Firefox

Vendor:

First CVE: Dec 31, 2003 · Active for 22 years

3,231
Total CVEs
More Total CVEs than 100% of tracked products
134.6
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Firefox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

CVE Severity & Scoring

Firefox3,231 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local80 (2.5%)
Network1,858 (57.5%)
Unknown1,291 (40.0%)
Physical1 (0.0%)
Adjacent Network1 (0.0%)
Attack Complexity
Low1,798 (55.6%)
High142 (4.4%)
Unknown1,291 (40.0%)
User Interaction
None890 (27.5%)
Unknown1,291 (40.0%)
Required1,050 (32.5%)
Privileges Required
Low61 (1.9%)
High2 (0.1%)
None1,877 (58.1%)
Unknown1,291 (40.0%)

Top CVEs

Signals from CVEs in this product scope (3231 CVEs).

3,231 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users
Jun 11, 20187.597YESYES
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled,
Oct 28, 20109.897YESYES
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag
Sep 12, 20238.896YESNO
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitr
Aug 8, 20158.896YESYES
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in c
Jun 26, 20138.896YESYES
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content cho
Jul 23, 201910.094YESYES
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. Thi
Mar 2, 20208.890YESYES
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks
Jul 23, 20198.889YESYES
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra
Sep 28, 20238.887YESNO
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit
Mar 19, 20149.887NOYES

Exploit Exposure

Signals from CVEs in this product scope (3231 CVEs).

CISA KEV
15 CVEs
0.5% of CVEs· 96th percentile
Metasploit
28 CVEs
0.9% of CVEs· 96th percentile
Nuclei
1 CVE
0.0% of CVEs· 96th percentile
ExploitDB
120 CVEs
3.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (3231 CVEs).

Media Mentions

Signals from CVEs in this product scope (3231 CVEs).

Top CNAs Publishing CVEs For Firefox

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
preview_release157.44.8%02
9.0.1957.03.6%01
9.01006.93.5%01
8.0.11006.93.5%01
8.01066.94.1%02
7.0.11017.03.5%01
7.01146.93.4%01
69.016.10.8%00
65.014.31.6%00
62.015.31.7%00
6.0.21127.03.4%01
6.0.11127.03.4%01
6.01206.93.4%01
56.017.53.1%00
52.4.017.53.1%00
52.0229.24.9%02
5.0.11126.93.4%01
50.018.81.9%00
5.01317.03.4%01
49.018.81.9%00