Mozilla
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Mozilla product.
RSS Feeds for Mozilla security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Mozilla products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Mozilla Sorted by Most Security Vulnerabilities since 2018
Recent Mozilla Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-61 | Security Vulnerabilities fixed in Thunderbird 140.12 mfsa2026-61 | June 16, 2026 |
| mfsa2026-58 | Security Vulnerabilities fixed in Firefox ESR 140.12 mfsa2026-58 | June 16, 2026 |
| mfsa2026-59 | Security Vulnerabilities fixed in Firefox ESR 115.37 mfsa2026-59 | June 16, 2026 |
| mfsa2026-60 | Security Vulnerabilities fixed in Thunderbird 152 mfsa2026-60 | June 16, 2026 |
| mfsa2026-57 | Security Vulnerabilities fixed in Firefox 152 mfsa2026-57 | June 16, 2026 |
| mfsa2026-56 | Security Vulnerabilities fixed in Firefox for iOS 152.0 mfsa2026-56 | June 16, 2026 |
| mfsa2026-55 | Security Vulnerabilities fixed in Focus for iOS / Klar 151.3.1 mfsa2026-55 | June 9, 2026 |
| mfsa2026-54 | Security Vulnerabilities fixed in Firefox 151.0.3 mfsa2026-54 | June 2, 2026 |
| mfsa2026-53 | Security Vulnerabilities fixed in Firefox for iOS 151.2 mfsa2026-53 | June 1, 2026 |
| mfsa2026-52 | Security Vulnerabilities fixed in Firefox for iOS 151.1 mfsa2026-52 | May 25, 2026 |
Known Exploited Mozilla Vulnerabilities
The following Mozilla vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mozilla Multiple Products Remote Code Execution Vulnerability |
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. CVE-2010-3765 Exploit Probability: 83.3% |
October 6, 2025 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CVE-2024-9680 Exploit Probability: 32.6% |
October 15, 2024 |
| Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability |
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. CVE-2016-9079 Exploit Probability: 87.9% |
June 22, 2023 |
| Mozilla Firefox Security Feature Bypass Vulnerability |
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 Exploit Probability: 70.2% |
May 25, 2022 |
| Mozilla Firefox and Thunderbird Type Confusion Vulnerability |
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. CVE-2019-11707 Exploit Probability: 38.0% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability |
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. CVE-2019-11708 Exploit Probability: 55.9% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability |
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service or possibly execute arbitrary code via a crafted web site. CVE-2013-1690 Exploit Probability: 69.2% |
March 28, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 Exploit Probability: 2.3% |
March 7, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 Exploit Probability: 14.3% |
March 7, 2022 |
| Mozilla Firefox Information Disclosure Vulnerability |
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 Exploit Probability: 6.7% |
March 3, 2022 |
| Mozilla Firefox 74 and Firefox ESR 68.6 nsDocShell vulnerability |
A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6819 Exploit Probability: 3.0% |
November 3, 2021 |
| Mozilla Firefox 74 and Firefox ESR 68.6 ReadableStream vulnerability |
A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6820 Exploit Probability: 6.3% |
November 3, 2021 |
| Mozilla Firefox IonMonkey JIT compiler Type Confusion Vulnerability |
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1 CVE-2019-17026 Exploit Probability: 46.6% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Mozilla vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 268 vulnerabilities in Mozilla with an average score of 7.9 out of ten. Last year, in 2025 Mozilla had 209 security vulnerabilities published. That is, 59 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.44.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 268 | 7.90 |
| 2025 | 209 | 7.46 |
| 2024 | 204 | 7.10 |
| 2023 | 202 | 7.24 |
| 2022 | 188 | 7.42 |
| 2021 | 158 | 7.12 |
| 2020 | 184 | 7.25 |
| 2019 | 152 | 7.53 |
| 2018 | 345 | 7.65 |
It may take a day or so for new Mozilla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-53900 | Jun 16, 2026 |
Cookies Across Redirect in Firefox iOS before 152.0 (TemporaryDocument)Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability was fixed in Firefox for iOS 152.0. |
|
| CVE-2026-53899 | Jun 16, 2026 |
Firefox-iOS 152.0 & Before: Partial Domain Matching Cookie Leak in PDF RequestsFirefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the target site. This vulnerability was fixed in Firefox for iOS 152.0. |
|
| CVE-2026-12330 | Jun 16, 2026 |
Firefox ESR 115.37/140.12: I18N Boundary Condition FlawIncorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12. |
|
| CVE-2026-12329 | Jun 16, 2026 |
CVE-2026-12329: Firefox ESR 140.12 Memory Safety BugMemory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. |
|
| CVE-2026-12328 | Jun 16, 2026 |
Firefox ESR 115.36115.37, ESR 140.11140.12 & 151 Memory Corruption (Arbitrary Code)Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12327 | Jun 16, 2026 |
MemorySafety Bugs in Firefox 151 & Thunderbird 151, Fixed in 152Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12326 | Jun 16, 2026 |
Memory Corruption in Firefox/Thunderbird 151 Enables RCEMemory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12325 | Jun 16, 2026 |
DoS via ImageLib in Firefox 152 & ESR 140.12/115.37 (fixed)Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12324 | Jun 16, 2026 |
Graphics: CanvasWebGL Boundary Condition Vulnerability in Firefox <152Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12323 | Jun 16, 2026 |
