mozilla security advisories
44 threat alerts tracking vulnerabilities and security advisories that affect mozilla products.
Vulnios monitors mozilla CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent mozilla security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2025-14860 — mozilla — firefox
Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.
criticalCVE-2025-14860Critical Vulnerability: CVE-2026-92238 — mozilla — thunderbird
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and
criticalCVE-2026-92238Critical Vulnerability: CVE-2026-92240 — mozilla — thunderbird
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachabl
criticalCVE-2026-92240Critical Vulnerability: CVE-2026-2771 — mozilla — firefox, thunderbird
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
criticalCVE-2026-2771Critical Vulnerability: CVE-2026-84133 — mozilla — firefox, thunderbird
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
criticalCVE-2026-84133Critical Vulnerability: CVE-2026-84134 — mozilla — firefox, thunderbird
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
criticalCVE-2026-84134Critical Vulnerability: CVE-2026-84135 — mozilla — firefox_mobile
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
criticalCVE-2026-84135Critical Vulnerability: CVE-2026-84140 — mozilla — firefox, thunderbird
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
criticalCVE-2026-84140Critical Vulnerability: CVE-2026-84141 — mozilla — firefox, thunderbird
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
criticalCVE-2026-84141Critical Vulnerability: CVE-2026-84142 — mozilla — firefox, thunderbird
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could
criticalCVE-2026-84142Critical Vulnerability: CVE-2026-84143 — mozilla — firefox, thunderbird
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we p
criticalCVE-2026-84143Critical Vulnerability: CVE-2026-74936 — mozilla — firefox, thunderbird
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
criticalCVE-2026-74936Critical Vulnerability: CVE-2026-74940 — mozilla — firefox, thunderbird
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunder
criticalCVE-2026-74940Critical Vulnerability: CVE-2026-74943 — mozilla — firefox, thunderbird
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thu
criticalCVE-2026-74943Critical Vulnerability: CVE-2026-74944 — mozilla — firefox, thunderbird
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
criticalCVE-2026-74944Critical Vulnerability: CVE-2026-74961 — mozilla — firefox, thunderbird
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
criticalCVE-2026-74961Critical Vulnerability: CVE-2026-74988 — mozilla — firefox, thunderbird
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough
criticalCVE-2026-74988Critical Vulnerability: CVE-2026-74989 — mozilla — firefox, thunderbird
Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could
criticalCVE-2026-74989Critical Vulnerability: CVE-2026-16392 — mozilla — firefox, thunderbird
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
criticalCVE-2026-16392Critical Vulnerability: CVE-2024-9680 — mozilla, debian — firefox, thunderbird
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This
criticalCVE-2024-9680Critical Vulnerability: CVE-2026-16352 — mozilla — firefox, thunderbird
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.
criticalCVE-2026-16352Critical Vulnerability: CVE-2026-16353 — mozilla — firefox, thunderbird
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
criticalCVE-2026-16353Critical Vulnerability: CVE-2026-16361 — mozilla — firefox, thunderbird
Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbi
criticalCVE-2026-16361Critical Vulnerability: CVE-2026-14241 — mozilla — firefox
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary c
criticalCVE-2026-14241Critical Vulnerability: CVE-2026-12293 — mozilla — firefox, thunderbird
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
criticalCVE-2026-12293Critical Vulnerability: CVE-2026-8091 — mozilla — firefox, thunderbird
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2
criticalCVE-2026-8091Critical Vulnerability: CVE-2026-8094 — mozilla — firefox, thunderbird
Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
criticalCVE-2026-8094Critical Vulnerability: CVE-2026-41512 — mozilla — 0din_scanner
ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability via JavaScript injection in `BrowserAutomatio
criticalCVE-2026-41512Critical Vulnerability: CVE-2016-5280 — mozilla — firefox
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remo
criticalCVE-2016-5280Critical Vulnerability: CVE-2016-5281 — mozilla — firefox
Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leverag
criticalCVE-2016-5281Critical Vulnerability: CVE-2016-5257 — mozilla — firefox
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memo
criticalCVE-2016-5257Critical Vulnerability: CVE-2016-5277 — mozilla — firefox
Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary cod
criticalCVE-2016-5277Critical Vulnerability: CVE-2016-5274 — mozilla — firefox
Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute a
criticalCVE-2016-5274Critical Vulnerability: CVE-2016-5256 — mozilla — firefox
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exec
criticalCVE-2016-5256Critical Vulnerability: CVE-2016-5276 — mozilla — firefox
Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote at
criticalCVE-2016-5276Critical Vulnerability: CVE-2016-5270 — mozilla — firefox
Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers t
criticalCVE-2016-5270Critical Vulnerability: CVE-2026-7321 — mozilla — firefox, thunderbird
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.
criticalCVE-2026-7321Critical Vulnerability: CVE-2007-4039 — mozilla — mozilla
Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metach
criticalCVE-2007-4039Critical Vulnerability: CVE-2026-6771 — mozilla — firefox, thunderbird
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
criticalCVE-2026-6771Critical Vulnerability: CVE-2026-6768 — mozilla — firefox, thunderbird
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
criticalCVE-2026-6768Critical Vulnerability: CVE-2026-6760 — mozilla — firefox, thunderbird
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
criticalCVE-2026-6760Critical Vulnerability: CVE-2026-6748 — mozilla — firefox, thunderbird
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
criticalCVE-2026-6748Critical Vulnerability: CVE-2007-5341 — mozilla — firefox
Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
criticalCVE-2007-5341Critical Vulnerability: CVE-2017-5461 — mozilla — network_security_services
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-
criticalCVE-2017-5461
Track mozilla exposure across your environment
Vulnios automatically cross-references your asset inventory against new mozilla CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan