Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Mozilla

7,140 known vulnerabilities

444
CRITICAL
788
HIGH
788
MEDIUM
19
LOW

Top Products

firefox 1837 thunderbird 1183 firefox esr 435 firefox mobile 60 firefox focus 20 focus 16 network security services 16 thunderbird esr 14 bleach 5 vpn 4
2,039 CVEs · Page 28/41
6.5
CVE-2020-26965

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field,

6.8
CVE-2020-26964

If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, u

4.3
CVE-2020-26963

Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by in

6.1
CVE-2020-26962

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated

6.5
CVE-2020-26961

When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not

8.8
CVE-2020-26960

If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers

8.8
CVE-2020-26959

During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-afte

6.1
CVE-2020-26958

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached throug

6.5
CVE-2020-26957

OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a

6.1
CVE-2020-26956

In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to X

6.5
CVE-2020-26955

When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent

4.3
CVE-2020-26954

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file

4.3
CVE-2020-26953

It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possibl

8.8
CVE-2020-26952

Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially

6.1
CVE-2020-26951

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitizati

8.8
CVE-2020-26950

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable

5.3
CVE-2020-6829

When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial i

9.8
CVE-2020-15684

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corru

9.8
CVE-2020-15683

Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of

6.5
CVE-2020-15682

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application

7.5
CVE-2020-15681

When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could ha

5.3
CVE-2020-15680

If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguis

7.5
CVE-2019-17007

In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in

9.8
CVE-2019-17006

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases whe

6.5
CVE-2018-18508

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a nul

7.5
CVE-2020-25648

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker t

5.9
CVE-2020-15646

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange

4.7
CVE-2020-12401

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication w

4.7
CVE-2020-12400

When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulti

8.8
CVE-2020-15678

When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential u

6.1
CVE-2020-15677

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the down

6.1
CVE-2020-15676

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScr

8.8
CVE-2020-15675

When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially ex

8.8
CVE-2020-15674

Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corru

8.8
CVE-2020-15673

Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evi

3.1
CVE-2020-15671

When typing in a password under certain conditions, a race may have occured where the InputContext was not being correct

8.8
CVE-2020-15670

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of

8.8
CVE-2020-15669

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. T

4.3
CVE-2020-15668

A lock was missing when accessing a data structure and importing certificate information into the trust database. This v

8.8
CVE-2020-15667

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap

6.5
CVE-2020-15666

When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was

4.3
CVE-2020-15665

Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. T

6.5
CVE-2020-15664

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access t

8.8
CVE-2020-15663

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the

6.5
CVE-2020-15662

A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the

6.5
CVE-2020-15661

A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaki

8.8
CVE-2020-15659

Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of

6.5
CVE-2020-15658

The code for downloading files did not properly take care of special characters, which led to an attacker being able to

7.8
CVE-2020-15657

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker tha

8.8
CVE-2020-15656

JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mit

Frequently Asked Questions

How many CVEs affect Mozilla?

Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Mozilla vulnerabilities?

Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Mozilla vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Mozilla Vulnerabilities

CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.

Get Started