Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Mozilla

5,033 known vulnerabilities

314
CRITICAL
335
HIGH
262
MEDIUM
3
LOW

Top Products

firefox 857 thunderbird 560 firefox esr 53 thunderbird esr 14 network security services 11 firefox mobile 8 firefox focus 2 bugzilla 2 focus 1 klar 1
914 CVEs · Page 3/19
8.8
CVE-2026-16371

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,

9.1
CVE-2026-16370

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

9.8
CVE-2026-16369

Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.

9.8
CVE-2026-16368

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Fir

10.0
CVE-2026-16367

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 1

8.8
CVE-2026-16366

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

8.8
CVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

9.1
CVE-2026-16364

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Th

9.8
CVE-2026-16363

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 14

8.8
CVE-2026-16362

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Th

9.8
CVE-2026-16361

Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we pre

9.8
CVE-2026-16360

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence

9.1
CVE-2026-16359

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ES

9.8
CVE-2026-16358

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.

9.8
CVE-2026-16357

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38

9.8
CVE-2026-16356

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15

9.8
CVE-2026-16355

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115

7.5
CVE-2026-16354

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115

9.8
CVE-2026-16353

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38

9.8
CVE-2026-16352

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15

9.8
CVE-2026-16351

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Fire

9.8
CVE-2026-16350

Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox

9.8
CVE-2026-16349

Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115

5.4
CVE-2026-15719

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.

4.3
CVE-2026-15718

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.

5.3
CVE-2026-14906

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within t

6.3
CVE-2026-13356

A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the brows

6.5
CVE-2026-57963

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, an

5.3
CVE-2026-57962

A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitr

9.8
CVE-2026-14241

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume th

4.3
CVE-2026-53900

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument

6.5
CVE-2026-53899

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suff

5.4
CVE-2026-12330

Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12,

5.3
CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 14

8.1
CVE-2026-12328

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbir

8.1
CVE-2026-12327

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these

8.1
CVE-2026-12326

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption a

6.5
CVE-2026-12325

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12,

7.3
CVE-2026-12324

Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firef

5.4
CVE-2026-12323

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

5.4
CVE-2026-12322

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

5.4
CVE-2026-12321

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird

4.3
CVE-2026-12320

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 15

6.5
CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 15

7.3
CVE-2026-12318

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunder

7.5
CVE-2026-12317

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

9.1
CVE-2026-12316

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

9.1
CVE-2026-12315

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thund

7.5
CVE-2026-12314

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152

4.7
CVE-2026-12313

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi

Frequently Asked Questions

How many CVEs affect Mozilla?

Mozilla has 5,033 CVE records in our database, including 641 critical and 701 high severity vulnerabilities. 3 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Mozilla vulnerabilities?

Mozilla has 641 critical severity (CVSS 9.0+) and 701 high severity (CVSS 7.0-8.9) vulnerabilities. 3 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Mozilla vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Mozilla Vulnerabilities

CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.

Get Started