Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Mozilla

7,140 known vulnerabilities

444
CRITICAL
788
HIGH
788
MEDIUM
19
LOW

Top Products

firefox 1837 thunderbird 1183 firefox esr 435 firefox mobile 60 firefox focus 20 focus 16 network security services 16 thunderbird esr 14 bleach 5 vpn 4
2,039 CVEs · Page 40/41
9.8
CVE-2017-5402

A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroye

9.8
CVE-2017-5401

A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resu

9.8
CVE-2017-5400

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potenti

9.8
CVE-2017-5399

Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume t

9.8
CVE-2017-5398

Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we pre

9.8
CVE-2017-5397

The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from

9.8
CVE-2017-5396

A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the m

4.3
CVE-2017-5395

Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the n

8.8
CVE-2017-5394

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due t

6.1
CVE-2017-5393

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessib

9.8
CVE-2017-5392

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorre

9.8
CVE-2017-5391

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a con

9.8
CVE-2017-5390

The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing J

6.1
CVE-2017-5389

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions

7.5
CVE-2017-5388

A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN pac

3.3
CVE-2017-5387

The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "so

7.3
CVE-2017-5386

WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, le

7.5
CVE-2017-5385

Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy r

5.9
CVE-2017-5384

Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which

5.3
CVE-2017-5383

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allo

7.5
CVE-2017-5382

Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for th

7.5
CVE-2017-5381

The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certif

9.8
CVE-2017-5380

A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thun

7.5
CVE-2017-5379

Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulner

7.5
CVE-2017-5378

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address c

9.8
CVE-2017-5377

A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potenti

9.8
CVE-2017-5376

Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45

9.8
CVE-2017-5375

JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T

9.8
CVE-2017-5374

Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume

9.8
CVE-2017-5373

Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corr

8.8
CVE-2016-9905

A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability af

7.5
CVE-2016-9904

An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon

6.1
CVE-2016-9903

Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerabili

7.5
CVE-2016-9902

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin o

9.8
CVE-2016-9901

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will b

7.5
CVE-2016-9900

External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of

9.8
CVE-2016-9899

Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.

9.8
CVE-2016-9898

Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerabili

7.5
CVE-2016-9897

Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a

8.1
CVE-2016-9896

Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default.

6.1
CVE-2016-9895

Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline

7.5
CVE-2016-9894

A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buf

9.8
CVE-2016-9893

Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we pre

9.8
CVE-2016-9080

Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presu

7.5
CVE-2016-9079 KEV

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis

8.8
CVE-2016-9078

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circ

7.0
CVE-2016-9077

Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is va

5.9
CVE-2016-9076

An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing att

9.8
CVE-2016-9075

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed

5.9
CVE-2016-9074

An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in

Frequently Asked Questions

How many CVEs affect Mozilla?

Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Mozilla vulnerabilities?

Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Mozilla vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Mozilla Vulnerabilities

CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.

Get Started