Firefox
Vendor:
First CVE: Dec 31, 2003 · Active for 22 years
3,231
Total CVEs
More Total CVEs than 100% of tracked products
134.6
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Firefox over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
CVE Severity & Scoring
Firefox3,231 CVEs
40%
44%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local80 (2.5%)
Network1,858 (57.5%)
Unknown1,291 (40.0%)
Physical1 (0.0%)
Adjacent Network1 (0.0%)
Attack Complexity
Low1,798 (55.6%)
High142 (4.4%)
Unknown1,291 (40.0%)
User Interaction
None890 (27.5%)
Unknown1,291 (40.0%)
Required1,050 (32.5%)
Privileges Required
Low61 (1.9%)
High2 (0.1%)
None1,877 (58.1%)
Unknown1,291 (40.0%)
Top CVEs
Signals from CVEs in this product scope (3231 CVEs).
3,231 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9079HIGH A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users | Jun 11, 2018 | 7.5 | 97 | YES | YES |
CVE-2010-3765CRITICAL Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, | Oct 28, 2010 | 9.8 | 97 | YES | YES |
CVE-2023-4863HIGH Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag | Sep 12, 2023 | 8.8 | 96 | YES | NO |
CVE-2015-4495HIGH The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitr | Aug 8, 2015 | 8.8 | 96 | YES | YES |
CVE-2013-1690HIGH Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in c | Jun 26, 2013 | 8.8 | 96 | YES | YES |
CVE-2019-11708CRITICAL Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content cho | Jul 23, 2019 | 10.0 | 94 | YES | YES |
CVE-2019-17026HIGH Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. Thi | Mar 2, 2020 | 8.8 | 90 | YES | YES |
CVE-2019-11707HIGH A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks | Jul 23, 2019 | 8.8 | 89 | YES | YES |
CVE-2023-5217HIGH Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra | Sep 28, 2023 | 8.8 | 87 | YES | NO |
CVE-2014-1510CRITICAL The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit | Mar 19, 2014 | 9.8 | 87 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (3231 CVEs).
CISA KEV
15 CVEs
0.5% of CVEs· 96th percentile
Metasploit
28 CVEs
0.9% of CVEs· 96th percentile
Nuclei
1 CVE
0.0% of CVEs· 96th percentile
ExploitDB
120 CVEs
3.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (3231 CVEs).
Media Mentions
Signals from CVEs in this product scope (3231 CVEs).
Top CNAs Publishing CVEs For Firefox
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| preview_release | 15 | 7.4 | 4.8% | 0 | 2 |
| 9.0.1 | 95 | 7.0 | 3.6% | 0 | 1 |
| 9.0 | 100 | 6.9 | 3.5% | 0 | 1 |
| 8.0.1 | 100 | 6.9 | 3.5% | 0 | 1 |
| 8.0 | 106 | 6.9 | 4.1% | 0 | 2 |
| 7.0.1 | 101 | 7.0 | 3.5% | 0 | 1 |
| 7.0 | 114 | 6.9 | 3.4% | 0 | 1 |
| 69.0 | 1 | 6.1 | 0.8% | 0 | 0 |
| 65.0 | 1 | 4.3 | 1.6% | 0 | 0 |
| 62.0 | 1 | 5.3 | 1.7% | 0 | 0 |
| 6.0.2 | 112 | 7.0 | 3.4% | 0 | 1 |
| 6.0.1 | 112 | 7.0 | 3.4% | 0 | 1 |
| 6.0 | 120 | 6.9 | 3.4% | 0 | 1 |
| 56.0 | 1 | 7.5 | 3.1% | 0 | 0 |
| 52.4.0 | 1 | 7.5 | 3.1% | 0 | 0 |
| 52.0 | 22 | 9.2 | 4.9% | 0 | 2 |
| 5.0.1 | 112 | 6.9 | 3.4% | 0 | 1 |
| 50.0 | 1 | 8.8 | 1.9% | 0 | 0 |
| 5.0 | 131 | 7.0 | 3.4% | 0 | 1 |
| 49.0 | 1 | 8.8 | 1.9% | 0 | 0 |