Mozilla
Mozilla Firefox: vulnerabilities and CVEs
Mozilla Firefox has 3,453 published vulnerabilities, 607 of them in the last 12 months. 500 are rated critical and 15 are listed by CISA as actively exploited.
CVEs3,453
Last 12 months607
Critical500
Actively exploited15
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2010-3765 | Critical (9.8) | 83% | ⚠ Active exploitation | Oct 28, 2010 | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute… |
| CVE-2024-9680 | Critical (9.8) | 23% | ⚠ Active exploitation | Oct 9, 2024 | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability… |
| CVE-2023-5217 | High (8.8) | 49% | ⚠ Active exploitation | Sep 28, 2023 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security… |
| CVE-2023-4863 | High (8.8) | 100% | ⚠ Active exploitation | Sep 12, 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
| CVE-2016-9079 | High (7.5) | 87% | ⚠ Active exploitation | Jun 11, 2018 | A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects… |
| CVE-2015-4495 | High (8.8) | 69% | ⚠ Active exploitation | Aug 8, 2015 | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via… |
| CVE-2019-11708 | Critical (10) | 56% | ⚠ Active exploitation | Jul 23, 2019 | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process.… |
| CVE-2019-11707 | High (8.8) | 38% | ⚠ Active exploitation | Jul 23, 2019 | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This… |
| CVE-2013-1690 | High (8.8) | 69% | ⚠ Active exploitation | Jun 26, 2013 | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which… |
| CVE-2022-26486 | Critical (9.6) | 2.3% | ⚠ Active exploitation | Dec 22, 2022 | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2,… |
| CVE-2022-26485 | High (8.8) | 14% | ⚠ Active exploitation | Dec 22, 2022 | Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR <… |
| CVE-2013-1675 | Medium (6.5) | 6.7% | ⚠ Active exploitation | May 16, 2013 | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and… |
| CVE-2019-17026 | High (8.8) | 46% | ⚠ Active exploitation | Mar 2, 2020 | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR <… |
| CVE-2020-6820 | High (8.1) | 7.1% | ⚠ Active exploitation | Apr 24, 2020 | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0,… |
| CVE-2020-6819 | High (8.1) | 3.0% | ⚠ Active exploitation | Apr 24, 2020 | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird <… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-96869 | Medium (4.3) | 0.21% | — | Sep 29, 2026 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. |
| CVE-2026-100832 | High (8.8) | 0.26% | — | Sep 29, 2026 | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 140.17, Thunderbird 153.4, Firefox ESR 115.42, and Firefox ESR 140.17. |
| CVE-2026-100831 | High (8.8) | 0.25% | — | Sep 29, 2026 | Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100830 | Unscored | 0.15% | — | Sep 29, 2026 | Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100829 | Unscored | 0.15% | — | Sep 29, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100828 | Unscored | 0.15% | — | Sep 29, 2026 | Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100826 | Medium (6.5) | 0.23% | — | Sep 29, 2026 | Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100825 | High (8.8) | 0.25% | — | Sep 29, 2026 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100824 | High (8.8) | 0.24% | — | Sep 29, 2026 | Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100822 | Medium (5.4) | 0.24% | — | Sep 29, 2026 | Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100821 | Unscored | 0.16% | — | Sep 29, 2026 | Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR… |
| CVE-2026-100820 | High (8.8) | 0.25% | — | Sep 29, 2026 | Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. |
| CVE-2026-100819 | Critical (9.6) | 0.28% | — | Sep 29, 2026 | Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and… |
| CVE-2026-100818 | Critical (9.6) | 0.28% | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. |
| CVE-2026-100817 | Unscored | 0.15% | — | Sep 29, 2026 | Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. |
| CVE-2026-100816 | Unscored | 0.15% | — | Sep 29, 2026 | Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100815 | High (8.8) | 0.25% | — | Sep 29, 2026 | Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100814 | High (8.8) | 0.26% | — | Sep 29, 2026 | Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100813 | High (8.8) | 0.25% | — | Sep 29, 2026 | Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. |
| CVE-2026-100812 | Medium (6.5) | 0.29% | — | Sep 29, 2026 | Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100811 | Critical (9.6) | 0.28% | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. |
| CVE-2026-100810 | Unscored | 0.15% | — | Sep 29, 2026 | Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. |
| CVE-2026-100809 | Unscored | 0.16% | — | Sep 29, 2026 | Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100808 | Unscored | 0.16% | — | Sep 29, 2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100807 | High (8.8) | 0.25% | — | Sep 29, 2026 | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. |
| CVE-2026-100806 | Medium (4.3) | 0.27% | — | Sep 29, 2026 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. |
| CVE-2026-100805 | High (7.5) | 0.22% | — | Sep 29, 2026 | Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. |
| CVE-2026-100804 | Critical (9.6) | 0.30% | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. |
| CVE-2026-100803 | Unscored | 0.17% | — | Sep 29, 2026 | Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR… |
| CVE-2026-100802 | Medium (4.3) | 0.26% | — | Sep 29, 2026 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. |