Mozilla Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Mozilla products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
14
In CISA KEV
13
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Mozilla KEVs Added by Year
14 Mozilla KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before... |
Firefox, Thunderbird, SeaMonkey | Confirmed | In CISA | 27 Oct 2010 |
|
CVE-2009-1308
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary... |
Firefox, Thunderbird, SeaMonkey | High | Not in CISA | 22 Apr 2009 |
|
CVE-2019-17026
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks... |
Firefox ESR, Thunderbird, Firefox | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-6820
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild... |
Thunderbird, Firefox, Firefox ESR | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-6819
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in... |
Thunderbird, Firefox, Firefox ESR | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2013-1675
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly... |
Firefox, Firefox ESR, Thunderbird, Thunderbird ESR | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-26485
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing... |
Firefox, Firefox ESR, Firefox for Android, Thunderbird, Focus | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2022-26486
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in... |
Firefox, Firefox ESR, Firefox for Android, Thunderbird, Focus | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-1690
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly... |
Firefox, Firefox ESR, Thunderbird, Thunderbird ESR | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2019-11708
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed... |
Firefox ESR, Firefox, Thunderbird | Confirmed | In CISA | 23 May 2022 |
|
CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash.... |
Firefox ESR, Firefox, Thunderbird | Confirmed | In CISA | 23 May 2022 |
|
CVE-2015-4495
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the... |
Firefox | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild... |
Firefox, Firefox ESR, Thunderbird | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of... |
Firefox, Firefox ESR, Thunderbird | Confirmed | In CISA | 15 Oct 2024 |
Common Vulnerability Classes (CWE)
- CWE-416 — Use After Free 5
- CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion') 2
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 2
- CWE-362 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') 1
- CWE-20 — Improper Input Validation 1
- CWE-665 — Improper Initialization 1
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
- CWE-346 — Origin Validation Error 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology