1940
Android Intent confirmation prompt tapjacking using Select options
Published 2025-03-04 · Modified
7.1EPSS 0.002
CVE-2016-9077
Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.
Published 2018-06-11 · Modified
7.0EPSS 0.008
CVE-2024-5700
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Published 2024-06-11 · Analyzed
7.0EPSS 0.004
CVE-2018-12385
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.
Published 2018-10-18 · Modified
7.0EPSS 0.004
CVE-2022-22736
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>*This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.
Published 2022-12-22 · Modified
7.0EPSS 0.002
CVE-2019-11736
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. <br>*Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Published 2019-09-27 · Modified
7.0EPSS 0.002
CVE-2013-1715
Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.
Published 2013-08-07 · Modified
6.9EPSS 0.004
CVE-2014-1520
maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.
Published 2014-04-30 · Modified
6.9EPSS 0.004
← Prev44 / 73Next →