Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Mozilla

Vulnerabilities across Mozilla Firefox, Thunderbird, and the shared Gecko/SpiderMonkey stack — the Mozilla Foundation Security Advisories (MFSA) cadence, browser-sandbox escapes, and the JavaScript-engine bugs that Pwn2Own and in-the-wild attackers keep finding.

16 CVEs2 articlesRSS
CVEs
CVE-2026-15718
[ MEDIUM ]CVSS 4.3EPSS 0.5%patched

Firefox JavaScript/WebAssembly invalid pointer with public exploit code

An invalid-pointer flaw in Firefox's JavaScript / WebAssembly component. Mozilla notes exploit code is public but no in-the-wild attacks are confirmed. Fixed in Firefox 152.0.6.

Mozilla / Firefox (pre-152.0.6)
CVE-2026-15719
[ MEDIUM ]CVSS 5.4EPSS 0.3%patched

Firefox DOM Navigation site-isolation flaw with public exploit code

A site-isolation flaw in Firefox's DOM Navigation component. Mozilla notes exploit code is public but no in-the-wild attacks are confirmed. Fixed in Firefox 152.0.6.

Mozilla / Firefox (pre-152.0.6)
CVE-2026-10702
[ MEDIUM ]CVSS 4.3EPSS 0.9%patched

JIT miscompilation in Firefox JavaScript engine allows renderer code execution

A JIT miscompilation in Firefox's JavaScript engine allows attackers to execute code in the browser renderer via a malicious webpage. Fixed in Firefox 151.0.3; also affected Tor Browser.

Mozilla / Firefox
CVE-2010-3765
[ CRITICAL ]CVSS 9.8EPSS 83.3%kev

Mozilla Multiple Products Remote Code Execution Vulnerability

Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.

Mozilla / Multiple Products
CVE-2024-9680
[ CRITICAL ]CVSS 9.8EPSS 23.2%kev

Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

Mozilla / Firefox
CVE-2016-9079
[ HIGH ]CVSS 7.5EPSS 87.4%kev

Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.

Mozilla / Firefox, Firefox ESR, and Thunderbird
CVE-2015-4495
[ HIGH ]CVSS 8.8EPSS 71.4%kev

Mozilla Firefox Security Feature Bypass Vulnerability

Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.

Mozilla / Firefox
CVE-2019-11707
[ HIGH ]CVSS 8.8EPSS 37.7%kev

Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.

Mozilla / Firefox and Thunderbird
CVE-2019-11708
[ CRITICAL ]CVSS 10.0EPSS 55.9%kev

Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.

Mozilla / Firefox and Thunderbird
CVE-2013-1690
[ HIGH ]CVSS 8.8EPSS 69.0%kev

Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.

Mozilla / Firefox and Thunderbird
CVE-2022-26485
[ HIGH ]CVSS 8.8EPSS 14.3%kev

Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

Mozilla / Firefox
CVE-2022-26486
[ CRITICAL ]CVSS 9.6EPSS 2.3%kev

Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

Mozilla / Firefox
CVE-2013-1675
[ MEDIUM ]CVSS 6.5EPSS 6.7%kev

Mozilla Firefox Information Disclosure Vulnerability

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

Mozilla / Firefox
CVE-2019-17026
[ HIGH ]CVSS 8.8EPSS 46.6%kev

Mozilla Firefox And Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.

Mozilla / Firefox and Thunderbird
CVE-2020-6819
[ HIGH ]CVSS 8.1EPSS 3.0%kev

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

Mozilla / Firefox and Thunderbird
CVE-2020-6820
[ HIGH ]CVSS 8.1EPSS 7.1%kev

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

Mozilla / Firefox and Thunderbird
Articles