Mozilla
7,140 known vulnerabilities
Top Products
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leadi
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI f
Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite F
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choo
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-O
A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage,
Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed ev
Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leadi
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in
In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, r
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were le
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to me
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; cau
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicio
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was bei
By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with
Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corru
Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evi
When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This
When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path in
Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary G
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploi
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which enta
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbi
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, a
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PP
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruptio
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridgin
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can b
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed t
Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability a
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a pot
Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed ev
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of
A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by sel
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address t
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentia
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started