mozilla
239 known vulnerabilities affecting mozilla products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-49061 | Low | 0.3% | 6.1 | An attacker could have performed HTML template injection via Reader Mode and exf… | |
| CVE-2024-0953 | Low | 0.3% | 6.1 | When a user scans a QR Code with the QR Code Scanner feature, the user is not pr… | |
| CVE-2024-38312 | Low | 0.3% | 6.5 | When browsing private tabs, some data related to location history or webpage thu… | |
| CVE-2024-43111 | Low | 0.3% | 6.1 | Long pressing on a download link could potentially allow Javascript commands to … | |
| CVE-2020-12400 | Low | 0.3% | 4.7 | When converting coordinates from projective to affine, the modular inversion was… | |
| CVE-2026-74971 | Low | 0.3% | 4.3 | Information disclosure in the DOM: UI Events & Focus Handling component. This vu… | |
| CVE-2026-74972 | Low | 0.3% | 4.3 | Information disclosure in the DOM: Push Subscriptions component. This vulnerabil… | |
| CVE-2024-43112 | Low | 0.3% | 6.1 | Long pressing on a download link could potentially provide a means for cross-sit… | |
| CVE-2024-43113 | Low | 0.3% | 6.1 | The contextual menu for links could provide an opportunity for cross-site script… | |
| CVE-2024-38313 | Low | 0.2% | 4.3 | In certain scenarios a malicious website could attempt to display a fake locatio… | |
| CVE-2026-84120 | Low | 0.2% | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Fir… | |
| CVE-2026-84122 | Low | 0.2% | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Fir… | |
| CVE-2026-8971 | Low | 0.2% | 6.5 | Same-origin policy bypass in the Networking: JAR component. This vulnerability w… | |
| CVE-2026-81267 | Low | 0.2% | 5.4 | A malicious webpage could stall a popup's cross-origin navigation after commit, … | |
| CVE-2026-84118 | Low | 0.2% | 5.4 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in … | |
| CVE-2026-84138 | Low | 0.2% | 6.5 | Denial-of-service in the PDF Viewer component. This vulnerability was fixed in F… | |
| CVE-2026-84136 | Low | 0.2% | 6.1 | Other issue in the DOM: Navigation component. This vulnerability was fixed in Fi… | |
| CVE-2026-9078 | Low | 0.2% | 5.4 | Firefox for iOS displayed specially crafted right-to-left (RTL) and internationa… | |
| CVE-2026-16403 | Low | 0.2% | 6.5 | Spoofing issue in the Address Bar component. This vulnerability was fixed in Fir… | |
| CVE-2026-8706 | Low | 0.2% | 6.5 | Firefox for iOS hosted Reader mode on an unauthenticated local web server, allow… | |
| CVE-2026-74984 | Low | 0.2% | 6.8 | Race condition in the JavaScript Engine component. This vulnerability was fixed … | |
| CVE-2026-84139 | Low | 0.2% | 6.1 | Clickjacking issue in the DOM: Events component. This vulnerability was fixed in… | |
| CVE-2026-84126 | Low | 0.2% | 4.3 | Incorrect boundary conditions in the Layout: Grid component. This vulnerability … | |
| CVE-2026-74973 | Low | 0.2% | 4.2 | Race condition, use-after-free in the Graphics component. This vulnerability was… | |
| CVE-2026-74980 | Low | 0.2% | 6.5 | Clickjacking issue in the Downloads component in Firefox for Android. This vulne… | |
| CVE-2026-16397 | Low | 0.2% | 6.5 | Clickjacking issue in the WebExtensions component in Firefox for Android. This v… | |
| CVE-2026-84124 | Low | 0.2% | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-84125 | Low | 0.2% | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-74951 | Low | 0.2% | 6.5 | Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firef… | |
| CVE-2026-9308 | Low | 0.2% | 5.4 | Firefox for iOS Reader View replaced page content in its HTML template before re… | |
| CVE-2026-9309 | Low | 0.2% | 5.4 | Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadat… | |
| CVE-2026-84127 | Low | 0.2% | 4.3 | Information disclosure in the WebExtensions component in Firefox for Android. Th… | |
| CVE-2026-74975 | Low | 0.2% | 5.4 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerabi… | |
| CVE-2026-74970 | Low | 0.1% | 5.4 | Site isolation issue in the Graphics component. This vulnerability was fixed in … | |
| CVE-2026-74974 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Graphics: ImageLib component. This vulnerabilit… | |
| CVE-2026-84137 | Low | 0.1% | 4.3 | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-74963 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Networking: Cookies component. This vulnerabili… | |
| CVE-2026-74967 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Audio/Video: Playback component. This vulnerabi… | |
| CVE-2026-74968 | Low | 0.1% | 5.4 | Site isolation issue in the Graphics: WebRender component. This vulnerability wa… |
← Prev Page 5 of 5