VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2026-0885
Use-after-free in the JavaScript: GC component
Published 2026-01-13 · Modified
6.5EPSS 0.004
CVE-2024-10941
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.
Published 2024-11-06 · Modified
6.5EPSS 0.004
CVE-2026-6770
Other issue in the Storage: IndexedDB component
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2024-3855
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
Published 2024-04-16 · Analyzed
6.5EPSS 0.004
CVE-2026-6764
Incorrect boundary conditions in the DOM: Device Interfaces component
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2025-8027
JavaScript engine only wrote partial return value to stack
Published 2025-07-22 · Modified
6.5EPSS 0.004
CVE-2025-8033
Incorrect JavaScript state machine for generators
Published 2025-07-22 · Modified
6.5EPSS 0.004
CVE-2024-4774
The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Modified
6.5EPSS 0.004
CVE-2022-45419
If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2022-38472
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2025-9181
Uninitialized memory in the JavaScript Engine component
Published 2025-08-19 · Modified
6.5EPSS 0.004
CVE-2025-6429
Incorrect parsing of URLs could have allowed embedding of youtube.com
Published 2025-06-24 · Modified
6.5EPSS 0.004
CVE-2026-8961
Spoofing issue in the Form Autofill component
Published 2026-05-19 · Analyzed
6.5EPSS 0.003
CVE-2023-23601
URL being dragged from cross-origin iframe into same tab triggers navigation
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2023-28164
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2023-23597
Logic bug in process allocation allowed to read arbitrary files
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2025-1938
Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
Published 2025-03-04 · Modified
6.5EPSS 0.003
CVE-2026-4728
Spoofing issue in the Privacy: Anti-Tracking component
Published 2026-03-24 · Modified
6.5EPSS 0.003
CVE-2024-11708
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
6.5EPSS 0.003
CVE-2023-29549
Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2025-1013
Potential opening of private browsing tabs in normal browsing windows
Published 2025-02-04 · Modified
6.5EPSS 0.003
CVE-2026-6763
Mitigation bypass in the File Handling component
Published 2026-04-21 · Analyzed
6.5EPSS 0.003
CVE-2025-3608
Race condition in nsHttpTransaction could lead to memory corruption
Published 2025-04-15 · Modified
6.5EPSS 0.003
CVE-2025-10532
Incorrect boundary conditions in the JavaScript: GC component
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-5271
Devtools' preview ignored CSP headers
Published 2025-05-27 · Modified
6.5EPSS 0.003
CVE-2025-4092
Memory safety bugs fixed in Firefox 138 and Thunderbird 138
Published 2025-04-29 · Modified
6.5EPSS 0.003
CVE-2025-10529
Same-origin policy bypass in the Layout component
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-10530
Spoofing issue in the WebAuthn component in Firefox for Android
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-3031
JIT optimization bug with different stack slot sizes
Published 2025-04-01 · Modified
6.5EPSS 0.003
CVE-2025-4086
Specially crafted filename could be used to obscure download type
Published 2025-04-29 · Modified
6.5EPSS 0.003
CVE-2023-37210
A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
Published 2023-07-05 · Modified
6.5EPSS 0.003
CVE-2024-9391
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
Published 2024-10-01 · Analyzed
6.5EPSS 0.003
CVE-2026-8951
Spoofing issue in the Toolbar component in Firefox for Android
Published 2026-05-19 · Analyzed
6.5EPSS 0.003
CVE-2024-9936
When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.
Published 2024-10-14 · Analyzed
6.5EPSS 0.003
CVE-2025-6431
The prompt in Firefox for Android that asks before opening a link in an external application could be bypassed
Published 2025-06-24 · Modified
6.5EPSS 0.003
CVE-2026-6755
Mitigation bypass in the DOM: postMessage component
Published 2026-04-21 · Analyzed
6.5EPSS 0.002
CVE-2025-9183
Spoofing issue in the Address Bar component
Published 2025-08-19 · Modified
6.5EPSS 0.002
CVE-2026-12302
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2022-34471
When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.
Published 2022-12-22 · Modified
6.5EPSS 0.002
CVE-2026-12309
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
6.5EPSS 0.002
← Prev53 / 73Next →