mozilla / firefox
194 known vulnerabilities in mozilla firefox.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-16371 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-74953 | Medium | 0.3% | 8.8 | Privilege escalation in the Networking: Cookies component. This vulnerability wa… | |
| CVE-2026-74965 | Medium | 0.3% | 8.8 | Privilege escalation in the Shell Integration component. This vulnerability was … | |
| CVE-2026-16372 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Content Processes component. This vulnerability… | |
| CVE-2026-16362 | Medium | 0.3% | 8.8 | Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixe… | |
| CVE-2026-74937 | Medium | 0.3% | 8.8 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in … | |
| CVE-2026-8969 | Medium | 0.3% | 8.1 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed i… | |
| CVE-2026-16409 | Medium | 0.3% | 7.5 | Invalid pointer in the Security: PSM component. This vulnerability was fixed in … | |
| CVE-2026-74956 | Medium | 0.3% | 9.1 | Same-origin policy bypass in the DOM: Service Workers component. This vulnerabil… | |
| CVE-2026-16407 | Medium | 0.3% | 9.8 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was … | |
| CVE-2026-16365 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Workers component. This vulnerability was fixed… | |
| CVE-2026-16379 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Content Processes component. This vulnerability… | |
| CVE-2026-16366 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-74958 | Medium | 0.3% | 7.5 | Information disclosure in the WebRTC component. This vulnerability was fixed in … | |
| CVE-2026-16359 | Medium | 0.3% | 9.1 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerabil… | |
| CVE-2026-16405 | Medium | 0.3% | 7.5 | Information disclosure in the Networking: WebSockets component. This vulnerabili… | |
| CVE-2026-74954 | Medium | 0.3% | 7.5 | Information disclosure due to side-channel in the Storage: Cache API component. … | |
| CVE-2026-74966 | Medium | 0.3% | 7.5 | Information disclosure in the Form Autofill component. This vulnerability was fi… | |
| CVE-2026-84130 | Medium | 0.3% | 7.5 | Information disclosure in the Graphics: WebGPU component. This vulnerability was… | |
| CVE-2026-84132 | Medium | 0.3% | 7.5 | Information disclosure in the Networking: HTTP component. This vulnerability was… | |
| CVE-2026-74961 | Medium | 0.3% | 9.1 | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox… | |
| CVE-2026-16394 | Medium | 0.3% | 9.1 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed i… | |
| CVE-2026-16406 | Medium | 0.3% | 9.1 | Mitigation bypass in the Networking component. This vulnerability was fixed in F… | |
| CVE-2026-16400 | Medium | 0.2% | 7.5 | Information disclosure in the DOM: Security component. This vulnerability was fi… | |
| CVE-2026-74947 | Medium | 0.2% | 8.8 | Privilege escalation due to invalid pointer in the Graphics component. This vuln… | |
| CVE-2026-16396 | Medium | 0.2% | 8.8 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 1… | |
| CVE-2026-84144 | Medium | 0.2% | 7.5 | Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some… | |
| CVE-2026-84123 | Medium | 0.2% | 8.8 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. Th… | |
| CVE-2026-84128 | Medium | 0.2% | 8.8 | Privilege escalation in the WebDriver BiDi component. This vulnerability was fix… | |
| CVE-2026-74978 | Medium | 0.2% | 8.1 | Clickjacking issue in the Widget component. This vulnerability was fixed in Fire… | |
| CVE-2026-74952 | Medium | 0.2% | 8.8 | Privilege escalation in the Application Update component. This vulnerability was… | |
| CVE-2026-74950 | Medium | 0.2% | 8.8 | Privilege escalation in the Downloads API component. This vulnerability was fixe… | |
| CVE-2026-74955 | Medium | 0.2% | 8.8 | Privilege escalation in the Request Handling component. This vulnerability was f… | |
| CVE-2026-16358 | Medium | 0.2% | 9.8 | Site isolation issue in the Graphics: WebRender component. This vulnerability wa… | |
| CVE-2026-16349 | Medium | 0.2% | 9.8 | Same-origin policy bypass in the DOM: Navigation component. This vulnerability w… | |
| CVE-2026-16401 | Medium | 0.2% | 8.8 | Privilege escalation in the Data Loss Prevention component. This vulnerability w… | |
| CVE-2026-16375 | Medium | 0.2% | 9.8 | Site isolation issue in the Networking: HTTP component. This vulnerability was f… | |
| CVE-2026-16387 | Medium | 0.2% | 9.8 | Site isolation issue in the Networking component. This vulnerability was fixed i… | |
| CVE-2026-84129 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-84133 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Push Subscriptions component. This vulnerabilit… | |
| CVE-2026-84140 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-16381 | Medium | 0.2% | 9.1 | Same-origin policy bypass in the Networking: DNS component. This vulnerability w… | |
| CVE-2026-74960 | Medium | 0.2% | 8.1 | Site isolation issue in the WebExtensions component. This vulnerability was fixe… | |
| CVE-2026-74962 | Medium | 0.2% | 8.1 | Site isolation issue in the Networking: Cookies component. This vulnerability wa… | |
| CVE-2026-74934 | Medium | 0.2% | 7.5 | Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability … | |
| CVE-2026-16398 | Medium | 0.1% | 7.5 | Site isolation issue in the Graphics component. This vulnerability was fixed in … | |
| CVE-2026-16399 | Medium | 0.1% | 7.5 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-74981 | Medium | 0.1% | 8.1 | Site isolation issue in the Audio/Video: Web Codecs component. This vulnerabilit… | |
| CVE-2020-6829 | Low | 1.5% | 5.3 | When performing EC scalar point multiplication, the wNAF point multiplication al… | |
| CVE-2020-15664 | Low | 1.4% | 6.5 | By holding a reference to the eval() function from an about:blank window, a mali… |