Mozilla
7,140 known vulnerabilities
Top Products
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly bein
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting
A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially ex
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerabi
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs s
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an emai
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScri
Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Fi
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bug
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. Thi
The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have e
The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affec
An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origi
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team r
Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory s
In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. T
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user conf
When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjun
SVG's <code><use></code> element could have been used to load unexpected content that could have executed script i
The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include
By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object
If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent pr
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of at
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming t
Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>,
In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scri
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This
While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fo
An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploi
Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefo
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it shoul
Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed un
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors d
When importing resources using Web Workers, error messages would distinguish the difference between <code>application/ja
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the
When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone nu
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connec
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been
By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute J
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so,
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write a
Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these b
Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon
By generally accepting and passing resource handles across processes, a compromised content process might have confused
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started