Mozilla Vulnerabilities
Mozilla develops the Firefox web browser and is the advisory source for the Thunderbird email client. The database tracks 13 Mozilla CVE records. CISA lists 13 of them as exploited in the wild, most recently on 2025-10-06. The most affected products are Firefox and Thunderbird, Firefox, Firefox, Firefox ESR, and Thunderbird.
Recently Exploited Mozilla CVEs
Mozilla Multiple Products Remote Code Execution Vulnerability
Mozilla Firefox Use-After-Free Vulnerability
Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
Mozilla Firefox Security Feature Bypass Vulnerability
Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
Mozilla Firefox and Thunderbird Type Confusion Vulnerability
Affected Products
4 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Firefox and Thunderbird | 6 | 6 | 2022-05-23 |
| Firefox | 5 | 5 | 2024-10-15 |
| Firefox, Firefox ESR, and Thunderbird | 1 | 1 | 2023-06-22 |
| Multiple Products | 1 | 1 | 2025-10-06 |
All Mozilla CVEs
13 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2010-3765 | Mozilla Multiple Products Remote Code Execution Vulnerability | - | 9.8 | 83.2% | KEV | 2010-10-27 |
| CVE-2024-9680 | Mozilla Firefox Use-After-Free Vulnerability | Mozilla | 9.8 | 23.2% | KEV | 2024-10-09 |
| CVE-2016-9079 | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability | Mozilla | 7.5 | 87.5% | KEV | 2018-06-11 |
| CVE-2015-4495 | Mozilla Firefox Security Feature Bypass Vulnerability | - | 8.8 | 68.6% | KEV | 2015-08-08 |
| CVE-2019-11708 | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability | Mozilla | 10.0 | 55.9% | KEV | 2019-07-23 |
| CVE-2019-11707 | Mozilla Firefox and Thunderbird Type Confusion Vulnerability | Mozilla | 8.8 | 37.7% | KEV | 2019-07-23 |
| CVE-2013-1690 | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability | - | 8.8 | 69.0% | KEV | 2013-06-26 |
| CVE-2022-26485 | Mozilla Firefox Use-After-Free Vulnerability | Mozilla | 8.8 | 14.3% | KEV | 2022-12-22 |
| CVE-2022-26486 | Mozilla Firefox Use-After-Free Vulnerability | Mozilla | 9.6 | 2.4% | KEV | 2022-12-22 |
| CVE-2013-1675 | Mozilla Firefox Information Disclosure Vulnerability | - | 6.5 | 6.7% | KEV | 2013-05-16 |
| CVE-2019-17026 | Mozilla Firefox And Thunderbird Type Confusion Vulnerability | Mozilla | 8.8 | 46.3% | KEV | 2020-03-02 |
| CVE-2020-6820 | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability | Mozilla | 8.1 | 7.1% | KEV | 2020-04-24 |
| CVE-2020-6819 | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability | Mozilla | 8.1 | 3.0% | KEV | 2020-04-24 |
Frequently Asked Questions
How many Mozilla vulnerabilities are actively exploited?→
13 Mozilla CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2025-10-06.
Which Mozilla vulnerabilities are used in ransomware attacks?→
CISA marks 1 Mozilla KEV entries as known to be used in ransomware campaigns, including CVE-2024-9680.
Which Mozilla products have the most exploited vulnerabilities?→
- +Firefox and Thunderbird: 6 CVEs (6 in KEV)
- +Firefox: 5 CVEs (5 in KEV)
- +Firefox, Firefox ESR, and Thunderbird: 1 CVE (1 in KEV)
- +Multiple Products: 1 CVE (1 in KEV)
Where does Mozilla publish security advisories?→
Mozilla publishes security advisories at https://www.mozilla.org/en-US/security/advisories/. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Mozilla, MITRE, CISA, or FIRST.