VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2026-6756
Mitigation bypass in Firefox for Android
Published 2026-04-21 · Analyzed
7.5EPSS 0.004
CVE-2026-4712
Information disclosure in the Widget: Cocoa component
Published 2026-03-24 · Modified
7.5EPSS 0.004
CVE-2024-31392
If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.
Published 2024-04-03 · Analyzed
7.5EPSS 0.004
CVE-2025-14327
Spoofing issue in the Downloads Panel component
Published 2025-12-09 · Modified
7.5EPSS 0.004
CVE-2025-9182
Denial-of-service due to out-of-memory in the Graphics: WebRender component
Published 2025-08-19 · Modified
7.5EPSS 0.004
CVE-2026-12305
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.004
CVE-2026-84138
Denial-of-service in the PDF Viewer component
Published 2026-09-01 · Modified
7.5EPSS 0.004
CVE-2026-84145
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
Published 2026-09-01 · Analyzed
7.5EPSS 0.004
CVE-2026-7324
Memory safety bugs fixed in Thunderbird 150.0.1
Published 2026-04-28 · Modified
7.5EPSS 0.004
CVE-2026-16376
Denial-of-service in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.004
CVE-2024-3853
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.
Published 2024-04-16 · Analyzed
7.5EPSS 0.004
CVE-2026-4684
Race condition, use-after-free in the Graphics: WebRender component
Published 2026-03-24 · Modified
7.5EPSS 0.004
CVE-2026-8390
Use-after-free in the JavaScript: WebAssembly component
Published 2026-05-12 · Modified
7.5EPSS 0.003
CVE-2026-16354
Information disclosure in the Graphics: ImageLib component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2025-55029
Malicious scripts could spam popups for denial of service attacks
Published 2025-08-19 · Modified
7.5EPSS 0.003
CVE-2026-16391
Information disclosure in the Storage: IndexedDB component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16374
Information disclosure in the Framework component in DevTools
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12329
Memory safety bug fixed in Thunderbird ESR 140.12
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2025-10535
Information disclosure, mitigation bypass in the Privacy component in Firefox for Android
Published 2025-09-16 · Modified
7.5EPSS 0.003
CVE-2026-16384
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16386
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-16385
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12299
JIT miscompilation in the DOM: Core & HTML component
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12298
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16378
Other issue in the DOM: Copy & Paste and Drag & Drop component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-10701
Incorrect boundary conditions in the Graphics: Text component
Published 2026-06-02 · Modified
7.5EPSS 0.003
CVE-2026-16409
Invalid pointer in the Security: PSM component
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-12317
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2025-5270
SNI was sometimes unencrypted
Published 2025-05-27 · Modified
7.5EPSS 0.003
CVE-2025-13025
Incorrect boundary conditions in the Graphics: WebGPU component
Published 2025-11-11 · Modified
7.5EPSS 0.003
CVE-2026-16405
Information disclosure in the Networking: WebSockets component
Published 2026-07-21 · Modified
7.5EPSS 0.003
CVE-2026-12314
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12310
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-12312
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-16400
Information disclosure in the DOM: Security component
Published 2026-07-21 · Analyzed
7.5EPSS 0.002
CVE-2025-13012
Race condition in the Graphics component
Published 2025-11-11 · Modified
7.5EPSS 0.002
CVE-2025-11153
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-09-30 · Modified
7.5EPSS 0.002
CVE-2026-74934
Site isolation issue in the Graphics: CanvasWebGL component
Published 2026-08-18 · Analyzed
7.5EPSS 0.002
CVE-2026-16398
Site isolation issue in the Graphics component
Published 2026-07-21 · Analyzed
7.5EPSS 0.001
CVE-2026-16399
Site isolation issue in the DOM: Navigation component
Published 2026-07-21 · Analyzed
7.5EPSS 0.001
← Prev48 / 84Next →