Mozilla
7,140 known vulnerabilities
Top Products
WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This v
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabl
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a know
A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vu
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amoun
The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated.
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal"
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefo
A previously installed malicious Android application with same signature-level permissions as Firefox can intercept Auth
A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to
An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issu
A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially
This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Mainten
The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the upda
When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be ap
During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Fire
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affe
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corrup
Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume t
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the co
A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect
Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS)
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to pla
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to pla
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the us
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the
Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS)
The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to
Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS)
Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) a
Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.
Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows
Frequently Asked Questions
How many CVEs affect Mozilla?
Mozilla has 7,140 CVE records in our database, including 872 critical and 3343 high severity vulnerabilities. 11 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Mozilla vulnerabilities?
Mozilla has 872 critical severity (CVSS 9.0+) and 3343 high severity (CVSS 7.0-8.9) vulnerabilities. 11 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Mozilla vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mozilla products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mozilla Vulnerabilities
CyberStrike scans your infrastructure for Mozilla vulnerabilities and provides real-time remediation guidance.
Get Started