Mozilla
7,140 known vulnerabilities
Top Products
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a spe
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a d
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permiss
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain obj
A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in th
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtoo
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability aff
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full scr
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigation
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a t
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a p
Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Fo
Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that w
Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing th
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of anot
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusi
The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that
Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for th
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects F
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects F
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vuln
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on a
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into gr
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Fir
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak s
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and
Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a si
A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into gr
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, F
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulner
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spo
Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption a
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This cause
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affec
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to p
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerabilit
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewp
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notificati
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started