Mozilla Corporation maintains a modestly scoped but exceptionally prominent product portfolio centered on widely deployed web browsers and email clients, with Firefox and Thunderbird serving as foundational components across consumer and enterprise environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and parsing demands of large, feature-rich native codebases that process untrusted web content and network data at scale. The exposure recurs through weakness classes including buffer-boundary violations, use-after-free conditions, and out-of-bounds writes—hallmark memory-management flaws in C/C++ implementations—and spans both mainline release and extended-support (ESR) product streams that serve different user populations and update cadences. The prominence of Mozilla's products in the vulnerability landscape stems from their reach and the inherent complexity of browser engines rather than from a sprawling product inventory. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mozilla Corporation over time
Of all the CVEs published by Mozilla Corporation as a CNA, 97.7% affect products that Mozilla Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Mozilla Corporation, 67.4% are self-published by Mozilla Corporation as a CNA.
Signals from CVEs in this vendor scope (3671 CVEs).
3,671 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9079HIGH A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users | Jun 11, 2018 | 7.5 | 97 | YES | YES |
CVE-2010-3765CRITICAL Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, | Oct 28, 2010 | 9.8 | 97 | YES | YES |
CVE-2023-4863HIGH Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag | Sep 12, 2023 | 8.8 | 96 | YES | NO |
CVE-2015-4495HIGH The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitr | Aug 8, 2015 | 8.8 | 96 | YES | YES |
CVE-2013-1690HIGH Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in c | Jun 26, 2013 | 8.8 | 96 | YES | YES |
CVE-2019-11708CRITICAL Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content cho | Jul 23, 2019 | 10.0 | 94 | YES | YES |
CVE-2019-17026HIGH Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. Thi | Mar 2, 2020 | 8.8 | 90 | YES | YES |
CVE-2019-11707HIGH A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks | Jul 23, 2019 | 8.8 | 89 | YES | YES |
CVE-2023-5217HIGH Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra | Sep 28, 2023 | 8.8 | 87 | YES | NO |
CVE-2014-1510CRITICAL The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit | Mar 19, 2014 | 9.8 | 87 | NO | YES |
Signals from CVEs in this vendor scope (3671 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mozilla Corporation.
Media articles that mention a CVE ID that affects a product developed by Mozilla Corporation — matched by CVE ID, not by vendor name.