VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2026-12309
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
6.5EPSS 0.002
CVE-2026-8706
Sensitive user data could be leaked to other applications through Reader mode
Published 2026-05-19 · Undergoing Analysis
6.5EPSS 0.002
CVE-2022-22757
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.
Published 2022-12-22 · Modified
6.5EPSS 0.002
CVE-2025-11711
Some non-writable Object properties could be modified
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-12325
Denial-of-service in the Graphics: ImageLib component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2025-55028
JavaScript alerts could impede UI interaction or allow denial of service attacks
Published 2025-08-19 · Modified
6.5EPSS 0.002
CVE-2026-24868
Mitigation bypass in the Privacy: Anti-Tracking component
Published 2026-01-27 · Modified
6.5EPSS 0.002
CVE-2025-9186
Spoofing issue in the Address Bar component of Firefox Focus for Android
Published 2025-08-19 · Modified
6.5EPSS 0.002
CVE-2025-11718
Address bar could be spoofed on Android using visibilitychange
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-12319
Denial-of-service in the Audio/Video: Playback component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2025-14744
Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS
Published 2025-12-18 · Undergoing Analysis
6.5EPSS 0.002
CVE-2026-16403
Spoofing issue in the Address Bar component
Published 2026-07-21 · Analyzed
6.5EPSS 0.002
CVE-2025-14331
Same-origin policy bypass in the Request Handling component
Published 2025-12-09 · Modified
6.5EPSS 0.002
CVE-2025-23109
Address bar spoofing on iOS using long hostnames
Published 2025-01-11 · Modified
6.5EPSS 0.002
CVE-2025-4088
Cross-site request forgery via storage access API redirects
Published 2025-04-29 · Modified
6.5EPSS 0.002
CVE-2026-8971
Same-origin policy bypass in the Networking: JAR component
Published 2026-05-19 · Analyzed
6.5EPSS 0.002
CVE-2026-16397
Clickjacking issue in the WebExtensions component in Firefox for Android
Published 2026-07-21 · Analyzed
6.5EPSS 0.002
CVE-2026-3846
Same-origin policy bypass in the CSS Parsing and Computation component
Published 2026-03-10 · Modified
6.5EPSS 0.002
CVE-2015-4504
The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.
Published 2015-09-24 · Modified
6.4EPSS 0.035
CVE-2015-4512
gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS element to trigger 2D rendering.
Published 2015-09-24 · Modified
6.4EPSS 0.035
CVE-2012-4196
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
Published 2012-10-29 · Modified
6.4EPSS 0.033
CVE-2015-4520
Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.
Published 2015-09-24 · Modified
6.4EPSS 0.031
CVE-2014-1577
The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via an invalid custom waveform that triggers a calculation of a negative frequency value.
Published 2014-10-15 · Modified
6.4EPSS 0.029
CVE-2015-0811
The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.
Published 2015-04-01 · Modified
6.4EPSS 0.028
CVE-2005-2706
Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.
Published 2005-09-23 · Modified
6.4EPSS 0.028
CVE-2014-1506
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.
Published 2014-03-19 · Modified
6.4EPSS 0.023
CVE-2024-6600
Memory corruption in WebGL API
Published 2024-07-09 · Modified
6.3EPSS 0.004
CVE-2024-6610
Form validation popups could block exiting full-screen mode
Published 2024-07-09 · Modified
6.3EPSS 0.003
CVE-2026-6757
Invalid pointer in the JavaScript: WebAssembly component
Published 2026-04-21 · Analyzed
6.3EPSS 0.003
CVE-2026-6762
Spoofing issue in the DOM: Core & HTML component
Published 2026-04-21 · Analyzed
6.3EPSS 0.003
CVE-2026-13356
Interrupted navigation could allow address bar origin spoofing in Firefox for iOS
Published 2026-07-06 · Analyzed
6.3EPSS 0.002
CVE-2013-1726
Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
Published 2013-09-18 · Modified
6.2EPSS 0.003
CVE-2024-3860
An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.
Published 2024-04-16 · Analyzed
6.2EPSS 0.002
CVE-2025-10536
Information disclosure in the Networking: Cache component
Published 2025-09-16 · Modified
6.2EPSS 0.002
CVE-2024-8897
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 130.0.1.
Published 2024-09-17 · Modified
6.1EPSS 0.076
CVE-2020-1933
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
Published 2020-01-28 · Modified
6.1EPSS 0.028
CVE-2020-6798
If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.
Published 2020-03-02 · Modified
6.1EPSS 0.021
CVE-2019-17016
When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Published 2020-01-08 · Modified
6.1EPSS 0.020
CVE-2019-17022
When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Published 2020-01-08 · Modified
6.1EPSS 0.020
CVE-2016-9895
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Published 2018-06-11 · Modified
6.1EPSS 0.018
← Prev54 / 73Next →