VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2023-47131
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
Published 2024-02-08 · Modified
7.5EPSS 0.005
CVE-2024-9399
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.005
CVE-2026-2794
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
Published 2026-02-24 · Modified
7.5EPSS 0.005
CVE-2024-5694
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.
Published 2024-06-11 · Modified
7.5EPSS 0.005
CVE-2026-8388
Incorrect boundary conditions in the JavaScript Engine: JIT component
Published 2026-05-12 · Modified
7.5EPSS 0.005
CVE-2026-4709
Incorrect boundary conditions in the Audio/Video: GMP component
Published 2026-03-24 · Modified
7.5EPSS 0.005
CVE-2026-6751
Uninitialized memory in the Audio/Video: Web Codecs component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-6752
Incorrect boundary conditions in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-6753
Incorrect boundary conditions in the WebRTC component
Published 2026-04-21 · Modified
7.5EPSS 0.005
CVE-2026-7323
Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1
Published 2026-04-28 · Modified
7.5EPSS 0.005
CVE-2026-6772
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2026-4706
Incorrect boundary conditions in the Graphics: Canvas2D component
Published 2026-03-24 · Modified
7.5EPSS 0.005
CVE-2026-74958
Information disclosure in the WebRTC component
Published 2026-08-18 · Analyzed
7.5EPSS 0.005
CVE-2026-8090
Use-after-free in the DOM: Networking component
Published 2026-05-07 · Modified
7.5EPSS 0.004
CVE-2026-2803
Information disclosure, mitigation bypass in the Settings UI component
Published 2026-02-24 · Modified
7.5EPSS 0.004
CVE-2026-8947
Use-after-free in the DOM: Bindings (WebIDL) component
Published 2026-05-19 · Modified
7.5EPSS 0.004
CVE-2025-13016
Incorrect boundary conditions in the JavaScript: WebAssembly component
Published 2025-11-11 · Modified
7.5EPSS 0.004
CVE-2026-84132
Information disclosure in the Networking: HTTP component
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-84130
Information disclosure in the Graphics: WebGPU component
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-74954
Information disclosure due to side-channel in the Storage: Cache API component
Published 2026-08-18 · Analyzed
7.5EPSS 0.004
CVE-2026-74966
Information disclosure in the Form Autofill component
Published 2026-08-18 · Analyzed
7.5EPSS 0.004
CVE-2026-4714
Incorrect boundary conditions in the Audio/Video component
Published 2026-03-24 · Modified
7.5EPSS 0.004
CVE-2026-4708
Incorrect boundary conditions in the Graphics component
Published 2026-03-24 · Modified
7.5EPSS 0.004
CVE-2026-4719
Incorrect boundary conditions in the Graphics: Text component
Published 2026-03-24 · Modified
7.5EPSS 0.004
CVE-2026-4713
Incorrect boundary conditions in the Graphics component
Published 2026-03-24 · Modified
7.5EPSS 0.004
CVE-2026-8954
Incorrect boundary conditions, integer overflow in the Audio/Video component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-6766
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-04-21 · Analyzed
7.5EPSS 0.004
CVE-2024-8900
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
Published 2024-09-17 · Modified
7.5EPSS 0.004
CVE-2026-8965
Information disclosure in the DOM: Security component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-8966
Information disclosure in the IP Protection component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-8967
Information disclosure in the Graphics: WebGPU component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-6782
Information disclosure in the IP Protection component
Published 2026-04-21 · Analyzed
7.5EPSS 0.004
CVE-2026-84144
Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-6784
Memory safety bugs fixed in Firefox 150 and Thunderbird 150
Published 2026-04-21 · Modified
7.5EPSS 0.004
CVE-2026-2783
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-02-24 · Modified
7.5EPSS 0.004
CVE-2026-8960
Spoofing issue in WebExtensions
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-8963
Spoofing issue in the Web Speech component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
CVE-2026-8945
Sandbox escape in Firefox and Firefox Focus for Android
Published 2026-05-19 · Modified
7.5EPSS 0.004
CVE-2024-9393
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Published 2024-10-01 · Modified
7.5EPSS 0.004
CVE-2026-8964
Spoofing issue in the Popup Blocker component
Published 2026-05-19 · Analyzed
7.5EPSS 0.004
← Prev47 / 84Next →