Mozilla
7,140 known vulnerabilities
Top Products
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and d
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certif
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certific
open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/M
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags s
bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerabili
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Fire
Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety
A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firef
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploita
A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*:
Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team re
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs p
By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a use
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious ext
Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject marku
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipb
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability af
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some o
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of t
If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server th
If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the brow
Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers bei
Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing
When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink
Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the Se
The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> m
Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seein
If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred,
If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while refere
Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free a
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for
Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firef
Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk.
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUt
If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may p
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirec
Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reporte
During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially ex
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started