Mozilla
7,140 known vulnerabilities
Top Products
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerab
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerabi
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidenc
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 1
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerabilit
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allo
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as t
When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly w
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that w
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidenc
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the ad
A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Fire
By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentiall
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an asserti
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another sit
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file w
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if click
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were fun
In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant.
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new
The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This
Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that w
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidenc
A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability a
An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid
The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This
An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vuln
A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have tri
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability af
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascr
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting per
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the win
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to pot
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite anot
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability a
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that w
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory c
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows
The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and l
An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently tra
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by
It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects F
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started