VendorsMozillafirefoxany version
Vulnerabilities

Mozilla Firefox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2913CVEs
CVE-2024-53976
Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
Published 2024-11-26 · Analyzed
5.4EPSS 0.003
CVE-2023-37455
The permission request prompt from the site in the background tab was overlaid on top of the site in the foreground tab. This vulnerability affects Firefox for iOS < 115.
Published 2023-07-12 · Modified
5.4EPSS 0.003
CVE-2026-2804
Use-after-free in the JavaScript: WebAssembly component
Published 2026-02-24 · Modified
5.4EPSS 0.003
CVE-2026-84125
Use-after-free in the DOM: Core & HTML component
Published 2026-09-01 · Analyzed
5.4EPSS 0.003
CVE-2026-84118
Use-after-free in the JavaScript: GC component
Published 2026-09-01 · Analyzed
5.4EPSS 0.003
CVE-2024-53975
Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.
Published 2024-11-26 · Modified
5.4EPSS 0.003
CVE-2025-10531
Mitigation bypass in the Web Compatibility: Tooling component
Published 2025-09-16 · Modified
5.4EPSS 0.003
CVE-2025-5267
Clickjacking vulnerability could have led to leaking saved payment card details
Published 2025-05-27 · Modified
5.4EPSS 0.003
CVE-2026-9309
Arbitrary JavaScript execution in internal pages via Reader View JSON-LD injection
Published 2026-06-01 · Analyzed
5.4EPSS 0.003
CVE-2026-9308
Arbitrary JavaScript execution in Reader View due to wrong HTML replacement order
Published 2026-06-01 · Analyzed
5.4EPSS 0.003
CVE-2026-6774
Mitigation bypass in the DOM: Security component
Published 2026-04-21 · Analyzed
5.4EPSS 0.003
CVE-2026-9078
Firefox iOS RTL Domain Rendering Issue in Link Preview
Published 2026-05-25 · Undergoing Analysis
5.4EPSS 0.003
CVE-2025-27426
Firefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error page
Published 2025-03-04 · Modified
5.4EPSS 0.002
CVE-2025-54144
Internal Firefox open-text URL scheme allowed loading of arbitrary URLs
Published 2025-08-19 · Modified
5.4EPSS 0.002
CVE-2026-84120
Use-after-free in the Audio/Video component
Published 2026-09-01 · Analyzed
5.4EPSS 0.002
CVE-2026-84122
Use-after-free in the Audio/Video component
Published 2026-09-01 · Analyzed
5.4EPSS 0.002
CVE-2026-12322
Clickjacking issue in the Widget: Gtk component
Published 2026-06-16 · Analyzed
5.4EPSS 0.002
CVE-2026-84124
Use-after-free in the DOM: Core & HTML component
Published 2026-09-01 · Analyzed
5.4EPSS 0.002
CVE-2026-74974
Same-origin policy bypass in the Graphics: ImageLib component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2026-12323
Spoofing issue in the DOM: Core & HTML component
Published 2026-06-16 · Analyzed
5.4EPSS 0.002
CVE-2026-74967
Same-origin policy bypass in the Audio/Video: Playback component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2026-74963
Same-origin policy bypass in the Networking: Cookies component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2026-12330
Incorrect boundary conditions in the Internationalization component
Published 2026-06-16 · Analyzed
5.4EPSS 0.002
CVE-2026-12321
JIT miscompilation in the JavaScript: WebAssembly component
Published 2026-06-16 · Analyzed
5.4EPSS 0.002
CVE-2026-74970
Site isolation issue in the Graphics component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2026-74968
Site isolation issue in the Graphics: WebRender component
Published 2026-08-18 · Analyzed
5.4EPSS 0.002
CVE-2016-7152
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Published 2016-09-06 · Modified
5.3EPSS 0.140
CVE-2016-7153
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Published 2016-09-06 · Modified
5.3EPSS 0.140
CVE-2017-5415
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
Published 2018-06-11 · Modified
5.31 PoCEPSS 0.126
CVE-2019-7317
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
Published 2019-02-04 · Modified
5.3EPSS 0.094
CVE-2025-0244
Address bar spoofing using an invalid protocol scheme on Firefox for Android
Published 2025-01-07 · Modified
5.3EPSS 0.065
CVE-2017-5462
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
5.3EPSS 0.026
CVE-2017-5405
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Published 2018-06-11 · Modified
5.3EPSS 0.026
CVE-2017-5408
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Published 2018-06-11 · Modified
5.3EPSS 0.026
CVE-2017-5383
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Published 2018-06-11 · Modified
5.3EPSS 0.025
CVE-2018-5117
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Published 2018-06-11 · Modified
5.3EPSS 0.024
CVE-2018-5168
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Published 2018-06-11 · Modified
5.3EPSS 0.024
CVE-2019-11717
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Published 2019-07-23 · Modified
5.3EPSS 0.021
CVE-2018-12403
If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63.
Published 2019-02-28 · Modified
5.3EPSS 0.021
CVE-2017-7764
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be mixed with Latin characters in the "moderately restrictive" IDN profile. We have changed Firefox behavior to match the upcoming Unicode version 10.0 which removes this category and treats them as "Limited Use Scripts.". This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Published 2018-06-11 · Modified
5.3EPSS 0.020
← Prev59 / 73Next →