Mozilla Mozilla

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Mozilla product.

RSS Feeds for Mozilla security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Mozilla products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Mozilla Sorted by Most Security Vulnerabilities since 2018

Mozilla Firefox2300 vulnerabilities
Open source web browser

Mozilla Thunderbird1522 vulnerabilities
Email client

Mozilla SeaMonkey286 vulnerabilities
Browser, email and newsgroup client

Mozilla Thunderbird Esr217 vulnerabilities

Mozilla Focus24 vulnerabilities

Mozilla Firefox Mobile21 vulnerabilities

Mozilla Firefox Focus17 vulnerabilities

Mozilla9 vulnerabilities

Mozilla Nss8 vulnerabilities

Mozilla Firefox Os5 vulnerabilities

Mozilla Vpn4 vulnerabilities

Mozilla Nunjucks1 vulnerability

Mozilla Zamboni1 vulnerability

Recent Mozilla Security Advisories

Advisory Title Published
mfsa2026-71 Security Vulnerabilities fixed in Thunderbird 153 mfsa2026-71 July 21, 2026
mfsa2026-68 Security Vulnerabilities fixed in Firefox 153 mfsa2026-68 July 21, 2026
mfsa2026-69 Security Vulnerabilities fixed in Firefox ESR 115.38 mfsa2026-69 July 21, 2026
mfsa2026-72 Security Vulnerabilities fixed in Thunderbird 140.13 mfsa2026-72 July 21, 2026
mfsa2026-70 Security Vulnerabilities fixed in Firefox ESR 140.13 mfsa2026-70 July 21, 2026
mfsa2026-67 Security Vulnerabilities fixed in Firefox 152.0.6 mfsa2026-67 July 14, 2026
mfsa2026-66 Security Vulnerabilities fixed in Firefox for iOS 152.4 mfsa2026-66 July 13, 2026
mfsa2026-65 Security Vulnerabilities fixed in Firefox for iOS 152.3 mfsa2026-65 July 5, 2026
mfsa2026-64 Security Vulnerabilities fixed in Thunderbird 140.12.1 mfsa2026-64 June 30, 2026
mfsa2026-63 Security Vulnerabilities fixed in Thunderbird 152.0.1 mfsa2026-63 June 30, 2026

Known Exploited Mozilla Vulnerabilities

The following Mozilla vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Mozilla Multiple Products Remote Code Execution Vulnerability Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.
CVE-2010-3765 Exploit Probability: 83.3%
October 6, 2025
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
CVE-2024-9680 Exploit Probability: 23.2%
October 15, 2024
Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
CVE-2016-9079 Exploit Probability: 87.6%
June 22, 2023
Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-4495 Exploit Probability: 67.3%
May 25, 2022
Mozilla Firefox and Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2019-11707 Exploit Probability: 38.0%
May 23, 2022
Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2019-11708 Exploit Probability: 55.9%
May 23, 2022
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service or possibly execute arbitrary code via a crafted web site.
CVE-2013-1690 Exploit Probability: 69.0%
March 28, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
CVE-2022-26486 Exploit Probability: 2.3%
March 7, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
CVE-2022-26485 Exploit Probability: 13.8%
March 7, 2022
Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
CVE-2013-1675 Exploit Probability: 6.7%
March 3, 2022
Mozilla Firefox 74 and Firefox ESR 68.6 nsDocShell vulnerability A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CVE-2020-6819 Exploit Probability: 3.0%
November 3, 2021
Mozilla Firefox 74 and Firefox ESR 68.6 ReadableStream vulnerability A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CVE-2020-6820 Exploit Probability: 6.3%
November 3, 2021
Mozilla Firefox IonMonkey JIT compiler Type Confusion Vulnerability Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1
CVE-2019-17026 Exploit Probability: 43.7%
November 3, 2021

Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Mozilla vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 340 vulnerabilities in Mozilla with an average score of 7.7 out of ten. Last year, in 2025 Mozilla had 209 security vulnerabilities published. That is, 131 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.25.




Year Vulnerabilities Average Score
2026 340 7.72
2025 209 7.46
2024 204 7.10
2023 202 7.24
2022 188 7.42
2021 158 7.12
2020 184 7.25
2019 152 7.53
2018 345 7.65

