Mozilla Security Vulnerabilities (CVEs)
Track 378 security vulnerabilities affecting Mozilla products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
CVE-2024-9403 is a memory safety vulnerability in Firefox and Thunderbird that could allow memory corruption. With sufficient effort, attackers could ...
Oct 1, 2024This vulnerability allows a compromised content process in Firefox or Thunderbird to load cross-origin web pages arbitrarily, bypassing Same-Origin Po...
Oct 1, 2024This vulnerability allows attackers to execute arbitrary JavaScript in the privileged devtools origin via specially crafted multipart responses, enabl...
Oct 1, 2024A memory corruption vulnerability in Firefox, Firefox ESR, and Thunderbird could allow attackers to execute arbitrary code or cause denial of service ...
Oct 1, 2024This vulnerability allows attackers to detect whether specific protocol handler applications are installed on a user's system by exploiting how Firefo...
Oct 1, 2024A denial-of-service vulnerability in Firefox, Firefox ESR, and Thunderbird allows a malicious website to crash the browser process by initiating a spe...
Oct 1, 2024This vulnerability allows attackers to write arbitrary data to a user's clipboard without user consent during specific navigational sequences. It affe...
Sep 17, 2024This vulnerability allows attackers to spoof the address bar in Firefox for Android by exploiting an open redirect on a trusted site. When users are r...
Sep 17, 2024This vulnerability allows malicious websites to spoof URL addresses displayed in the Focus navigation bar on iOS devices. Attackers can make a malicio...
Sep 3, 2024CVE-2024-8389 is a critical memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulne...
Sep 3, 2024This vulnerability allows attackers to trigger type confusion when accessing properties on objects used as 'with' statement environments in Mozilla pr...
Sep 3, 2024Firefox versions before 130, 128.2 ESR, and 115.15 ESR automatically launch external applications for news: and snews: schemes without user confirmati...
Sep 3, 2024A critical memory corruption vulnerability in Mozilla's JavaScript garbage collector could allow attackers to execute arbitrary code or cause denial o...
Sep 3, 2024This vulnerability allows malicious websites with popup permissions to overlay select elements on top of legitimate sites, enabling UI spoofing attack...
Sep 3, 2024This CVE describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird that could lead to memory corruption. With sufficient effort, attackers...
Sep 3, 2024A cross-site scripting (XSS) vulnerability in Firefox for iOS allows attackers to execute malicious scripts by tricking users into long-pressing on sp...
Aug 6, 2024This vulnerability allows memory corruption through insufficient checks in graphics shared memory processing, potentially enabling sandbox escape. It ...
Aug 6, 2024A use-after-free vulnerability in WebAssembly exception handling in Mozilla products could allow remote code execution. This affects Firefox, Firefox ...
Aug 6, 2024This vulnerability allows malicious websites to partially obscure security permission prompts in Firefox for Android, potentially tricking users into ...
Aug 6, 2024This vulnerability allows web extensions with minimal permissions to intercept and modify HTTP responses for any website, bypassing normal security re...
Aug 6, 2024This CVE describes a use-after-free vulnerability in Mozilla's garbage collection mechanism that could allow an attacker to execute arbitrary code or ...
Aug 6, 2024This vulnerability allows malicious websites to partially obscure security permission prompts using the date picker interface, potentially tricking us...
Aug 6, 2024CVE-2024-7530 is a use-after-free vulnerability in Firefox caused by incorrect garbage collection interaction. Attackers could exploit this to execute...
Aug 6, 2024This vulnerability allows malicious websites to obscure the fullscreen notification dialog in Firefox and Thunderbird, enabling spoofing attacks where...
Aug 6, 2024This vulnerability allows malicious websites to bypass SameSite cookie restrictions by using nested iframes to trigger cross-site navigations, enablin...
Jul 9, 2024This vulnerability in Firefox and Thunderbird involves a WebAssembly (wasm) frame iterator getting stuck in an infinite loop when processing certain w...
Jul 9, 2024This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...
Jul 9, 2024This vulnerability in Angle's GLSL shader memory allocation on macOS allows out-of-bounds memory access when allocating large amounts of private shade...
Jul 9, 2024CVE-2024-6602 is a critical memory corruption vulnerability in Mozilla products caused by mismatched memory allocation and deallocation functions. Thi...
Jul 9, 2024This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...
Jul 9, 2024This vulnerability in Firefox and Thunderbird involves improper bounds checking in clipboard code, allowing an out-of-bounds read. Attackers could exp...
Jul 9, 2024This vulnerability allows an attacker to move the cursor outside the browser viewport and Firefox window using pointerlock from an iframe. This affect...
Jul 9, 2024A use-after-free vulnerability in Firefox and Thunderbird occurs when the browser is nearly out of memory, causing an elliptic curve key that was neve...
Jul 9, 2024This vulnerability in Firefox Focus for iOS allows URL spoofing by hiding the file scheme in the location bar, potentially tricking users into believi...
May 17, 2024A vulnerability in Firefox allows a file dialog displayed during full-screen mode to leave the window disabled, potentially enabling clickjacking atta...
May 14, 2024CVE-2024-4778 is a critical memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulne...
May 14, 2024CVE-2024-4772 is a vulnerability in Firefox where HTTP digest authentication nonce values were generated using the predictable rand() function instead...
May 14, 2024This vulnerability in Firefox allows attackers to spoof websites by exploiting a network error during page loading. When a network error occurs, previ...
May 14, 2024A missing iterator stop condition in Firefox's built-in profiler when handling WASM code could lead to invalid memory access and undefined behavior. T...
May 14, 2024This vulnerability in Firefox, Firefox ESR, and Thunderbird allows attackers to trick users into granting WebAuthn permissions via manipulated popup n...
May 14, 2024A use-after-free vulnerability in Firefox, Firefox ESR, and Thunderbird occurs when saving pages to PDF with certain font styles, potentially causing ...
May 14, 2024This vulnerability allows attackers to hide the fullscreen notification in Firefox for Android, potentially tricking users into interacting with spoof...
May 14, 2024A use-after-free vulnerability in Firefox's WebRTC audio input handling allows multiple threads to claim the same audio connection, potentially leadin...
May 14, 2024This vulnerability in Firefox, Firefox ESR, and Thunderbird occurs when the GetBoundName function returns an incorrect object version due to JIT optim...
Apr 16, 2024This vulnerability in Mozilla's JavaScript JIT compiler incorrectly optimizes switch statements, leading to out-of-bounds memory reads. It affects Fir...
Apr 16, 2024A use-after-free vulnerability in Firefox's WebAssembly (WASM) garbage collection allows attackers to execute arbitrary code when users visit maliciou...
Apr 16, 2024This vulnerability allows an attacker to crash Firefox by manipulating JavaScript objects to trigger a JIT (Just-In-Time) compiler failure. It affects...
Apr 16, 2024This vulnerability allows attackers to download malicious .xrm-ms files without the usual executable file warning in Firefox, Thunderbird, and Firefox...
Apr 16, 2024CVE-2024-3865 is a memory safety vulnerability in Firefox that could allow attackers to execute arbitrary code on affected systems. The vulnerability ...
Apr 16, 2024This vulnerability in Firefox for iOS causes the browser to incorrectly display a secure lock icon when insecure content loads on a page after a delay...
Apr 3, 2024Why Monitor Mozilla Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 378+ known vulnerabilities affecting Mozilla products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Mozilla packages in under 60 seconds. No agents required - completely agentless scanning that works across Mozilla deployments.
Free vulnerability database: Access detailed information about every Mozilla CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Mozilla CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions