VendorsMozillafirefoxall versions
Vulnerabilities

Mozilla Firefox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3337CVEs
CVE-2024-3862
The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.
Published 2024-04-16 · Analyzed
5.3EPSS 0.004
CVE-2024-8388
Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser UI if the sudden appearance of the prompt distracted the user from noticing the visual transition happening behind the prompt. These notifications now use the Android Toast feature. *This bug only affects Firefox on Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 130.
Published 2024-09-03 · Modified
5.3EPSS 0.004
CVE-2026-6765
Information disclosure in the Form Autofill component
Published 2026-04-21 · Analyzed
5.3EPSS 0.004
CVE-2026-0888
Information disclosure in the XML component
Published 2026-01-13 · Modified
5.3EPSS 0.004
CVE-2026-6779
Other issue in the JavaScript Engine component
Published 2026-04-21 · Analyzed
5.3EPSS 0.003
CVE-2026-6775
Incorrect boundary conditions in the WebRTC component
Published 2026-04-21 · Analyzed
5.3EPSS 0.003
CVE-2025-4090
Leaked library paths in Thunderbird for Android
Published 2025-04-29 · Modified
5.3EPSS 0.003
CVE-2024-9395
A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
Published 2024-10-01 · Analyzed
5.3EPSS 0.003
CVE-2025-8041
Incorrect URL truncation in Firefox for Android
Published 2025-08-19 · Modified
5.3EPSS 0.003
CVE-2025-3035
Tab title disclosure across pages when using AI chatbot
Published 2025-04-01 · Modified
5.3EPSS 0.003
CVE-2026-12306
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-12307
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-12308
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-12300
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-12301
Memory safety bug fixed in Firefox 152
Published 2026-06-16 · Modified
5.3EPSS 0.003
CVE-2026-6777
Other issue in the Networking: DNS component
Published 2026-04-21 · Analyzed
5.3EPSS 0.002
CVE-2006-0295
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
Published 2006-02-02 · Modified
5.13 PoCEPSS 0.713
CVE-2006-1993
Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.
Published 2006-04-25 · Modified
5.11 PoCEPSS 0.540
CVE-2005-1476
Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.
Published 2005-05-09 · Modified
5.11 PoCEPSS 0.167
CVE-2005-1477
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.
Published 2005-05-09 · Modified
5.11 PoCEPSS 0.152
CVE-2005-0399
Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.
Published 2005-03-24 · Modified
5.1EPSS 0.151
CVE-2005-0527
Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."
Published 2005-02-25 · Modified
5.1EPSS 0.073
CVE-2010-0166
The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.
Published 2010-03-25 · Modified
5.11 PoCEPSS 0.069
CVE-2005-2262
Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."
Published 2005-07-13 · Modified
5.11 PoCEPSS 0.065
CVE-2015-0813
Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.
Published 2015-04-01 · Modified
5.1EPSS 0.053
CVE-2006-3803
Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code by causing the garbage collector to delete a temporary variable while it is still being used during the creation of a new Function object.
Published 2006-07-27 · Modified
5.1EPSS 0.045
CVE-2006-0297
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
Published 2006-02-02 · Modified
5.1EPSS 0.039
CVE-2011-1179
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.
Published 2011-04-18 · Modified
5.1EPSS 0.039
CVE-2005-0401
FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."
Published 2005-03-24 · Modified
5.1EPSS 0.033
CVE-2010-0179
Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.
Published 2010-04-05 · Modified
5.1EPSS 0.033
CVE-2005-0230
Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."
Published 2005-02-10 · Modified
5.1EPSS 0.033
CVE-2009-0356
Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs. NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.
Published 2009-02-04 · Modified
5.1EPSS 0.032
CVE-2015-4507
The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.
Published 2015-09-24 · Modified
5.1EPSS 0.032
CVE-2005-1160
The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
Published 2005-04-18 · Modified
5.1EPSS 0.027
CVE-2006-1942
Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."
Published 2006-04-20 · Modified
5.1EPSS 0.025
CVE-2008-5015
Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.
Published 2008-11-13 · Modified
5.1EPSS 0.022
CVE-2006-2784
The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.
Published 2006-06-02 · Modified
5.1EPSS 0.018
CVE-2025-0243
Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6
Published 2025-01-07 · Modified
5.1EPSS 0.003
CVE-2025-4089
Potential local code execution in "copy as cURL" command
Published 2025-04-29 · Modified
5.1EPSS 0.002
CVE-2005-2265
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.
Published 2005-07-13 · Modified
5.02 PoCEPSS 0.681
← Prev68 / 84Next →