VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2016-5284
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.
Published 2016-09-22 · Modified
7.4EPSS 0.024
CVE-2016-1942
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
Published 2016-01-31 · Modified
7.4EPSS 0.018
CVE-2021-23961
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
Published 2021-02-26 · Modified
7.4EPSS 0.015
CVE-2020-15647
A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.
Published 2020-08-10 · Modified
7.4EPSS 0.011
CVE-2019-17014
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.
Published 2020-01-08 · Modified
7.4EPSS 0.011
CVE-2019-9798
On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.
Published 2019-04-26 · Modified
7.4EPSS 0.009
CVE-2021-23957
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
Published 2021-02-26 · Modified
7.4EPSS 0.008
CVE-2023-5170
In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.
Published 2023-09-27 · Modified
7.4EPSS 0.007
CVE-2019-9803
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources. This vulnerability affects Firefox < 66.
Published 2019-04-26 · Modified
7.4EPSS 0.006
CVE-2024-6603
Memory corruption in thread creation
Published 2024-07-09 · Analyzed
7.4EPSS 0.005
CVE-2025-3032
Leaking file descriptors from the fork server
Published 2025-04-01 · Modified
7.4EPSS 0.004
CVE-2016-1963
The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.
Published 2016-03-13 · Modified
7.4EPSS 0.003
CVE-2024-9403
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.
Published 2024-10-01 · Analyzed
7.3EPSS 0.004
CVE-2025-1936
Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents
Published 2025-03-04 · Modified
7.3EPSS 0.004
CVE-2025-1018
Fullscreen notification is not displayed when fullscreen is re-requested
Published 2025-02-04 · Modified
7.3EPSS 0.004
CVE-2025-10528
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component
Published 2025-09-16 · Modified
7.3EPSS 0.004
CVE-2025-14325
JIT miscompilation in the JavaScript Engine: JIT component
Published 2025-12-09 · Modified
7.3EPSS 0.003
CVE-2025-3029
URL Bar Spoofing via non-BMP Unicode characters
Published 2025-04-01 · Modified
7.3EPSS 0.003
CVE-2025-5272
Memory safety bugs fixed in Firefox 139 and Thunderbird 139
Published 2025-05-27 · Modified
7.3EPSS 0.003
CVE-2025-14332
Memory safety bugs fixed in Firefox 146 and Thunderbird 146
Published 2025-12-09 · Modified
7.3EPSS 0.003
CVE-2026-12318
Incorrect boundary conditions in the Libraries component in NSS
Published 2026-06-16 · Analyzed
7.3EPSS 0.003
CVE-2026-12324
Incorrect boundary conditions in the Graphics: CanvasWebGL component
Published 2026-06-16 · Analyzed
7.3EPSS 0.002
CVE-2004-2228
Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.
Published 2005-07-17 · Modified
7.2EPSS 0.004
CVE-2013-0799
Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and Thunderbird ESR 17.x before 17.0.5 on Windows allows local users to gain privileges via crafted arguments.
Published 2013-04-03 · Modified
7.2EPSS 0.004
CVE-2013-1700
The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location.
Published 2013-06-26 · Modified
7.2EPSS 0.004
CVE-2013-1706
Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.
Published 2013-08-07 · Modified
7.2EPSS 0.003
CVE-2013-1707
Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.
Published 2013-08-07 · Modified
7.2EPSS 0.003
CVE-2011-2980
Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows local users to gain privileges by leveraging write access in an unspecified directory to place a Trojan horse DLL that is loaded into the running Firefox process.
Published 2011-08-18 · Modified
7.2EPSS 0.003
CVE-2012-1942
The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain privileges by loading a DLL file in a privileged context.
Published 2012-06-05 · Modified
7.2EPSS 0.003
CVE-2007-2671
Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access.
Published 2007-05-14 · Modified
7.11 PoCEPSS 0.032
CVE-2016-1956
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
Published 2016-03-13 · Modified
7.1EPSS 0.024
CVE-2006-6502
Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Published 2006-12-20 · Modified
7.1EPSS 0.024
CVE-2009-0776
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
Published 2009-03-05 · Modified
7.1EPSS 0.016
CVE-2007-3072
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.
Published 2007-06-06 · Modified
7.1EPSS 0.016
CVE-2014-8643
Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.
Published 2015-01-14 · Modified
7.1EPSS 0.015
CVE-2007-5896
Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) file:/// URI.
Published 2007-11-08 · Modified
7.1EPSS 0.012
CVE-2021-29964
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Published 2021-06-24 · Modified
7.1EPSS 0.008
CVE-2022-22753
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Published 2022-12-22 · Modified
7.1EPSS 0.006
CVE-2022-42930
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.
Published 2022-12-22 · Modified
7.1EPSS 0.004
CVE-2018-12397
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
Published 2019-02-28 · Modified
7.1EPSS 0.004
← Prev49 / 84Next →