Mozilla
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Mozilla product.
RSS Feeds for Mozilla security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Mozilla products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Mozilla Sorted by Most Security Vulnerabilities since 2018
Recent Mozilla Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-86 | Security Vulnerabilities fixed in Thunderbird 155 mfsa2026-86 | September 1, 2026 |
| mfsa2026-84 | Security Vulnerabilities fixed in Firefox ESR 140.15 mfsa2026-84 | September 1, 2026 |
| mfsa2026-82 | Security Vulnerabilities fixed in Firefox 155 mfsa2026-82 | September 1, 2026 |
| mfsa2026-85 | Security Vulnerabilities fixed in Firefox ESR 153.2 mfsa2026-85 | September 1, 2026 |
| mfsa2026-88 | Security Vulnerabilities fixed in Thunderbird 153.2 mfsa2026-88 | September 1, 2026 |
| mfsa2026-87 | Security Vulnerabilities fixed in Thunderbird 140.15 mfsa2026-87 | September 1, 2026 |
| mfsa2026-83 | Security Vulnerabilities fixed in Firefox ESR 115.40 mfsa2026-83 | September 1, 2026 |
| mfsa2026-81 | Security Vulnerabilities fixed in Firefox for iOS 155.0 mfsa2026-81 | August 31, 2026 |
| mfsa2026-77 | Security Vulnerabilities fixed in Firefox ESR 153.1 mfsa2026-77 | August 18, 2026 |
| mfsa2026-75 | Security Vulnerabilities fixed in Firefox ESR 115.39 mfsa2026-75 | August 18, 2026 |
Known Exploited Mozilla Vulnerabilities
The following Mozilla vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mozilla Multiple Products Remote Code Execution Vulnerability |
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. CVE-2010-3765 Exploit Probability: 83.3% |
October 6, 2025 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CVE-2024-9680 Exploit Probability: 23.2% |
October 15, 2024 |
| Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability |
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. CVE-2016-9079 Exploit Probability: 87.4% |
June 22, 2023 |
| Mozilla Firefox Security Feature Bypass Vulnerability |
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 Exploit Probability: 71.4% |
May 25, 2022 |
| Mozilla Firefox and Thunderbird Type Confusion Vulnerability |
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. CVE-2019-11707 Exploit Probability: 37.7% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability |
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. CVE-2019-11708 Exploit Probability: 55.9% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability |
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service or possibly execute arbitrary code via a crafted web site. CVE-2013-1690 Exploit Probability: 69.0% |
March 28, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 Exploit Probability: 2.3% |
March 7, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 Exploit Probability: 13.8% |
March 7, 2022 |
| Mozilla Firefox Information Disclosure Vulnerability |
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 Exploit Probability: 6.7% |
March 3, 2022 |
| Mozilla Firefox 74 and Firefox ESR 68.6 nsDocShell vulnerability |
A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6819 Exploit Probability: 3.0% |
November 3, 2021 |
| Mozilla Firefox 74 and Firefox ESR 68.6 ReadableStream vulnerability |
A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6820 Exploit Probability: 7.1% |
November 3, 2021 |
| Mozilla Firefox IonMonkey JIT compiler Type Confusion Vulnerability |
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1 CVE-2019-17026 Exploit Probability: 46.6% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Mozilla vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 434 vulnerabilities in Mozilla with an average score of 7.8 out of ten. Last year, in 2025 Mozilla had 209 security vulnerabilities published. That is, 225 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.32.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 434 | 7.78 |
| 2025 | 209 | 7.46 |
| 2024 | 204 | 7.10 |
| 2023 | 202 | 7.24 |
| 2022 | 188 | 7.42 |
| 2021 | 158 | 7.12 |
| 2020 | 184 | 7.25 |
| 2019 | 152 | 7.53 |
| 2018 | 345 | 7.65 |
It may take a day or so for new Mozilla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-84642 | Sep 01, 2026 |
Regex Injection via mail.allowed_attachment_hostnames in Thunderbird <155The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird 153.2. |
|
| CVE-2026-84641 | Sep 01, 2026 |
Thunderbird IMAP use-after-free heap disclosure before 155A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84640 | Sep 01, 2026 |
Mail Header Buffer Overread (Read Past End) in Thunderbird <155 (fixed in 155)A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84639 | Sep 01, 2026 |
Thunderbird Uninitialized Memory Use in MIME Bodies (before 155)Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84637 | Sep 01, 2026 |
Thunderbird <=153: Windows Local Exec via File URI Calendar InvitesMalicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2. |
|
| CVE-2026-84144 | Sep 01, 2026 |
Firefox 154/153.1 memcorr flaw (CVE-2026-84144)Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84143 | Sep 01, 2026 |
Firefox <155 memory corruption CVE-2026-84143Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84142 | Sep 01, 2026 |
Memory Corruption in Firefox 154 (CVE-2026-84142)Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
|
| CVE-2026-84141 | Sep 01, 2026 |
Firefox Integer Overflow in ImageLib (Graphics) Before v155Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84140 | Sep 01, 2026 |
Firefox 153.x+ Site Isolation DOM Navigation Vulnerability (CVE-2026-84140)Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84139 | Sep 01, 2026 |
