Mozilla
7,140 known vulnerabilities
Top Products
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run atta
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in s
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-ext
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-contro
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resu
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resul
A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen
Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that w
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website
When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable na
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have
If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a fi
When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual lo
The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potenti
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within
Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorre
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private brows
Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to thes
By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potenti
Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume
Memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that w
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruptio
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrom
When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This
When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shippe
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path t
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-fre
Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resu
An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in t
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path
When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not co
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser in
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensio
The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Some of these bugs s
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6
A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromS
Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` w
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src head
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to webs
Per origin notification permissions were being stored in a way that didn't take into account what browsing context the p
When copying a network request from the developer tools panel as a curl command the output was not being properly saniti
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing f
A compromised web child process could disable web security opening restrictions, leading to a new child process being sp
Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable cr
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started