Mozilla Security Vulnerabilities (CVEs)

Track 378 security vulnerabilities affecting Mozilla products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

104 Critical
200 High
73 Medium
1 Low
🔔 Get Alerts for Mozilla
CVE-2025-1943 8.2

CVE-2025-1943 is a heap-based buffer overflow vulnerability in Firefox and Thunderbird that could allow memory corruption. Attackers could potentially...

Mar 4, 2025
CVE-2025-27425 4.3

This vulnerability in Firefox for iOS allows QR codes containing website URLs to open those URLs automatically without user confirmation. It affects F...

Mar 4, 2025
CVE-2025-1932 8.1

A memory corruption vulnerability in Firefox and Thunderbird's XSLT processor could allow attackers to execute arbitrary code or cause denial of servi...

Mar 4, 2025
CVE-2025-1934 6.5

This vulnerability allows an attacker to interrupt RegExp bailout processing and execute additional JavaScript, potentially triggering unexpected garb...

Mar 4, 2025
CVE-2025-1936 7.3

This vulnerability in Firefox and Thunderbird allows attackers to hide malicious code in web extensions by disguising it as other file types like imag...

Mar 4, 2025
CVE-2025-1938 6.5

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

Mar 4, 2025
CVE-2025-1940 7.1

This vulnerability allows attackers to partially obscure confirmation prompts in Firefox for Android, tricking users into launching external apps unex...

Mar 4, 2025
CVE-2025-1930 8.8

A use-after-free vulnerability in Firefox and Thunderbird on Windows allows a compromised content process to send malicious AudioIPC StreamData to the...

Mar 4, 2025
CVE-2025-1414 6.5

CVE-2025-1414 is a memory safety vulnerability in Firefox that could allow attackers to corrupt memory and potentially execute arbitrary code. This af...

Feb 18, 2025
CVE-2025-1012 7.5

A race condition during concurrent delazification in Mozilla products could lead to use-after-free vulnerabilities, potentially allowing attackers to ...

Feb 4, 2025
CVE-2025-1013 6.5

A race condition vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird could cause private browsing tabs to open in normal browsing windows, ...

Feb 4, 2025
CVE-2025-1014 8.8

A certificate validation vulnerability in Mozilla products allows improper certificate length checking when adding certificates to a certificate store...

Feb 4, 2025
CVE-2025-1015 5.4

This vulnerability allows attackers to embed malicious links in Thunderbird address book fields. When another user imports the infected address book a...

Feb 4, 2025
CVE-2025-1016 9.8

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...

Feb 4, 2025
CVE-2025-1018 5.3

This vulnerability allows attackers to hide the fullscreen notification in Firefox and Thunderbird by rapidly requesting fullscreen mode, enabling pot...

Feb 4, 2025
CVE-2025-1020 9.8

Memory safety vulnerabilities in Firefox and Thunderbird versions before 135 could allow attackers to execute arbitrary code through memory corruption...

Feb 4, 2025
CVE-2025-0510 6.5

Thunderbird email client displays incorrect sender addresses when emails use invalid group name syntax in the From field. This allows attackers to spo...

Feb 4, 2025
CVE-2025-1009 9.8

A use-after-free vulnerability in Firefox and Thunderbird allows attackers to cause potentially exploitable crashes via crafted XSLT data. This affect...

Feb 4, 2025
CVE-2025-1011 8.8

A WebAssembly code generation bug in Mozilla products could allow attackers to cause crashes and potentially execute arbitrary code. This affects Fire...

Feb 4, 2025
CVE-2025-23108 4.3

This vulnerability in Firefox for iOS allows malicious JavaScript links opened via long-press to spoof the URL displayed in the new tab, potentially t...

Jan 11, 2025
CVE-2025-0244 5.3

This vulnerability in Firefox for Android allows attackers to spoof the address bar when redirecting to invalid protocol schemes, potentially tricking...

Jan 7, 2025
CVE-2025-0246 6.5

This vulnerability allows an attacker to spoof the address bar in Firefox on Android by using an invalid protocol scheme. Only Android users running F...

Jan 7, 2025
CVE-2025-0247 9.8

CVE-2025-0247 is a critical memory safety vulnerability in Firefox and Thunderbird that could allow attackers to execute arbitrary code through memory...

Jan 7, 2025
CVE-2025-0237 5.4

This vulnerability in Mozilla's WebChannel API allows privilege escalation by accepting arbitrary principal information from untrusted sources. Attack...

Jan 7, 2025
CVE-2025-0239 4.0

This vulnerability allows attackers to bypass certificate validation when Firefox or Thunderbird redirects from a secure server to an insecure one usi...

Jan 7, 2025
CVE-2025-0241 7.7

A memory corruption vulnerability in text segmentation components of Mozilla products could allow attackers to cause crashes or potentially execute ar...

Jan 7, 2025
CVE-2025-0242 6.5

This CVE describes memory safety bugs in Mozilla Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could...

Jan 7, 2025
CVE-2024-53975 5.4

This vulnerability causes Firefox for iOS to incorrectly display a secure SSL padlock icon when accessing HTTP sites on non-existent ports, creating a...

Nov 26, 2024
CVE-2024-11706 6.5

A null pointer dereference vulnerability in pk12util's SEC_ASN1DecodeItem_Util function allows attackers to cause denial of service by crashing applic...

Nov 26, 2024
CVE-2024-11695 5.4

This vulnerability allows attackers to craft URLs with Arabic script and whitespace characters to hide the true origin of web pages, enabling spoofing...

Nov 26, 2024
CVE-2024-11697 8.8

This vulnerability allows attackers to bypass the 'Open Executable File?' confirmation dialog in Firefox and Thunderbird by tricking users with keypre...

Nov 26, 2024
CVE-2024-11698 9.8

A fullscreen transition flaw in Firefox and Thunderbird on macOS causes applications to become stuck in fullscreen mode when modal dialogs appear duri...

Nov 26, 2024
CVE-2024-11700 8.1

This CVE describes a tapjacking vulnerability in Firefox and Thunderbird where malicious websites could trick users into approving external applicatio...

Nov 26, 2024
CVE-2024-11702 7.5

This vulnerability in Firefox and Thunderbird on Android allows sensitive data copied from Private Browsing tabs (like passwords) to be unintentionall...

Nov 26, 2024
CVE-2024-11704 9.8

A double-free vulnerability in Firefox and Thunderbird's PKCS7 decryption function could allow memory corruption when processing malformed encrypted d...

Nov 26, 2024
CVE-2024-11691 8.8

A WebGL vulnerability in Apple silicon M series devices allows out-of-bounds writes and memory corruption through Apple's GPU driver. This affects Fir...

Nov 26, 2024
CVE-2024-11693 9.8

This vulnerability in Firefox and Thunderbird allows attackers to download .library-ms files without the usual executable file warning on Windows syst...

Nov 26, 2024
CVE-2023-2142 6.1

Nunjucks templating engine versions before 3.2.4 have an autoescape bypass vulnerability that allows cross-site scripting (XSS) attacks. When two user...

Nov 26, 2024
CVE-2023-0163 8.4

This CVE describes a Prototype Pollution vulnerability in Mozilla Convict, a Node.js configuration management library. Attackers can inject or overrid...

Nov 26, 2024
CVE-2024-10941 6.5

This vulnerability allows malicious websites to crash Firefox browsers by including iframes with malformed URIs. It affects Firefox versions before 12...

Nov 6, 2024
CVE-2024-10464 6.5

This vulnerability allows attackers to cause browser denial-of-service by repeatedly writing to history interface attributes. It affects Firefox, Fire...

Oct 29, 2024
CVE-2024-10466 7.5

A remote server can send a specially crafted push message that causes the browser's parent process to hang, making Firefox or Thunderbird unresponsive...

Oct 29, 2024
CVE-2024-10468 5.3

This CVE describes a race condition vulnerability in IndexedDB implementations in Firefox and Thunderbird that could lead to memory corruption and pot...

Oct 29, 2024
CVE-2024-10458 7.5

This vulnerability allows a malicious website to bypass same-origin policy restrictions via embedded content, potentially accessing sensitive data fro...

Oct 29, 2024
CVE-2024-10460 5.3

This vulnerability allows attackers to obscure the origin of external protocol handler prompts using data: URLs within iframes, potentially tricking u...

Oct 29, 2024
CVE-2024-10462 6.5

This vulnerability allows attackers to spoof website origins in permission prompts by truncating long URLs, potentially tricking users into granting p...

Oct 29, 2024
CVE-2024-10004 9.1

This vulnerability in Firefox for iOS causes the browser to incorrectly display an HTTPS padlock icon when opening an external HTTP link after the app...

Oct 15, 2024
CVE-2024-9936 6.5

This vulnerability in Firefox's selection node cache manipulation allows attackers to cause unexpected behavior leading to exploitable crashes. It aff...

Oct 14, 2024
CVE-2024-9680 9.8

This critical vulnerability allows remote attackers to execute arbitrary code by exploiting a use-after-free flaw in Firefox's animation timeline impl...

Oct 9, 2024
CVE-2024-9401 9.8

CVE-2024-9401 is a critical memory safety vulnerability in Mozilla Firefox and Thunderbird that could allow attackers to execute arbitrary code throug...

Oct 1, 2024

Why Monitor Mozilla Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 378+ known vulnerabilities affecting Mozilla products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Mozilla packages in under 60 seconds. No agents required - completely agentless scanning that works across Mozilla deployments.

Free vulnerability database: Access detailed information about every Mozilla CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Mozilla CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Mozilla CVEs Free