Mozilla Corporation

First CVE: Jan 13, 2013Active for: 14 years
2,531
CVEs Published
More CVEs Published than 95% of tracked CNAs
180.8
Avg CVEs / Year
More Avg CVEs / Year than 93% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 67% of tracked CNAs
0.5%
In CISA KEV
Higher KEV Rate than 85% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Mozilla Corporation as a CNA, 97.7% affect products that Mozilla Corporation develops as a vendor.

97.7%
Self-reported: 2,473Third-party: 58

Of all the CVEs published that affect products developed by Mozilla Corporation, 67.4% are self-published by Mozilla Corporation as a CNA.

67.4%
32.6%
Self-published: 2,473Published by other CNAs: 1,198

Trends Over Time

The number and severity of CVEs published by Mozilla Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2013
13 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by Mozilla Corporation as a CNA, regardless of affected vendor or product.

2,531 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users
Jun 11, 20187.597YESYES
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitr
Aug 8, 20158.896YESYES
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in c
Jun 26, 20138.896YESYES
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content cho
Jul 23, 201910.094YESYES
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. Thi
Mar 2, 20208.890YESYES
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks
Jul 23, 20198.889YESYES
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit
Mar 19, 20149.887NOYES
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vec
Mar 19, 20149.884NOYES
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploit
Oct 9, 20249.882YESNO
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ES
May 14, 20248.880NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA2,531 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local93 (3.7%)
Network2,006 (79.3%)
Unknown428 (16.9%)
Physical3 (0.1%)
Adjacent Network1 (0.0%)
Attack Complexity
Low1,953 (77.2%)
High150 (5.9%)
Unknown428 (16.9%)
User Interaction
None983 (38.8%)
Unknown428 (16.9%)
Required1,120 (44.3%)
Privileges Required
Low68 (2.7%)
High2 (0.1%)
None2,033 (80.3%)
Unknown428 (16.9%)

Exploit Exposure

Signals from CVEs in this cna scope (2531 CVEs).

CISA KEV
12 CVEs
0.5% of CVEs· 85th percentile
Metasploit
13 CVEs
0.5% of CVEs· 82nd percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
42 CVEs
1.7% of CVEs· 86th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Mozilla Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Mozilla Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs