Mozilla
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Mozilla product.
RSS Feeds for Mozilla security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Mozilla products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Mozilla Sorted by Most Security Vulnerabilities since 2018
Recent Mozilla Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-71 | Security Vulnerabilities fixed in Thunderbird 153 mfsa2026-71 | July 21, 2026 |
| mfsa2026-68 | Security Vulnerabilities fixed in Firefox 153 mfsa2026-68 | July 21, 2026 |
| mfsa2026-69 | Security Vulnerabilities fixed in Firefox ESR 115.38 mfsa2026-69 | July 21, 2026 |
| mfsa2026-72 | Security Vulnerabilities fixed in Thunderbird 140.13 mfsa2026-72 | July 21, 2026 |
| mfsa2026-70 | Security Vulnerabilities fixed in Firefox ESR 140.13 mfsa2026-70 | July 21, 2026 |
| mfsa2026-67 | Security Vulnerabilities fixed in Firefox 152.0.6 mfsa2026-67 | July 14, 2026 |
| mfsa2026-66 | Security Vulnerabilities fixed in Firefox for iOS 152.4 mfsa2026-66 | July 13, 2026 |
| mfsa2026-65 | Security Vulnerabilities fixed in Firefox for iOS 152.3 mfsa2026-65 | July 5, 2026 |
| mfsa2026-64 | Security Vulnerabilities fixed in Thunderbird 140.12.1 mfsa2026-64 | June 30, 2026 |
| mfsa2026-63 | Security Vulnerabilities fixed in Thunderbird 152.0.1 mfsa2026-63 | June 30, 2026 |
Known Exploited Mozilla Vulnerabilities
The following Mozilla vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mozilla Multiple Products Remote Code Execution Vulnerability |
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. CVE-2010-3765 Exploit Probability: 83.3% |
October 6, 2025 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CVE-2024-9680 Exploit Probability: 23.2% |
October 15, 2024 |
| Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability |
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. CVE-2016-9079 Exploit Probability: 87.6% |
June 22, 2023 |
| Mozilla Firefox Security Feature Bypass Vulnerability |
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 Exploit Probability: 67.3% |
May 25, 2022 |
| Mozilla Firefox and Thunderbird Type Confusion Vulnerability |
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. CVE-2019-11707 Exploit Probability: 38.0% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability |
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. CVE-2019-11708 Exploit Probability: 55.9% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability |
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service or possibly execute arbitrary code via a crafted web site. CVE-2013-1690 Exploit Probability: 69.0% |
March 28, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 Exploit Probability: 2.3% |
March 7, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 Exploit Probability: 13.8% |
March 7, 2022 |
| Mozilla Firefox Information Disclosure Vulnerability |
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 Exploit Probability: 6.7% |
March 3, 2022 |
| Mozilla Firefox 74 and Firefox ESR 68.6 nsDocShell vulnerability |
A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6819 Exploit Probability: 3.0% |
November 3, 2021 |
| Mozilla Firefox 74 and Firefox ESR 68.6 ReadableStream vulnerability |
A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6820 Exploit Probability: 6.3% |
November 3, 2021 |
| Mozilla Firefox IonMonkey JIT compiler Type Confusion Vulnerability |
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1 CVE-2019-17026 Exploit Probability: 43.7% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Mozilla vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 340 vulnerabilities in Mozilla with an average score of 7.7 out of ten. Last year, in 2025 Mozilla had 209 security vulnerabilities published. That is, 131 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.25.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 340 | 7.72 |
| 2025 | 209 | 7.46 |
| 2024 | 204 | 7.10 |
| 2023 | 202 | 7.24 |
| 2022 | 188 | 7.42 |
| 2021 | 158 | 7.12 |
| 2020 | 184 | 7.25 |
| 2019 | 152 | 7.53 |
| 2018 | 345 | 7.65 |
It may take a day or so for new Mozilla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-14899 | Jul 22, 2026 |
Thunderbird MIME header OBO read before 153The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13. |
|
| CVE-2026-16361 | Jul 21, 2026 |
Firefox ESR Memory Safety Bug (ESR 115.37/140.12) Fixed in 115.38/140.13Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13. |
|
| CVE-2026-16360 | Jul 21, 2026 |
Memory Safety Bugs in Firefox 115.37-140.12 & 152 (fixed 153 ESR)Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16412 | Jul 21, 2026 |
Memory Safety Bugs in Firefox 152 & ESR 140.12 (fixed 153/140.13)Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16411 | Jul 21, 2026 |
Firefox 152 Memory Safety Bugs Causing Arbitrary Code ExecMemory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16410 | Jul 21, 2026 |
Firefox JIT Miscompilation in JS Engine (CVE-2026-16410)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16409 | Jul 21, 2026 |
Firefox 153: Invalid Pointer in PSM ComponentInvalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16408 | Jul 21, 2026 |
Mozilla Firefox: Integer Overflow in Audio/Video Playback ComponentInteger overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16407 | Jul 21, 2026 |
Firefox: Service Workers DOM Mitigation Bypass (CVE-2026-16407)Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16406 | Jul 21, 2026 |
