Mozilla
7,140 known vulnerabilities
Top Products
A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address
By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applie
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network'
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack i
Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a
Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things
Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corru
Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evi
Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corru
Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evi
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read
When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user in
Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable cras
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an in
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exp
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the addre
The browser could have been confused into transferring a screen sharing state into another tab, which would leak uninten
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: Thi
An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading
The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to c
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin informatio
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file
The developer page about:memory has a Measure function for exploring what object types the browser has allocated and the
The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to b
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the conten
One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://[email protected]
When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy
Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure tha
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cr
Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corru
Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evi
If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there wa
When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not trigg
When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes ca
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network'
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab wh
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service wo
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary header
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wron
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been us
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video d
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended t
Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corru
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evi
When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into in
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started