Mozilla Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Mozilla products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

14

In CISA KEV

13

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

Mozilla KEVs Added by Year

Loading...

14 Mozilla KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2010-3765

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before...

Confirmed In CISA 27 Oct 2010
CVE-2009-1308

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary...

High Not in CISA 22 Apr 2009
CVE-2019-17026

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks...

Confirmed In CISA 03 Nov 2021
CVE-2020-6820

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild...

Confirmed In CISA 03 Nov 2021
CVE-2020-6819

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in...

Confirmed In CISA 03 Nov 2021
CVE-2013-1675

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly...

Confirmed In CISA 03 Mar 2022
CVE-2022-26485

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing...

Confirmed In CISA 07 Mar 2022
CVE-2022-26486

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in...

Confirmed In CISA 07 Mar 2022
CVE-2013-1690

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly...

Confirmed In CISA 28 Mar 2022
CVE-2019-11708

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed...

Confirmed In CISA 23 May 2022
CVE-2019-11707

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash....

Confirmed In CISA 23 May 2022
CVE-2015-4495

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the...

Confirmed In CISA 25 May 2022
CVE-2016-9079

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild...

Confirmed In CISA 22 Jun 2023
CVE-2024-9680

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of...

Confirmed In CISA 15 Oct 2024

Common Vulnerability Classes (CWE)

  • CWE-416 — Use After Free 5
  • CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion') 2
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 2
  • CWE-362 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') 1
  • CWE-20 — Improper Input Validation 1
  • CWE-665 — Improper Initialization 1
  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
  • CWE-346 — Origin Validation Error 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology