← All vendors

mozilla

239 known vulnerabilities affecting mozilla products.

Products

firefox 194 thunderbird 172 firefox_mobile 61 focus 15 firefox_esr 9 firefox_focus 4 klar 1

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2023-49061 Low 0.3% 6.1 An attacker could have performed HTML template injection via Reader Mode and exf…
CVE-2024-0953 Low 0.3% 6.1 When a user scans a QR Code with the QR Code Scanner feature, the user is not pr…
CVE-2024-38312 Low 0.3% 6.5 When browsing private tabs, some data related to location history or webpage thu…
CVE-2024-43111 Low 0.3% 6.1 Long pressing on a download link could potentially allow Javascript commands to …
CVE-2020-12400 Low 0.3% 4.7 When converting coordinates from projective to affine, the modular inversion was…
CVE-2026-74971 Low 0.3% 4.3 Information disclosure in the DOM: UI Events & Focus Handling component. This vu…
CVE-2026-74972 Low 0.3% 4.3 Information disclosure in the DOM: Push Subscriptions component. This vulnerabil…
CVE-2024-43112 Low 0.3% 6.1 Long pressing on a download link could potentially provide a means for cross-sit…
CVE-2024-43113 Low 0.3% 6.1 The contextual menu for links could provide an opportunity for cross-site script…
CVE-2024-38313 Low 0.2% 4.3 In certain scenarios a malicious website could attempt to display a fake locatio…
CVE-2026-84120 Low 0.2% 5.4 Use-after-free in the Audio/Video component. This vulnerability was fixed in Fir…
CVE-2026-84122 Low 0.2% 5.4 Use-after-free in the Audio/Video component. This vulnerability was fixed in Fir…
CVE-2026-8971 Low 0.2% 6.5 Same-origin policy bypass in the Networking: JAR component. This vulnerability w…
CVE-2026-81267 Low 0.2% 5.4 A malicious webpage could stall a popup's cross-origin navigation after commit, …
CVE-2026-84118 Low 0.2% 5.4 Use-after-free in the JavaScript: GC component. This vulnerability was fixed in …
CVE-2026-84138 Low 0.2% 6.5 Denial-of-service in the PDF Viewer component. This vulnerability was fixed in F…
CVE-2026-84136 Low 0.2% 6.1 Other issue in the DOM: Navigation component. This vulnerability was fixed in Fi…
CVE-2026-9078 Low 0.2% 5.4 Firefox for iOS displayed specially crafted right-to-left (RTL) and internationa…
CVE-2026-16403 Low 0.2% 6.5 Spoofing issue in the Address Bar component. This vulnerability was fixed in Fir…
CVE-2026-8706 Low 0.2% 6.5 Firefox for iOS hosted Reader mode on an unauthenticated local web server, allow…
CVE-2026-74984 Low 0.2% 6.8 Race condition in the JavaScript Engine component. This vulnerability was fixed …
CVE-2026-84139 Low 0.2% 6.1 Clickjacking issue in the DOM: Events component. This vulnerability was fixed in…
CVE-2026-84126 Low 0.2% 4.3 Incorrect boundary conditions in the Layout: Grid component. This vulnerability …
CVE-2026-74973 Low 0.2% 4.2 Race condition, use-after-free in the Graphics component. This vulnerability was…
CVE-2026-74980 Low 0.2% 6.5 Clickjacking issue in the Downloads component in Firefox for Android. This vulne…
CVE-2026-16397 Low 0.2% 6.5 Clickjacking issue in the WebExtensions component in Firefox for Android. This v…
CVE-2026-84124 Low 0.2% 5.4 Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i…
CVE-2026-84125 Low 0.2% 5.4 Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i…
CVE-2026-74951 Low 0.2% 6.5 Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firef…
CVE-2026-9308 Low 0.2% 5.4 Firefox for iOS Reader View replaced page content in its HTML template before re…
CVE-2026-9309 Low 0.2% 5.4 Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadat…
CVE-2026-84127 Low 0.2% 4.3 Information disclosure in the WebExtensions component in Firefox for Android. Th…
CVE-2026-74975 Low 0.2% 5.4 Spoofing issue in the Downloads component in Firefox for Android. This vulnerabi…
CVE-2026-74970 Low 0.1% 5.4 Site isolation issue in the Graphics component. This vulnerability was fixed in …
CVE-2026-74974 Low 0.1% 5.4 Same-origin policy bypass in the Graphics: ImageLib component. This vulnerabilit…
CVE-2026-84137 Low 0.1% 4.3 Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed i…
CVE-2026-74963 Low 0.1% 5.4 Same-origin policy bypass in the Networking: Cookies component. This vulnerabili…
CVE-2026-74967 Low 0.1% 5.4 Same-origin policy bypass in the Audio/Video: Playback component. This vulnerabi…
CVE-2026-74968 Low 0.1% 5.4 Site isolation issue in the Graphics: WebRender component. This vulnerability wa…
← Prev Page 5 of 5