It may take a day or so for new Mozilla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-14899 Jul 22, 2026
Thunderbird MIME header OBO read before 153 The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
Thunderbird
CVE-2026-16361 Jul 21, 2026
Firefox ESR Memory Safety Bug (ESR 115.37/140.12) Fixed in 115.38/140.13 Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16360 Jul 21, 2026
Memory Safety Bugs in Firefox 115.37-140.12 & 152 (fixed 153 ESR) Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16412 Jul 21, 2026
Memory Safety Bugs in Firefox 152 & ESR 140.12 (fixed 153/140.13) Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16411 Jul 21, 2026
Firefox 152 Memory Safety Bugs Causing Arbitrary Code Exec Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16410 Jul 21, 2026
Firefox JIT Miscompilation in JS Engine (CVE-2026-16410) JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16409 Jul 21, 2026
Firefox 153: Invalid Pointer in PSM Component Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16408 Jul 21, 2026
Mozilla Firefox: Integer Overflow in Audio/Video Playback Component Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16407 Jul 21, 2026
Firefox: Service Workers DOM Mitigation Bypass (CVE-2026-16407) Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16406 Jul 21, 2026
Mitigation Bypass in Firefox Networking Component Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16404 Jul 21, 2026
Spoofing Vulnerability CVE-2026-16404 in Firefox Android Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
Firefox
CVE-2026-16405 Jul 21, 2026
Info disclosure in Firefox WebSockets before v153/ESR140.13 Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16403 Jul 21, 2026
Address Bar Spoofing Issue in Firefox Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16402 Jul 21, 2026
Firefox Integer Overflow: ImageLib Component (Fixed in v153) Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16401 Jul 21, 2026
Firefox DLP Component Privilege Escalation (CVE-2026-16401) Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16400 Jul 21, 2026
Firefox DOM Security Component Info Disclosure (CVE-2026-16400) Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16399 Jul 21, 2026
Firefox DOM Navigation Site Isolation Vulnerability Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16398 Jul 21, 2026
Firefox Graphics Site Isolation Flaw Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16397 Jul 21, 2026
Firefox Android WebExt Clickjacking via UI Manipulation Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
Firefox
CVE-2026-16396 Jul 21, 2026
Firefox WebExtensions Privilege Escalation Fixed in v153 & ESR 140.13 Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16395 Jul 21, 2026
Integer Overflow in Firefox AV Component Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16394 Jul 21, 2026
Firefox DOM Mitigation Bypass in Security Component Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16393 Jul 21, 2026
Firefox WebGPU Boundary Condition Vulnerability Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16359 Jul 21, 2026
Firefox GMP Boundary Condition Vulnerability Fixed in 153/115.38/140.13 Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16392 Jul 21, 2026
Firefox JIT Engine Miscompilation CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16391 Jul 21, 2026
Mozilla Firefox <153 ESR 140.13: IndexedDB Info Disclosure Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16390 Jul 21, 2026
Firefox Mitigation Bypass in Enterprise Policies (before 153 / ESR 140.13) Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16389 Jul 21, 2026
Integer overflow in Mozilla NSS Libraries Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16388 Jul 21, 2026
Firefox Sandbox Escape: DOM Networking Component Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16386 Jul 21, 2026
CVE-2026-16386: WebGPU Uninitialized Memory Disclosure in Firefox Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16387 Jul 21, 2026
Site Isolation Issue in Firefox Networking Component (fixed in 153/140.13) Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16385 Jul 21, 2026
Info Disclosure via Uninit Mem in Firefox WebGPU Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16384 Jul 21, 2026
Firefox WebGPU Uninitialized Memory Disclosure Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16383 Jul 21, 2026
Mitigation Bypass in Firefox DOM Networking (before 153/140.13) Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16382 Jul 21, 2026
Firefox service workers mitigation bypass (CVE-2026-16382) Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16380 Jul 21, 2026
Mitigation bypass in Firefox Networking component Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16381 Jul 21, 2026
Firefox Same-Op Policy Bypass in Networking:DNS (pre-153/140.13) Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16358 Jul 21, 2026
CVE-2026-16358: FireFox WebRender Site Isolation Fix 153 Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16379 Jul 21, 2026
Privilege Escalation via DOM in Firefox 153/ESR 140.13 Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16378 Jul 21, 2026
Firefox DOM Copy&Paste/Drag&Drop Issue Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16377 Jul 21, 2026
Mitigation Bypass in Firefox PDF Viewer (before v153, ESR 140.13) Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16376 Jul 21, 2026
DoS via WebGPU in Firefox Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16374 Jul 21, 2026
Info Disclosure in Firefox DevTools Framework (153) Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16375 Jul 21, 2026
Site Isolation Flaw in Firefox HTTP Network (fixed 153, ESR140.13) Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16373 Jul 21, 2026
Firefox Android Info Disclosure Privacy Comp. Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
Firefox
CVE-2026-16372 Jul 21, 2026
Privilege Escalation in Firefox DOM Content Process Component Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16371 Jul 21, 2026
Firefox 153 Priv Esc in DOM Nav Component Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16370 Jul 21, 2026
Firefox Networking Component DOM Mitigation Bypass Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Firefox
Thunderbird
CVE-2026-16357 Jul 21, 2026
Boundary Cond. Bug in Firefox Graphics (Fixed before v153) Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
CVE-2026-16356 Jul 21, 2026
Firefox UAF Sandbox Escape in Disability Access APIs (pre153) Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Firefox
Thunderbird
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.