Mozilla
7,140 known vulnerabilities
Top Products
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garba
A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulne
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection st
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to cre
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protectio
If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that w
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence
Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption a
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or po
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissi
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjackin
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experience
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue onl
Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointe
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *N
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email mess
Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website,
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. Th
Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the cur
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external
Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that w
The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and und
When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulne
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional header
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user'
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potenti
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another we
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in a
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the pag
Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox
A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This c
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Fi
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started