Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

Firefox — Vulnerabilities & Security Advisories 1279

All 1279 CVE vulnerabilities found in Firefox, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for Mozilla Firefox categorized under general software weakness types. It serves as a centralized resource for tracking security issues specifically affecting the Firefox web browser developed by Mozilla. The content collected includes a comprehensive list of vulnerabilities reported for Firefox, spanning from the early days of the product’s public releases up to the most recent updates. This collection encompasses various severity levels, including critical, high, medium, and low risk findings. The time range covered ensures that historical context is available for older issues while maintaining up-to-date information on newly discovered flaws. This allows users to see the full lifecycle of security problems as they were identified and patched over time. Visitors to this page can track vendor advisories issued by Mozilla to understand how they respond to different types of security threats. You can also explore the broader context of specific weakness classes to see how frequently they appear in Firefox codebases. Additionally, the page enables you to look up a product’s vulnerability history to analyze trends in security stability and development practices. This data helps security researchers, developers, and users understand the effectiveness of current mitigation strategies and identify potential areas for improvement in future releases.

Vendor: Mozilla

CVE IDTitleCVSSSeverityPublished
CVE-2025-8364 Address bar spoofing using an blob URI on Firefox for Android 4.3 -2025-08-19
CVE-2025-8041 Incorrect URL truncation in Firefox for Android 4.3 -2025-08-19
CVE-2025-9184 Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 9.8 -2025-08-19
CVE-2025-9187 Memory safety bugs fixed in Firefox 142 and Thunderbird 142 9.8 -2025-08-19
CVE-2025-9182 Denial-of-service due to out-of-memory in the Graphics: WebRender component 6.5 -2025-08-19
CVE-2025-9183 Spoofing issue in the Address Bar component 4.3 -2025-08-19
CVE-2025-9185 Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 9.8 -2025-08-19
CVE-2025-9186 Spoofing issue in the Address Bar component of Firefox Focus for Android 4.3 -2025-08-19
CVE-2025-9180 Same-origin policy bypass in the Graphics: Canvas2D component 9.1 -2025-08-19
CVE-2025-9181 Uninitialized memory in the JavaScript Engine component 8.8 -2025-08-19
CVE-2025-9179 Sandbox escape due to invalid pointer in the Audio/Video: GMP component 9.8 -2025-08-19
CVE-2025-8043 Incorrect URL truncation 7.1 -2025-07-22
CVE-2025-8035 Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141 9.8 -2025-07-22
CVE-2025-8044 Memory safety bugs fixed in Firefox 141 and Thunderbird 141 9.8 -2025-07-22
CVE-2025-8040 Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141 8.8 -2025-07-22
CVE-2025-8034 Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141 9.8 -2025-07-22
CVE-2025-8032 XSLT documents could bypass CSP 7.1 -2025-07-22
CVE-2025-8039 Search terms persisted in URL bar 4.3 -2025-07-22
CVE-2025-8038 CSP frame-src was not correctly enforced for paths 9.1 -2025-07-22
CVE-2025-8033 Incorrect JavaScript state machine for generators 8.8 -2025-07-22
CVE-2025-8037 Nameless cookies shadow secure cookies 9.1 -2025-07-22
CVE-2025-8030 Potential user-assisted code execution in “Copy as cURL” command 8.8 -2025-07-22
CVE-2025-8031 Incorrect URL stripping in CSP reports 7.5 -2025-07-22
CVE-2025-8029 javascript: URLs executed on object and embed tags 6.1 -2025-07-22
CVE-2025-8036 DNS rebinding circumvents CORS 8.1 -2025-07-22
CVE-2025-8028 Large branch table could lead to truncated instruction 7.1 -2025-07-22
CVE-2025-8027 JavaScript engine only wrote partial return value to stack 9.1 -2025-07-22
CVE-2025-6435 Save as in Devtools could download files without sanitizing the extension 8.8AIHighAI2025-06-24
CVE-2025-6436 Memory safety bugs fixed in Firefox 140 and Thunderbird 140 9.8AICriticalAI2025-06-24
CVE-2025-6434 HTTPS-Only exception screen lacked anti-clickjacking delay 4.3AIMediumAI2025-06-24

All 1279 known CVE vulnerabilities affecting Firefox with full Chinese analysis, references, and POCs where available.