Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Mozilla

7,140 known vulnerabilities

444
CRITICAL
788
HIGH
788
MEDIUM
19
LOW

Top Products

firefox 1837 thunderbird 1183 firefox esr 435 firefox mobile 60 firefox focus 20 focus 16 network security services 16 thunderbird esr 14 bleach 5 vpn 4
2,039 CVEs · Page 27/41
6.5
CVE-2021-23984

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address

6.5
CVE-2021-23983

By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applie

6.5
CVE-2021-23982

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network'

8.1
CVE-2021-23981

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack i

6.1
CVE-2021-20628

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a

7.4
CVE-2021-21354

Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things

8.8
CVE-2021-23979

Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corru

8.8
CVE-2021-23978

Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evi

8.8
CVE-2021-23965

Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corru

8.8
CVE-2021-23964

Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evi

5.3
CVE-2021-23977

Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read

4.3
CVE-2021-23963

When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user in

8.8
CVE-2021-23962

Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable cras

7.4
CVE-2021-23961

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an in

8.8
CVE-2021-23960

Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exp

6.1
CVE-2021-23959

An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the addre

6.5
CVE-2021-23958

The browser could have been confused into transferring a screen sharing state into another tab, which would leak uninten

7.4
CVE-2021-23957

Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: Thi

6.5
CVE-2021-23956

An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading

6.1
CVE-2021-23955

The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to c

8.8
CVE-2021-23954

Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading

4.3
CVE-2021-23953

If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin informatio

8.1
CVE-2021-23976

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file

6.5
CVE-2021-23975

The developer page about:memory has a Measure function for exploring what object types the browser has allocated and the

6.1
CVE-2021-23974

The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to b

6.5
CVE-2021-23973

When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the conten

8.8
CVE-2021-23972

One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://[email protected]

6.5
CVE-2021-23971

When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy

6.5
CVE-2021-23970

Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm

4.3
CVE-2021-23969

As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure tha

4.3
CVE-2021-23968

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported

4.3
CVE-2020-16012

Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cr

8.8
CVE-2020-35114

Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corru

8.8
CVE-2020-35113

Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evi

8.8
CVE-2020-35112

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there wa

4.3
CVE-2020-35111

When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not trigg

6.1
CVE-2020-26979

When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes ca

6.1
CVE-2020-26978

Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network'

6.5
CVE-2020-26977

By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab wh

6.5
CVE-2020-26976

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service wo

6.5
CVE-2020-26975

When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary header

8.8
CVE-2020-26974

When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wron

8.8
CVE-2020-26973

Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been us

9.8
CVE-2020-26972

The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they

8.8
CVE-2020-26971

Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video d

8.8
CVE-2020-26970

When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended t

8.8
CVE-2020-26969

Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corru

8.8
CVE-2020-26968

Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evi

6.5
CVE-2020-26967

When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into in

6.5
CVE-2020-26966

Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a

Frequently Asked Questions

How many CVEs affect Mozilla?

Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Mozilla vulnerabilities?

Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Mozilla vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Mozilla Vulnerabilities

CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.

Get Started