Vulnerabilities (CVE)

Filtered by vendor Mozilla Subscribe
Total 3234 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-6612 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 5.3 MEDIUM
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6613 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 5.5 MEDIUM
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6614 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 4.3 MEDIUM
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6615 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 8.8 HIGH
Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-5702 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 7.5 HIGH
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-5700 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 7.0 HIGH
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-9391 1 Mozilla 1 Firefox 2025-04-04 N/A 6.5 MEDIUM
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
CVE-2024-9392 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 9.8 CRITICAL
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-9395 1 Mozilla 1 Firefox 2025-04-04 N/A 5.3 MEDIUM
A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.
CVE-2024-9396 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 8.8 HIGH
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-9400 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 8.8 HIGH
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-9401 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 9.8 CRITICAL
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-9402 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 9.8 CRITICAL
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-7652 1 Mozilla 2 Firefox, Thunderbird 2025-04-04 N/A 7.5 HIGH
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
CVE-2024-10004 1 Mozilla 1 Firefox 2025-04-04 N/A 9.1 CRITICAL
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
CVE-2024-4765 1 Mozilla 1 Firefox 2025-04-04 N/A 8.1 HIGH
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
CVE-2024-4766 2 Google, Mozilla 2 Android, Firefox 2025-04-04 N/A 4.3 MEDIUM
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
CVE-2024-4773 1 Mozilla 1 Firefox 2025-04-04 N/A 7.5 HIGH
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.
CVE-2024-4778 1 Mozilla 1 Firefox 2025-04-04 N/A 9.8 CRITICAL
Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126.
CVE-2024-5022 1 Mozilla 1 Firefox Focus 2025-04-04 N/A 4.4 MEDIUM
The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This vulnerability affects Focus for iOS < 126.