Mozilla
7,140 known vulnerabilities
Top Products
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing info
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these b
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.
Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbi
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunder
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thund
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fi
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, F
Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption a
Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.
Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunder
Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these b
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.
Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142
Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is al
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack.
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerab
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. T
Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially result
Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the conten
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An att
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the cont
Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. T
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and all
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that lev
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitra
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictio
Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption a
Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Fir
Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these b
In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set o
Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebindin
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Fire
Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunder
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fix
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, howeve
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started