← All vendors

mozilla

239 known vulnerabilities affecting mozilla products.

Products

firefox 194 thunderbird 172 firefox_mobile 61 focus 15 firefox_esr 9 firefox_focus 4 klar 1

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-16349 Medium 0.2% 9.8 Same-origin policy bypass in the DOM: Navigation component. This vulnerability w…
CVE-2026-16401 Medium 0.2% 8.8 Privilege escalation in the Data Loss Prevention component. This vulnerability w…
CVE-2026-16375 Medium 0.2% 9.8 Site isolation issue in the Networking: HTTP component. This vulnerability was f…
CVE-2026-16387 Medium 0.2% 9.8 Site isolation issue in the Networking component. This vulnerability was fixed i…
CVE-2026-84129 Medium 0.2% 9.8 Site isolation issue in the DOM: Navigation component. This vulnerability was fi…
CVE-2026-84133 Medium 0.2% 9.8 Site isolation issue in the DOM: Push Subscriptions component. This vulnerabilit…
CVE-2026-84140 Medium 0.2% 9.8 Site isolation issue in the DOM: Navigation component. This vulnerability was fi…
CVE-2026-16381 Medium 0.2% 9.1 Same-origin policy bypass in the Networking: DNS component. This vulnerability w…
CVE-2026-74960 Medium 0.2% 8.1 Site isolation issue in the WebExtensions component. This vulnerability was fixe…
CVE-2026-74962 Medium 0.2% 8.1 Site isolation issue in the Networking: Cookies component. This vulnerability wa…
CVE-2026-16404 Medium 0.2% 7.4 Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 1…
CVE-2026-74934 Medium 0.2% 7.5 Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability …
CVE-2026-16398 Medium 0.1% 7.5 Site isolation issue in the Graphics component. This vulnerability was fixed in …
CVE-2026-16399 Medium 0.1% 7.5 Site isolation issue in the DOM: Navigation component. This vulnerability was fi…
CVE-2026-74981 Medium 0.1% 8.1 Site isolation issue in the Audio/Video: Web Codecs component. This vulnerabilit…
CVE-2020-6829 Low 1.5% 5.3 When performing EC scalar point multiplication, the wNAF point multiplication al…
CVE-2020-15664 Low 1.4% 6.5 By holding a reference to the eval() function from an about:blank window, a mali…
CVE-2020-15666 Low 1.2% 6.5 When trying to load a non-video in an audio/video context the exact status code …
CVE-2020-26964 Low 0.9% 6.8 If the Remote Debugging via USB feature was enabled in Firefox for Android on an…
CVE-2020-26975 Low 0.9% 6.5 When a malicious application installed on the user's device broadcast an Intent …
CVE-2026-10702 Low 0.9% 4.3 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w…
CVE-2020-26977 Low 0.9% 6.5 By attempting to connect a website using an unresponsive port, an attacker could…
CVE-2020-15661 Low 0.8% 6.5 A rogue webpage could override the injected WKUserScript used by the logins auto…
CVE-2020-26955 Low 0.8% 6.5 When a user downloaded a file in Firefox for Android, if a cookie is set, it wou…
CVE-2020-12404 Low 0.8% 4.3 For native-to-JS bridging the app requires a unique token to be passed that ensu…
CVE-2023-29535 Low 0.7% 6.5 Following a Garbage Collector compaction, weak maps may have been accessed befor…
CVE-2023-29548 Low 0.7% 6.5 A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optim…
CVE-2020-12414 Low 0.7% 6.5 IndexedDB should be cleared when leaving private browsing mode and it is not, th…
CVE-2020-15662 Low 0.7% 6.5 A rogue webpage could override the injected WKUserScript used by the download fe…
CVE-2020-26954 Low 0.6% 4.3 When accepting a malicious intent from other installed apps, Firefox for Android…
CVE-2023-29533 Low 0.6% 4.3 A website could have obscured the fullscreen notification by using a combination…
CVE-2020-26957 Low 0.5% 6.5 OneCRL was non-functional in the new Firefox for Android due to a missing servic…
CVE-2020-15668 Low 0.5% 4.3 A lock was missing when accessing a data structure and importing certificate inf…
CVE-2023-29546 Low 0.5% 6.5 When recording the screen while in Private Browsing on Firefox for Android the a…
CVE-2026-15718 Low 0.5% 4.3 We are aware that exploit code for this is public however we are not aware of an…
CVE-2020-15671 Low 0.5% 3.1 When typing in a password under certain conditions, a race may have occured wher…
CVE-2023-29544 Low 0.4% 6.5 If multiple instances of resource exhaustion occurred at the incorrect time, the…
CVE-2023-5758 Low 0.4% 6.1 When opening a page in reader mode, the redirect URL could have caused attacker-…
CVE-2026-74945 Low 0.4% 6.5 Information disclosure in the Graphics: Text component. This vulnerability was f…
CVE-2022-31746 Low 0.4% 6.5 Internal URLs are protected by a secret UUID key, which could have been leaked t…
CVE-2019-17003 Low 0.4% 6.1 Scanning a QR code that contained a javascript: URL would have resulted in the J…
CVE-2023-29538 Low 0.4% 4.3 Under specific circumstances a WebExtension may have received a <code>jar:file:/…
CVE-2022-38474 Low 0.4% 4.3 A website that had permission to access the microphone could record audio withou…
CVE-2026-15719 Low 0.3% 5.4 We are aware that exploit code for this is public however we are not aware of an…
CVE-2023-29549 Low 0.3% 6.5 Under certain circumstances, a call to the <code>bind</code> function may have r…
CVE-2020-12401 Low 0.3% 4.7 During ECDSA signature generation, padding applied in the nonce designed to ensu…
CVE-2026-8961 Low 0.3% 6.5 Spoofing issue in the Form Autofill component. This vulnerability was fixed in F…
CVE-2026-74976 Low 0.3% 6.5 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w…
CVE-2023-29540 Low 0.3% 6.1 Using a redirect embedded into <code>sourceMappingUrls</code> could allow for na…
CVE-2026-74948 Low 0.3% 6.5 Information disclosure in the Graphics component. This vulnerability was fixed i…
← Prev Page 4 of 5 Next →