Mozilla
7,140 known vulnerabilities
Top Products
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an
The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files tha
A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL par
Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled ou
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event cou
A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base doma
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecry
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to crea
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains im
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects
A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exp
A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching whi
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a pot
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during han
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a p
A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This
A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash.
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dr
A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash.
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence o
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability di
A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is starte
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matc
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploit
A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user co
A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressba
If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-respons
An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leaka
When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the
In certain circumstances a networking event listener can be prematurely released. This appears to result in a null deref
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leadin
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating sys
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and
A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects
A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. T
Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a specia
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pi
A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip i
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. Thi
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root obje
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started