VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2025-1938
Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
Published 2025-03-04 · Modified
6.5EPSS 0.003
CVE-2026-4728
Spoofing issue in the Privacy: Anti-Tracking component
Published 2026-03-24 · Modified
6.5EPSS 0.003
CVE-2024-11708
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Published 2024-11-26 · Analyzed
6.5EPSS 0.003
CVE-2023-29549
Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Published 2023-06-02 · Modified
6.5EPSS 0.003
CVE-2025-1013
Potential opening of private browsing tabs in normal browsing windows
Published 2025-02-04 · Modified
6.5EPSS 0.003
CVE-2026-6763
Mitigation bypass in the File Handling component
Published 2026-04-21 · Analyzed
6.5EPSS 0.003
CVE-2025-3608
Race condition in nsHttpTransaction could lead to memory corruption
Published 2025-04-15 · Modified
6.5EPSS 0.003
CVE-2025-10532
Incorrect boundary conditions in the JavaScript: GC component
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-5271
Devtools' preview ignored CSP headers
Published 2025-05-27 · Modified
6.5EPSS 0.003
CVE-2025-4092
Memory safety bugs fixed in Firefox 138 and Thunderbird 138
Published 2025-04-29 · Modified
6.5EPSS 0.003
CVE-2025-10529
Same-origin policy bypass in the Layout component
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-10530
Spoofing issue in the WebAuthn component in Firefox for Android
Published 2025-09-16 · Modified
6.5EPSS 0.003
CVE-2025-3031
JIT optimization bug with different stack slot sizes
Published 2025-04-01 · Modified
6.5EPSS 0.003
CVE-2025-4086
Specially crafted filename could be used to obscure download type
Published 2025-04-29 · Modified
6.5EPSS 0.003
CVE-2023-37210
A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
Published 2023-07-05 · Modified
6.5EPSS 0.003
CVE-2024-9391
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
Published 2024-10-01 · Analyzed
6.5EPSS 0.003
CVE-2026-8951
Spoofing issue in the Toolbar component in Firefox for Android
Published 2026-05-19 · Analyzed
6.5EPSS 0.003
CVE-2024-9936
When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.
Published 2024-10-14 · Analyzed
6.5EPSS 0.003
CVE-2025-9183
Spoofing issue in the Address Bar component
Published 2025-08-19 · Modified
6.5EPSS 0.003
CVE-2025-6431
The prompt in Firefox for Android that asks before opening a link in an external application could be bypassed
Published 2025-06-24 · Modified
6.5EPSS 0.003
CVE-2026-12302
Mitigation bypass in the DOM: Security component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2026-6755
Mitigation bypass in the DOM: postMessage component
Published 2026-04-21 · Analyzed
6.5EPSS 0.002
CVE-2022-34471
When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.
Published 2022-12-22 · Modified
6.5EPSS 0.002
CVE-2025-11716
Sandboxed iframes allowed links to open in external apps (Android only)
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-12309
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
6.5EPSS 0.002
CVE-2026-8706
Sensitive user data could be leaked to other applications through Reader mode
Published 2026-05-19 · Undergoing Analysis
6.5EPSS 0.002
CVE-2022-22757
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.
Published 2022-12-22 · Modified
6.5EPSS 0.002
CVE-2025-11711
Some non-writable Object properties could be modified
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-12325
Denial-of-service in the Graphics: ImageLib component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2025-55028
JavaScript alerts could impede UI interaction or allow denial of service attacks
Published 2025-08-19 · Modified
6.5EPSS 0.002
CVE-2025-9186
Spoofing issue in the Address Bar component of Firefox Focus for Android
Published 2025-08-19 · Modified
6.5EPSS 0.002
CVE-2025-11718
Address bar could be spoofed on Android using visibilitychange
Published 2025-10-14 · Modified
6.5EPSS 0.002
CVE-2026-24868
Mitigation bypass in the Privacy: Anti-Tracking component
Published 2026-01-27 · Modified
6.5EPSS 0.002
CVE-2026-12319
Denial-of-service in the Audio/Video: Playback component
Published 2026-06-16 · Analyzed
6.5EPSS 0.002
CVE-2025-14744
Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS
Published 2025-12-18 · Undergoing Analysis
6.5EPSS 0.002
CVE-2026-16403
Spoofing issue in the Address Bar component
Published 2026-07-21 · Analyzed
6.5EPSS 0.002
CVE-2025-14331
Same-origin policy bypass in the Request Handling component
Published 2025-12-09 · Modified
6.5EPSS 0.002
CVE-2025-23109
Address bar spoofing on iOS using long hostnames
Published 2025-01-11 · Modified
6.5EPSS 0.002
CVE-2025-4088
Cross-site request forgery via storage access API redirects
Published 2025-04-29 · Modified
6.5EPSS 0.002
CVE-2026-16397
Clickjacking issue in the WebExtensions component in Firefox for Android
Published 2026-07-21 · Analyzed
6.5EPSS 0.002
← Prev59 / 84Next →