mozilla
239 known vulnerabilities affecting mozilla products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-16349 | Medium | 0.2% | 9.8 | Same-origin policy bypass in the DOM: Navigation component. This vulnerability w… | |
| CVE-2026-16401 | Medium | 0.2% | 8.8 | Privilege escalation in the Data Loss Prevention component. This vulnerability w… | |
| CVE-2026-16375 | Medium | 0.2% | 9.8 | Site isolation issue in the Networking: HTTP component. This vulnerability was f… | |
| CVE-2026-16387 | Medium | 0.2% | 9.8 | Site isolation issue in the Networking component. This vulnerability was fixed i… | |
| CVE-2026-84129 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-84133 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Push Subscriptions component. This vulnerabilit… | |
| CVE-2026-84140 | Medium | 0.2% | 9.8 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-16381 | Medium | 0.2% | 9.1 | Same-origin policy bypass in the Networking: DNS component. This vulnerability w… | |
| CVE-2026-74960 | Medium | 0.2% | 8.1 | Site isolation issue in the WebExtensions component. This vulnerability was fixe… | |
| CVE-2026-74962 | Medium | 0.2% | 8.1 | Site isolation issue in the Networking: Cookies component. This vulnerability wa… | |
| CVE-2026-16404 | Medium | 0.2% | 7.4 | Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 1… | |
| CVE-2026-74934 | Medium | 0.2% | 7.5 | Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability … | |
| CVE-2026-16398 | Medium | 0.1% | 7.5 | Site isolation issue in the Graphics component. This vulnerability was fixed in … | |
| CVE-2026-16399 | Medium | 0.1% | 7.5 | Site isolation issue in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-74981 | Medium | 0.1% | 8.1 | Site isolation issue in the Audio/Video: Web Codecs component. This vulnerabilit… | |
| CVE-2020-6829 | Low | 1.5% | 5.3 | When performing EC scalar point multiplication, the wNAF point multiplication al… | |
| CVE-2020-15664 | Low | 1.4% | 6.5 | By holding a reference to the eval() function from an about:blank window, a mali… | |
| CVE-2020-15666 | Low | 1.2% | 6.5 | When trying to load a non-video in an audio/video context the exact status code … | |
| CVE-2020-26964 | Low | 0.9% | 6.8 | If the Remote Debugging via USB feature was enabled in Firefox for Android on an… | |
| CVE-2020-26975 | Low | 0.9% | 6.5 | When a malicious application installed on the user's device broadcast an Intent … | |
| CVE-2026-10702 | Low | 0.9% | 4.3 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… | |
| CVE-2020-26977 | Low | 0.9% | 6.5 | By attempting to connect a website using an unresponsive port, an attacker could… | |
| CVE-2020-15661 | Low | 0.8% | 6.5 | A rogue webpage could override the injected WKUserScript used by the logins auto… | |
| CVE-2020-26955 | Low | 0.8% | 6.5 | When a user downloaded a file in Firefox for Android, if a cookie is set, it wou… | |
| CVE-2020-12404 | Low | 0.8% | 4.3 | For native-to-JS bridging the app requires a unique token to be passed that ensu… | |
| CVE-2023-29535 | Low | 0.7% | 6.5 | Following a Garbage Collector compaction, weak maps may have been accessed befor… | |
| CVE-2023-29548 | Low | 0.7% | 6.5 | A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optim… | |
| CVE-2020-12414 | Low | 0.7% | 6.5 | IndexedDB should be cleared when leaving private browsing mode and it is not, th… | |
| CVE-2020-15662 | Low | 0.7% | 6.5 | A rogue webpage could override the injected WKUserScript used by the download fe… | |
| CVE-2020-26954 | Low | 0.6% | 4.3 | When accepting a malicious intent from other installed apps, Firefox for Android… | |
| CVE-2023-29533 | Low | 0.6% | 4.3 | A website could have obscured the fullscreen notification by using a combination… | |
| CVE-2020-26957 | Low | 0.5% | 6.5 | OneCRL was non-functional in the new Firefox for Android due to a missing servic… | |
| CVE-2020-15668 | Low | 0.5% | 4.3 | A lock was missing when accessing a data structure and importing certificate inf… | |
| CVE-2023-29546 | Low | 0.5% | 6.5 | When recording the screen while in Private Browsing on Firefox for Android the a… | |
| CVE-2026-15718 | Low | 0.5% | 4.3 | We are aware that exploit code for this is public however we are not aware of an… | |
| CVE-2020-15671 | Low | 0.5% | 3.1 | When typing in a password under certain conditions, a race may have occured wher… | |
| CVE-2023-29544 | Low | 0.4% | 6.5 | If multiple instances of resource exhaustion occurred at the incorrect time, the… | |
| CVE-2023-5758 | Low | 0.4% | 6.1 | When opening a page in reader mode, the redirect URL could have caused attacker-… | |
| CVE-2026-74945 | Low | 0.4% | 6.5 | Information disclosure in the Graphics: Text component. This vulnerability was f… | |
| CVE-2022-31746 | Low | 0.4% | 6.5 | Internal URLs are protected by a secret UUID key, which could have been leaked t… | |
| CVE-2019-17003 | Low | 0.4% | 6.1 | Scanning a QR code that contained a javascript: URL would have resulted in the J… | |
| CVE-2023-29538 | Low | 0.4% | 4.3 | Under specific circumstances a WebExtension may have received a <code>jar:file:/… | |
| CVE-2022-38474 | Low | 0.4% | 4.3 | A website that had permission to access the microphone could record audio withou… | |
| CVE-2026-15719 | Low | 0.3% | 5.4 | We are aware that exploit code for this is public however we are not aware of an… | |
| CVE-2023-29549 | Low | 0.3% | 6.5 | Under certain circumstances, a call to the <code>bind</code> function may have r… | |
| CVE-2020-12401 | Low | 0.3% | 4.7 | During ECDSA signature generation, padding applied in the nonce designed to ensu… | |
| CVE-2026-8961 | Low | 0.3% | 6.5 | Spoofing issue in the Form Autofill component. This vulnerability was fixed in F… | |
| CVE-2026-74976 | Low | 0.3% | 6.5 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… | |
| CVE-2023-29540 | Low | 0.3% | 6.1 | Using a redirect embedded into <code>sourceMappingUrls</code> could allow for na… | |
| CVE-2026-74948 | Low | 0.3% | 6.5 | Information disclosure in the Graphics component. This vulnerability was fixed i… |