Mozilla
7,140 known vulnerabilities
Top Products
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leak
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context c
Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<b
When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected elem
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerab
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the recei
When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to
If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute t
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firef
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerabilit
An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was ze
A website that had permission to access the microphone could record audio without the audio notification being shown. Th
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs s
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates tha
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability
When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this co
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus le
When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of prev
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to une
Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firef
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evid
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti
In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number
Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own conte
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applica
The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed
SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if atta
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect h
The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></code> tags; however i
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, r
When downloading an update for an addon, the downloaded addon update's version was not verified to match the version sel
Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affec
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to b
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This
Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported m
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs presen
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header.
If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnera
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so by
Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. Th
An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further
On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started