Mozilla
7,140 known vulnerabilities
Top Products
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could
Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox
Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing
A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, a
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecod
When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method,
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of t
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aw
Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed eviden
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed eviden
When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block cou
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's A
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification th
When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possi
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML doc
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been ex
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resize
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, res
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted an
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allo
Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corru
Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported fil
If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on
A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an
When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null poin
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passw
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location.
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. Thi
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could ste
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site a
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Pers
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through acti
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by
Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corru
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evi
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Securit
When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by P
When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started