Mozilla
7,140 known vulnerabilities
Top Products
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroye
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resu
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potenti
Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume t
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we pre
The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the m
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the n
A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due t
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessib
Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorre
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a con
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing J
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN pac
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "so
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, le
Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy r
Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allo
Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for th
The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certif
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thun
Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulner
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address c
A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potenti
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corr
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability af
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerabili
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin o
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will b
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerabili
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default.
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline
A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buf
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we pre
Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presu
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circ
Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is va
An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing att
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started