Mozilla
7,140 known vulnerabilities
Top Products
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field,
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, u
Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by in
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-afte
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached throug
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to X
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possibl
Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitizati
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial i
Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corru
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of
When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application
When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could ha
If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguis
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases whe
In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a nul
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker t
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication w
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulti
When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential u
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the down
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScr
When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially ex
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corru
Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evi
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correct
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of
When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. T
A lock was missing when accessing a data structure and importing certificate information into the trust database. This v
When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was
Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. T
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access t
If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the
A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaki
Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of
The code for downloading files did not properly take care of special characters, which led to an attacker being able to
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker tha
JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mit
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started