Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mozilla Corporation

First CVE: May 11, 2000Active for: 26 yearsTotal CVEs: 3,671
65.5
VTI Score
TOP TARGET

Mozilla Corporation maintains a modestly scoped but exceptionally prominent product portfolio centered on widely deployed web browsers and email clients, with Firefox and Thunderbird serving as foundational components across consumer and enterprise environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and parsing demands of large, feature-rich native codebases that process untrusted web content and network data at scale. The exposure recurs through weakness classes including buffer-boundary violations, use-after-free conditions, and out-of-bounds writes—hallmark memory-management flaws in C/C++ implementations—and spans both mainline release and extended-support (ESR) product streams that serve different user populations and update cadences. The prominence of Mozilla's products in the vulnerability landscape stems from their reach and the inherent complexity of browser engines rather than from a sprawling product inventory. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
3,671
Total CVEs
More Total CVEs than 100% of tracked vendors
3.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Mozilla Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2000
26 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Self-Reporting Analysis

Of all the CVEs published by Mozilla Corporation as a CNA, 97.7% affect products that Mozilla Corporation develops as a vendor.

97.7%
Self-reported: 2,473 (97.7%)
Third-party: 58 (2.3%)

Of all the CVEs published that affect products developed by Mozilla Corporation, 67.4% are self-published by Mozilla Corporation as a CNA.

67.4%
32.6%
Self-published: 2,473 (67.4%)
Other CNAs: 1,198 (32.6%)

Products(44 total)

Top CVEs

Signals from CVEs in this vendor scope (3671 CVEs).

3,671 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-9079HIGH
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users
Jun 11, 20187.597YESYES
CVE-2010-3765CRITICAL
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled,
Oct 28, 20109.897YESYES
CVE-2023-4863HIGH
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag
Sep 12, 20238.896YESNO
CVE-2015-4495HIGH
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitr
Aug 8, 20158.896YESYES
CVE-2013-1690HIGH
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in c
Jun 26, 20138.896YESYES
CVE-2019-11708CRITICAL
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content cho
Jul 23, 201910.094YESYES
CVE-2019-17026HIGH
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. Thi
Mar 2, 20208.890YESYES
CVE-2019-11707HIGH
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks
Jul 23, 20198.889YESYES
CVE-2023-5217HIGH
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra
Sep 28, 20238.887YESNO
CVE-2014-1510CRITICAL
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit
Mar 19, 20149.887NOYES
View all 3,671 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3,671 CVEs
42%
43%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local97 (2.6%)
Network2,016 (54.9%)
Unknown1,554 (42.3%)
Physical3 (0.1%)
Adjacent Network1 (0.0%)
Attack Complexity
Low1,953 (53.2%)
High164 (4.5%)
Unknown1,554 (42.3%)
User Interaction
None968 (26.4%)
Unknown1,554 (42.3%)
Required1,149 (31.3%)
Privileges Required
Low74 (2.0%)
High2 (0.1%)
None2,041 (55.6%)
Unknown1,554 (42.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (3671 CVEs).

CISA KEV
15 CVEs
0.4% of CVEs· 99th percentile
Metasploit
28 CVEs
0.8% of CVEs· 97th percentile
Nuclei
1 CVE
0.0% of CVEs· 95th percentile
ExploitDB
143 CVEs
3.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mozilla Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mozilla Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mozilla Corporation's Products

View all 17 CNAs →

Top CWEs