VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2023-6211
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.
Published 2023-11-21 · Modified
6.5EPSS 0.005
CVE-2023-23600
Notification permissions persisted between Normal and Private Browsing on Android
Published 2023-06-02 · Modified
6.5EPSS 0.005
CVE-2023-37456
The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.
Published 2023-07-12 · Modified
6.5EPSS 0.005
CVE-2007-5967
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
Published 2021-05-17 · Modified
6.5EPSS 0.005
CVE-2020-15682
When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.
Published 2020-10-22 · Modified
6.5EPSS 0.005
CVE-2024-1556
The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123.
Published 2024-02-20 · Analyzed
6.5EPSS 0.005
CVE-2023-29547
When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Published 2023-06-02 · Modified
6.5EPSS 0.005
CVE-2024-11706
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
6.5EPSS 0.005
CVE-2022-36317
When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.
Published 2022-12-22 · Modified
6.5EPSS 0.005
CVE-2023-23604
Creation of duplicate SystemPrincipal from less secure contexts
Published 2023-06-02 · Modified
6.5EPSS 0.005
CVE-2025-1934
Unexpected GC during RegExp bailout processing
Published 2025-03-04 · Modified
6.5EPSS 0.005
CVE-2025-1414
Memory safety bugs fixed in Firefox 135.0.1
Published 2025-02-18 · Modified
6.5EPSS 0.005
CVE-2023-29544
If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Published 2023-06-02 · Modified
6.5EPSS 0.005
CVE-2026-74945
Information disclosure in the Graphics: Text component
Published 2026-08-18 · Analyzed
6.5EPSS 0.004
CVE-2026-74948
Information disclosure in the Graphics component
Published 2026-08-18 · Analyzed
6.5EPSS 0.004
CVE-2025-0246
Address bar spoofing using an invalid protocol scheme on Firefox for Android
Published 2025-01-07 · Modified
6.5EPSS 0.004
CVE-2024-7531
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
Published 2024-08-06 · Modified
6.5EPSS 0.004
CVE-2021-23986
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.
Published 2021-03-31 · Modified
6.5EPSS 0.004
CVE-2022-31743
Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2024-0754
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.
Published 2024-01-23 · Modified
6.5EPSS 0.004
CVE-2026-74976
JIT miscompilation in the JavaScript Engine: JIT component
Published 2026-08-18 · Analyzed
6.5EPSS 0.004
CVE-2022-38475
An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not written to an invalid memory address. This vulnerability affects Firefox < 104.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2023-4580
Push notifications saved to disk unencrypted
Published 2023-09-11 · Modified
6.5EPSS 0.004
CVE-2024-0752
A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122.
Published 2024-01-23 · Modified
6.5EPSS 0.004
CVE-2026-0885
Use-after-free in the JavaScript: GC component
Published 2026-01-13 · Modified
6.5EPSS 0.004
CVE-2024-10941
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.
Published 2024-11-06 · Modified
6.5EPSS 0.004
CVE-2026-6770
Other issue in the Storage: IndexedDB component
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2024-3855
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
Published 2024-04-16 · Analyzed
6.5EPSS 0.004
CVE-2026-6764
Incorrect boundary conditions in the DOM: Device Interfaces component
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2025-8027
JavaScript engine only wrote partial return value to stack
Published 2025-07-22 · Modified
6.5EPSS 0.004
CVE-2025-8033
Incorrect JavaScript state machine for generators
Published 2025-07-22 · Modified
6.5EPSS 0.004
CVE-2024-4774
The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.
Published 2024-05-14 · Modified
6.5EPSS 0.004
CVE-2022-45419
If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2022-38472
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
Published 2022-12-22 · Modified
6.5EPSS 0.004
CVE-2025-9181
Uninitialized memory in the JavaScript Engine component
Published 2025-08-19 · Modified
6.5EPSS 0.004
CVE-2025-6429
Incorrect parsing of URLs could have allowed embedding of youtube.com
Published 2025-06-24 · Modified
6.5EPSS 0.004
CVE-2026-8961
Spoofing issue in the Form Autofill component
Published 2026-05-19 · Analyzed
6.5EPSS 0.003
CVE-2023-23601
URL being dragged from cross-origin iframe into same tab triggers navigation
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2023-28164
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2023-23597
Logic bug in process allocation allowed to read arbitrary files
Published 2023-06-02 · Modified
6.5EPSS 0.003
← Prev58 / 84Next →