Mozilla
7,140 known vulnerabilities
Top Products
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affecte
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, a
When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. Th
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure s
Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially
The WebChannel API, which is used to transport various information across processes, did not check the sending principal
Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, maki
Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Ut
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segme
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specif
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authenticatio
Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored da
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could hav
Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to use
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mo
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?"
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature ver
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resultin
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS thr
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Wind
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possib
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corrupti
In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoe
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convi
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects T
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. Th
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in link
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash.
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the brows
Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefo
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox <
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and d
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vu
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable cras
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vu
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in so
When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially lea
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that w
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these b
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started