Mozilla
7,140 known vulnerabilities
Top Products
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespectiv
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses pri
Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when
When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firef
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed ev
Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corru
A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to
Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affe
Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affe
When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an atta
Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usual
When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prev
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to
If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unp
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on
A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary m
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata s
A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the co
When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that w
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to ope
Signatures are written to disk before and read during verification, which might be subject to a race condition when a ma
Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed ev
Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking re
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash.
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy preven
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been inte
A compromised content process could have performed session history manipulations it should not have been able to due to
A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and gr
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS pag
Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We p
By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, res
When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vul
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker c
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may crea
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform ou
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to i
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chac
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user
Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corru
Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a c
If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the D
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started