Mozilla records
3,824 published records for vendor mozilla.
Researcher profile
- Entered KEV
- 15 · 0.4%
- Weaponized
- 39 · 1%
- Pre-auth RCE
- 1,052
- With a fix record
- 67.7%
- Median publish → KEV
- 611 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer423
- CWE-416 Use After Free302
- CWE-787 Out-of-bounds Write202
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')202
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor198
- CWE-20 Improper Input Validation170
The weakness classes this vendor ships most often: where to look.
CWEAll records
3,824 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2023-4863Weaponized | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | High8.8 | KEV | 100.0% | Sep 12, 2023 |
94Now | CVE-2010-3765Weaponized | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x befmozilla · firefox · CWE-119 | Critical9.8 | KEV | 83.2% | Oct 27, 2010 |
87Now | CVE-2019-11708Weaponized | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxemozilla · firefox · CWE-20 | Critical10.0 | KEV | 55.9% | Jul 23, 2019 |
86Now | CVE-2016-9079Weaponized | A use-after-free vulnerability in SVG Animation has been discovered.debian · debian linux · CWE-416 | High7.5 | KEV | 87.4% | Jun 11, 2018 |
86Now | CVE-2013-1690Weaponized | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | High8.8 | KEV | 69.0% | Jun 25, 2013 |
86Now | CVE-2015-4495Weaponized | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypassmozilla · firefox · CWE-346 | High8.8 | KEV | 68.6% | Aug 7, 2015 |
80Now | CVE-2023-5217Weaponized | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potengoogle · chrome · CWE-787 | High8.8 | KEV | 49.0% | Sep 28, 2023 |
79This week | CVE-2019-17026Weaponized | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.mozilla · firefox · CWE-843 | High8.8 | KEV | 46.3% | Mar 2, 2020 |
76This week | CVE-2019-11707Weaponized | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.mozilla · firefox · CWE-843 | High8.8 | KEV | 37.7% | Jul 23, 2019 |
76This week | CVE-2024-9680Weaponized | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.mozilla · firefox · CWE-416 | Critical9.8 | KEV | 23.2% | Oct 9, 2024 |
69This week | CVE-2022-26485Weaponized | Removing an XSLT parameter during processing could have lead to an exploitable use-after-free.mozilla · firefox · CWE-416 | High8.8 | KEV | 14.3% | Dec 22, 2022 |
69This week | CVE-2022-26486Weaponized | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.mozilla · firefox · CWE-416 | Critical9.6 | KEV | 2.3% | Dec 22, 2022 |
65This week | CVE-2009-3555Proof of concept | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Critical9.8 | — | 87.3% | Nov 9, 2009 |
64This week | CVE-2014-1511Weaponized | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypamozilla · firefox · CWE-269 | Critical9.8 | — | 83.6% | Mar 19, 2014 |
64This week | CVE-2014-1510Weaponized | The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 mozilla · firefox · CWE-269 | Critical9.8 | — | 82.3% | Mar 19, 2014 |
64This week | CVE-2020-6820Weaponized | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | High8.1 | KEV | 7.1% | Apr 24, 2020 |
63This week | CVE-2011-2371Weaponized | Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMmozilla · seamonkey · CWE-189 | Critical10.0 | — | 75.7% | Jun 30, 2011 |
63This week | CVE-2020-6819Weaponized | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | High8.1 | KEV | 3.0% | Apr 24, 2020 |
62This week | CVE-2011-0065Weaponized | Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers mozilla · firefox · CWE-399 | Critical10.0 | — | 73.8% | May 7, 2011 |
61This week | CVE-2011-0073Weaponized | Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, whichmozilla · firefox · CWE-20 | Critical10.0 | — | 70.2% | May 7, 2011 |
59Plan | CVE-2013-0758Weaponized | Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before mozilla · firefox · CWE-94 | Critical9.3 | — | 73.4% | Jan 13, 2013 |
58Plan | CVE-2013-1675Weaponized | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not propermozilla · firefox · CWE-665 | Medium6.5 | KEV | 6.7% | May 16, 2013 |
56Plan | CVE-2024-4367Proof of concept | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.mozilla · firefox · CWE-754 | High8.8 | — | 70.7% | May 14, 2024 |
55Plan | CVE-2013-0757Weaponized | The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thmozilla · firefox · CWE-20 | Critical9.3 | — | 60.9% | Jan 13, 2013 |
54Plan | CVE-2006-3677Weaponized | Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain propertimozilla · firefox · CWE-16 | High7.5 | — | 78.7% | Jul 27, 2006 |
- CVE-2023-486395Now
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
HighCVSS 8.8KEVWeaponizedEPSS 100%google · chromeSep 12, 2023
- CVE-2010-376594Now
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef
CriticalCVSS 9.8KEVWeaponizedEPSS 83%mozilla · firefoxOct 27, 2010
- CVE-2019-1170887Now
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxe
CriticalCVSS 10.0KEVWeaponizedEPSS 56%mozilla · firefoxJul 23, 2019
- CVE-2016-907986Now
A use-after-free vulnerability in SVG Animation has been discovered.
HighCVSS 7.5KEVWeaponizedEPSS 87%debian · debian linuxJun 11, 2018
- CVE-2013-169086Now
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
HighCVSS 8.8KEVWeaponizedEPSS 69%mozilla · firefoxJun 25, 2013
- CVE-2015-449586Now
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass
HighCVSS 8.8KEVWeaponizedEPSS 69%mozilla · firefoxAug 7, 2015
- CVE-2023-521780Now
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten
HighCVSS 8.8KEVWeaponizedEPSS 49%google · chromeSep 28, 2023
- CVE-2019-1702679This week
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.
HighCVSS 8.8KEVWeaponizedEPSS 46%mozilla · firefoxMar 2, 2020
- CVE-2019-1170776This week
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.
HighCVSS 8.8KEVWeaponizedEPSS 38%mozilla · firefoxJul 23, 2019
- CVE-2024-968076This week
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.
CriticalCVSS 9.8KEVWeaponizedEPSS 23%mozilla · firefoxOct 9, 2024
- CVE-2022-2648569This week
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free.
HighCVSS 8.8KEVWeaponizedEPSS 14%mozilla · firefoxDec 22, 2022
- CVE-2022-2648669This week
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.
CriticalCVSS 9.6KEVWeaponizedEPSS 2%mozilla · firefoxDec 22, 2022
- CVE-2009-355565This week
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
CriticalCVSS 9.8Proof of conceptEPSS 87%apache · http serverNov 9, 2009
- CVE-2014-151164This week
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypa
CriticalCVSS 9.8WeaponizedEPSS 84%mozilla · firefoxMar 19, 2014
- CVE-2014-151064This week
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25
CriticalCVSS 9.8WeaponizedEPSS 82%mozilla · firefoxMar 19, 2014
- CVE-2020-682064This week
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.
HighCVSS 8.1KEVWeaponizedEPSS 7%mozilla · firefoxApr 24, 2020
- CVE-2011-237163This week
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaM
CriticalCVSS 10.0WeaponizedEPSS 76%mozilla · seamonkeyJun 30, 2011
- CVE-2020-681963This week
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.
HighCVSS 8.1KEVWeaponizedEPSS 3%mozilla · firefoxApr 24, 2020
- CVE-2011-006562This week
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers
CriticalCVSS 10.0WeaponizedEPSS 74%mozilla · firefoxMay 7, 2011
- CVE-2011-007361This week
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which
CriticalCVSS 10.0WeaponizedEPSS 70%mozilla · firefoxMay 7, 2011
- CVE-2013-075859Plan
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before
CriticalCVSS 9.3WeaponizedEPSS 73%mozilla · firefoxJan 13, 2013
- CVE-2013-167558Plan
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper
MediumCVSS 6.5KEVWeaponizedEPSS 7%mozilla · firefoxMay 16, 2013
- CVE-2024-436756Plan
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
HighCVSS 8.8Proof of conceptEPSS 71%mozilla · firefoxMay 14, 2024
- CVE-2013-075755Plan
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Th
CriticalCVSS 9.3WeaponizedEPSS 61%mozilla · firefoxJan 13, 2013
- CVE-2006-367754Plan
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti
HighCVSS 7.5WeaponizedEPSS 79%mozilla · firefoxJul 27, 2006