Firefox DOM Events clickjacking before v155Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84138 | Sep 01, 2026 |
DoS in Firefox PDF Viewer (CVE-2026-84138)Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
|
| CVE-2026-84137 | Sep 01, 2026 |
Firefox DOM Spoofing in Core & HTML Fixed in 155Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84136 | Sep 01, 2026 |
Firefox DOM Navigation Component Vulnerability (Fixed in 155)Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84135 | Sep 01, 2026 |
Mozilla Firefox Focus Android CVE-2026-84135: Other IssueOther issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. |
|
| CVE-2026-84134 | Sep 01, 2026 |
Firefox 155+ Profile Backup component flaw (CVE-2026-84134)Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84133 | Sep 01, 2026 |
Firefox DOM Push Subscriptions site isolation flaw before v155Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84132 | Sep 01, 2026 |
Firefox <155 Info Disclosure in Networking HTTP ComponentInformation disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84130 | Sep 01, 2026 |
Firefox WebGPU Info Disclosure (before v155)Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84129 | Sep 01, 2026 |
Firefox SiteIsolation DOM Navigation Bug Fixed V155 ESR153.2Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84128 | Sep 01, 2026 |
Firefox Privilege Escalation via WebDriver BiDiPrivilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
|
| CVE-2026-84127 | Sep 01, 2026 |
Firefox Android WebExtensions Info DisclosureInformation disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155. |
|
| CVE-2026-84126 | Sep 01, 2026 |
Firefox Grid Layout Boundary Condition Vulnerability (CVE-2026-84126)Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
|
| CVE-2026-84125 | Sep 01, 2026 |
Use-After-Free in Firefox Core & HTML DOM Component <155Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84124 | Sep 01, 2026 |
Use-after-free in Firefox DOM: Core & HTML (before 155)Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84123 | Sep 01, 2026 |
Firefox Privilege Escalation via WebGPU Use-After-Free (before 155)Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84122 | Sep 01, 2026 |
UAF in Firefox Media Component (fixed 155/ESR 140.15/153.2)Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84118 | Sep 01, 2026 |
Use-after-Free in Firefox 155 JS GC component (before 155)Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
| CVE-2026-84117 | Sep 01, 2026 |
Privilege Escalation in Firefox Android 155+Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. |
|
| CVE-2026-84145 | Sep 01, 2026 |
Firefox 154 ESR 115.39 Memory Corruption VulnerabilityInternally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84131 | Sep 01, 2026 |
Firefox Priv Esc Prt Err in Graphics Comp (<155, ESR<115.40, ESR<140.15, ESR<153.2)Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84121 | Sep 01, 2026 |
Firefox Sandbox escape via DOM UAF (fixed in 155)Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84120 | Sep 01, 2026 |
Use-after-free in Audio/Video component of Firefox <155 (ESR 115.40)Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-84119 | Sep 01, 2026 |
Firefox Sandbox Escape UAF in DOM Navigation ComponentSandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
|
| CVE-2026-81267 | Aug 31, 2026 |
Firefox iOS 155.0: Cross-Origin Popup Navigation StallA malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0. |
|
| CVE-2026-74989 | Aug 18, 2026 |
Memory corruption bugs in Firefox 153Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. |
|
| CVE-2026-74988 | Aug 18, 2026 |
Firefox ESR 153.0 Memory Corruption Vulnerability (fixed in 153.1)Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74982 | Aug 18, 2026 |
DoS in Firefox Widget component before 154/ESR153.1Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74986 | Aug 18, 2026 |
CSS Parsing Component Site Isolation Flaw Fixed in Firefox 154 & ESR 153.1Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74985 | Aug 18, 2026 |
Firefox 154 ESR 153.1 Fixed PrivEsc in Enterprise PoliciesPrivilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74984 | Aug 18, 2026 |
Race Condition in JS Engine, Firefox <154, fixed v154Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74980 | Aug 18, 2026 |
Clickjacking Vulnerability in Firefox Android Downloads ComponentClickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. |
|
| CVE-2026-74978 | Aug 18, 2026 |
Clickjacking in Firefox/Thunderbird widget component before v154Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74979 | Aug 18, 2026 |
Mitigation bypass in Addons Manager (Firefox 154, ESR 153.1, Thunderbird 154)Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74981 | Aug 18, 2026 |
Site Isolation Vulnerability in Web Codecs (Firefox <154, Thunderbird <154)Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74970 | Aug 18, 2026 |
Site isolation flaw in Firefox Graphics before v154Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74968 | Aug 18, 2026 |
Site Isolation Flaw in WebRender of Firefox/Thunderbird (v<154)Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74977 | Aug 18, 2026 |
Firefox & Thunderbird Graphics INT Overflow CVE-2026-74977 Fixed 154Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
| CVE-2026-74975 | Aug 18, 2026 |
Firefox Android Downloads Spoofing VulnerabilitySpoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. |
|
| CVE-2026-74956 | Aug 18, 2026 |
Same-Origin Policy Bypass in Service Workers (Firefox <154, Thunderbird <154)Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|