Mozilla
7,140 known vulnerabilities
Top Products
Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption a
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not hav
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was inval
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in
When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correc
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. Th
The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affec
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's de
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects M
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Fir
Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption a
Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerab
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption a
Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bu
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leak
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user in
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into
Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin lea
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder
Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. Th
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attach
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the fil
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address t
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating be
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and
Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption a
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat.
Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into us
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitr
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null c
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user int
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow c
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vul
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by man
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only t
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started