Mitigation Bypass in Firefox Networking ComponentMitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16404 | Jul 21, 2026 |
Spoofing Vulnerability CVE-2026-16404 in Firefox AndroidSpoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. |
|
| CVE-2026-16405 | Jul 21, 2026 |
Info disclosure in Firefox WebSockets before v153/ESR140.13Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16403 | Jul 21, 2026 |
Address Bar Spoofing Issue in FirefoxSpoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16402 | Jul 21, 2026 |
Firefox Integer Overflow: ImageLib Component (Fixed in v153)Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16401 | Jul 21, 2026 |
Firefox DLP Component Privilege Escalation (CVE-2026-16401)Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16400 | Jul 21, 2026 |
Firefox DOM Security Component Info Disclosure (CVE-2026-16400)Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16399 | Jul 21, 2026 |
Firefox DOM Navigation Site Isolation VulnerabilitySite isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16398 | Jul 21, 2026 |
Firefox Graphics Site Isolation FlawSite isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16397 | Jul 21, 2026 |
Firefox Android WebExt Clickjacking via UI ManipulationClickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153. |
|
| CVE-2026-16396 | Jul 21, 2026 |
Firefox WebExtensions Privilege Escalation Fixed in v153 & ESR 140.13Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16395 | Jul 21, 2026 |
Integer Overflow in Firefox AV ComponentInteger overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16394 | Jul 21, 2026 |
Firefox DOM Mitigation Bypass in Security ComponentMitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16393 | Jul 21, 2026 |
Firefox WebGPU Boundary Condition VulnerabilityIncorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16359 | Jul 21, 2026 |
Firefox GMP Boundary Condition Vulnerability Fixed in 153/115.38/140.13Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16392 | Jul 21, 2026 |
Firefox JIT Engine Miscompilation CVE-2026-16392JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16391 | Jul 21, 2026 |
Mozilla Firefox <153 ESR 140.13: IndexedDB Info DisclosureInformation disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16390 | Jul 21, 2026 |
Firefox Mitigation Bypass in Enterprise Policies (before 153 / ESR 140.13)Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16389 | Jul 21, 2026 |
Integer overflow in Mozilla NSS LibrariesIncorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16388 | Jul 21, 2026 |
Firefox Sandbox Escape: DOM Networking ComponentSandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16386 | Jul 21, 2026 |
CVE-2026-16386: WebGPU Uninitialized Memory Disclosure in FirefoxInformation disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16387 | Jul 21, 2026 |
Site Isolation Issue in Firefox Networking Component (fixed in 153/140.13)Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16385 | Jul 21, 2026 |
Info Disclosure via Uninit Mem in Firefox WebGPUInformation disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16384 | Jul 21, 2026 |
Firefox WebGPU Uninitialized Memory DisclosureInformation disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16383 | Jul 21, 2026 |
Mitigation Bypass in Firefox DOM Networking (before 153/140.13)Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16382 | Jul 21, 2026 |
Firefox service workers mitigation bypass (CVE-2026-16382)Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16380 | Jul 21, 2026 |
Mitigation bypass in Firefox Networking componentMitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16381 | Jul 21, 2026 |
Firefox Same-Op Policy Bypass in Networking:DNS (pre-153/140.13)Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16358 | Jul 21, 2026 |
CVE-2026-16358: FireFox WebRender Site Isolation Fix 153Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16379 | Jul 21, 2026 |
Privilege Escalation via DOM in Firefox 153/ESR 140.13Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16378 | Jul 21, 2026 |
Firefox DOM Copy&Paste/Drag&Drop IssueOther issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16377 | Jul 21, 2026 |
Mitigation Bypass in Firefox PDF Viewer (before v153, ESR 140.13)Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16376 | Jul 21, 2026 |
DoS via WebGPU in FirefoxDenial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16374 | Jul 21, 2026 |
Info Disclosure in Firefox DevTools Framework (153)Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16375 | Jul 21, 2026 |
Site Isolation Flaw in Firefox HTTP Network (fixed 153, ESR140.13)Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16373 | Jul 21, 2026 |
Firefox Android Info Disclosure Privacy Comp.Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153. |
|
| CVE-2026-16372 | Jul 21, 2026 |
Privilege Escalation in Firefox DOM Content Process ComponentPrivilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16371 | Jul 21, 2026 |
Firefox 153 Priv Esc in DOM Nav ComponentPrivilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16370 | Jul 21, 2026 |
Firefox Networking Component DOM Mitigation BypassMitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
|
| CVE-2026-16357 | Jul 21, 2026 |
Boundary Cond. Bug in Firefox Graphics (Fixed before v153)Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|
| CVE-2026-16356 | Jul 21, 2026 |
Firefox UAF Sandbox Escape in Disability Access APIs (pre153)Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
|