Firefox DOM: Core & HTML Spoofing Vulnerability (CVE-2026-12323)Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12322 | Jun 16, 2026 |
Clickjacking via Firefox GTK WidgetClickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12321 | Jun 16, 2026 |
Firefox JIT miscompilation in JS WebAssembly component (CVE-2026-12321)JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12320 | Jun 16, 2026 |
Info Disclosure in FF Password ManagerInformation disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12319 | Jun 16, 2026 |
DoS via Audio/Video Playback in Firefox 152 (Mozilla)Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12318 | Jun 16, 2026 |
Moz NSS: Boundary Condition Flaw in Libraries ComponentIncorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12317 | Jun 16, 2026 |
Memory Safety Vulnerability in Firefox 152Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12316 | Jun 16, 2026 |
DOM Mitigation Bypass in Firefox Security ComponentMitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12315 | Jun 16, 2026 |
Firefox 152 DOM Mitigation Bypass in Security ComponentMitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12314 | Jun 16, 2026 |
Firefox Memory Safety Bug - Fixed in v152, ESR 140.12Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12313 | Jun 16, 2026 |
CVE-2026-12313: Info Disclosure via Sandbox Escape in Process Sandboxing (Pre-152)Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12312 | Jun 16, 2026 |
Firefox 152: Memory Safety Bug Fixed ESR 140.12 UpdateMemory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12311 | Jun 16, 2026 |
Firefox 152/140.12 Process Sandboxing Disclosure & Sandbox EscapeInformation disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12310 | Jun 16, 2026 |
Firefox 152 Memory Safety Bug (CVE-2026-12310)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12309 | Jun 16, 2026 |
Memory safety bug in Firefox <152, fixed in 152 & ESR 140.12Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12308 | Jun 16, 2026 |
Memory safety bug in Firefox before 152 (ESR 140.12)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12307 | Jun 16, 2026 |
CVE-2026-12307: Memory safety bug in Firefox <152 (ESR 140.12) fixedMemory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12306 | Jun 16, 2026 |
Firefox 152 MemSafe Bug FixedMemory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12305 | Jun 16, 2026 |
Memory safety bug before Firefox 152, fixed in 152 & ESR 140.12Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12304 | Jun 16, 2026 |
Same-origin Policy Bypass in Firefox Networking:Cookies (before FF 152)Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12303 | Jun 16, 2026 |
CVE-2026-12303 Info Disclosure via WebGPU Boundary Conditions in FirefoxInformation disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12302 | Jun 16, 2026 |
Firefox Mitigation Bypass in DOM Component before 152 / ESR 140.12 / 115.37Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12301 | Jun 16, 2026 |
Firefox 152 Memory Safety VulnerabilityMemory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12300 | Jun 16, 2026 |
Firefox mem safety bug CVE-2026-12300 fixed in v152Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12299 | Jun 16, 2026 |
Firefox JIT Miscompilation in DOM Core & HTML (before 152, ESR 140.12, 115.37)JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12298 | Jun 16, 2026 |
Memory safety bug in Firefox before 152 (fixed in 152)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12297 | Jun 16, 2026 |
Firefox Sandbox Escape (Networking Boundary, pre-152)Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12296 | Jun 16, 2026 |
Firefox 152 Sandbox Escape in Process Sandboxing ComponentSandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12295 | Jun 16, 2026 |
Sandbox Esc. in DOM Nav. - Firefox <152 (ESR 140.12/115.37)Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12294 | Jun 16, 2026 |
Firefox Sandbox Escape via DOM Workers (pre-152, ESR 140.12, ESR 115.37)Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12293 | Jun 16, 2026 |
UAF in Firefox 152 WebGPUUse-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
| CVE-2026-12292 | Jun 16, 2026 |
CVE-2026-12292: Firefox Web Audio boundary flaw (v<152)Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12291 | Jun 16, 2026 |
Use-after-free in Firefox Networking HTTP before 152Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12290 | Jun 16, 2026 |
Firefox Memory Safety bug fixed in 152 ESR 140.12/115.37Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-12289 | Jun 16, 2026 |
Firefox WebRender Privilege Escalation before 152Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
|
| CVE-2026-11799 | Jun 09, 2026 |
UXSS in Focus & Klar WebKit Nav Fixed in 151.3.1UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1. |
|
| CVE-2026-10702 | Jun 02, 2026 |
Firefox JIT miscompilation before v151.0.3JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. |
|
| CVE-2026-10701 | Jun 02, 2026 |
Firefox 151.0.3 - Graphics Text boundary error (CVE-2026-10701)Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3. |
|
| CVE-2026-9308 | Jun 01, 2026 |
CVE-2026-9308: Firefox iOS Reader View Templating flaw -> arbitrary JS exec before 151.2Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2. |
|
| CVE-2026-9309 | Jun 01, 2026 |
Firefox iOS Reader View XSS via JSONLD (fixed in v151.2)Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2. |
|
| CVE-2026-9078 | May 25, 2026 |
Firefox for iOS 151.1: RTL/IDN Link Preview Spoof VulnerabilityFirefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1. |
|