mozilla / firefox
194 known vulnerabilities in mozilla firefox.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2020-15666 | Low | 1.2% | 6.5 | When trying to load a non-video in an audio/video context the exact status code … | |
| CVE-2026-10702 | Low | 0.9% | 4.3 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… | |
| CVE-2023-29535 | Low | 0.7% | 6.5 | Following a Garbage Collector compaction, weak maps may have been accessed befor… | |
| CVE-2023-29548 | Low | 0.7% | 6.5 | A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optim… | |
| CVE-2023-29533 | Low | 0.6% | 4.3 | A website could have obscured the fullscreen notification by using a combination… | |
| CVE-2020-15668 | Low | 0.5% | 4.3 | A lock was missing when accessing a data structure and importing certificate inf… | |
| CVE-2026-15718 | Low | 0.5% | 4.3 | We are aware that exploit code for this is public however we are not aware of an… | |
| CVE-2023-29544 | Low | 0.4% | 6.5 | If multiple instances of resource exhaustion occurred at the incorrect time, the… | |
| CVE-2026-74945 | Low | 0.4% | 6.5 | Information disclosure in the Graphics: Text component. This vulnerability was f… | |
| CVE-2023-29538 | Low | 0.4% | 4.3 | Under specific circumstances a WebExtension may have received a <code>jar:file:/… | |
| CVE-2026-15719 | Low | 0.3% | 5.4 | We are aware that exploit code for this is public however we are not aware of an… | |
| CVE-2023-29549 | Low | 0.3% | 6.5 | Under certain circumstances, a call to the <code>bind</code> function may have r… | |
| CVE-2020-12401 | Low | 0.3% | 4.7 | During ECDSA signature generation, padding applied in the nonce designed to ensu… | |
| CVE-2026-8961 | Low | 0.3% | 6.5 | Spoofing issue in the Form Autofill component. This vulnerability was fixed in F… | |
| CVE-2026-74976 | Low | 0.3% | 6.5 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… | |
| CVE-2023-29540 | Low | 0.3% | 6.1 | Using a redirect embedded into <code>sourceMappingUrls</code> could allow for na… | |
| CVE-2026-74948 | Low | 0.3% | 6.5 | Information disclosure in the Graphics component. This vulnerability was fixed i… | |
| CVE-2020-12400 | Low | 0.3% | 4.7 | When converting coordinates from projective to affine, the modular inversion was… | |
| CVE-2026-74971 | Low | 0.3% | 4.3 | Information disclosure in the DOM: UI Events & Focus Handling component. This vu… | |
| CVE-2026-74972 | Low | 0.3% | 4.3 | Information disclosure in the DOM: Push Subscriptions component. This vulnerabil… | |
| CVE-2026-84120 | Low | 0.2% | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Fir… | |
| CVE-2026-84122 | Low | 0.2% | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Fir… | |
| CVE-2026-8971 | Low | 0.2% | 6.5 | Same-origin policy bypass in the Networking: JAR component. This vulnerability w… | |
| CVE-2026-84118 | Low | 0.2% | 5.4 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in … | |
| CVE-2026-84138 | Low | 0.2% | 6.5 | Denial-of-service in the PDF Viewer component. This vulnerability was fixed in F… | |
| CVE-2026-84136 | Low | 0.2% | 6.1 | Other issue in the DOM: Navigation component. This vulnerability was fixed in Fi… | |
| CVE-2026-9078 | Low | 0.2% | 5.4 | Firefox for iOS displayed specially crafted right-to-left (RTL) and internationa… | |
| CVE-2026-16403 | Low | 0.2% | 6.5 | Spoofing issue in the Address Bar component. This vulnerability was fixed in Fir… | |
| CVE-2026-8706 | Low | 0.2% | 6.5 | Firefox for iOS hosted Reader mode on an unauthenticated local web server, allow… | |
| CVE-2026-74984 | Low | 0.2% | 6.8 | Race condition in the JavaScript Engine component. This vulnerability was fixed … | |
| CVE-2026-84139 | Low | 0.2% | 6.1 | Clickjacking issue in the DOM: Events component. This vulnerability was fixed in… | |
| CVE-2026-84126 | Low | 0.2% | 4.3 | Incorrect boundary conditions in the Layout: Grid component. This vulnerability … | |
| CVE-2026-74973 | Low | 0.2% | 4.2 | Race condition, use-after-free in the Graphics component. This vulnerability was… | |
| CVE-2026-16397 | Low | 0.2% | 6.5 | Clickjacking issue in the WebExtensions component in Firefox for Android. This v… | |
| CVE-2026-84124 | Low | 0.2% | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-84125 | Low | 0.2% | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-9308 | Low | 0.2% | 5.4 | Firefox for iOS Reader View replaced page content in its HTML template before re… | |
| CVE-2026-9309 | Low | 0.2% | 5.4 | Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadat… | |
| CVE-2026-74970 | Low | 0.1% | 5.4 | Site isolation issue in the Graphics component. This vulnerability was fixed in … | |
| CVE-2026-74974 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Graphics: ImageLib component. This vulnerabilit… | |
| CVE-2026-84137 | Low | 0.1% | 4.3 | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-74963 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Networking: Cookies component. This vulnerabili… | |
| CVE-2026-74967 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Audio/Video: Playback component. This vulnerabi… | |
| CVE-2026-74968 | Low | 0.1% | 5.4 | Site isolation issue in the Graphics: WebRender component. This vulnerability wa… |
← Prev Page 4 of 4