Palemoon is an independent, open-source web browser maintained as a fork of Firefox, with its vulnerability profile centered on the core browser product and reflecting memory-safety and state-management challenges inherent to browser engines. The observed weakness classes—integer overflow, NULL-pointer dereference, and use-after-free conditions—are consistent with the parsing and rendering demands of a native codebase handling untrusted web content; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Palemoon over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12292CRITICAL A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3. | Jun 13, 2018 | 9.8 | 43 | NO | YES |
CVE-2013-1591CRITICAL Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this iss | Jan 31, 2013 | 9.8 | 25 | NO | NO |
CVE-2020-9545HIGH Pale Moon 28.x before 28.8.4 has a segmentation fault related to module scripting, as demonstrated by a Lacoste web site. | Mar 2, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Palemoon.
Media articles that mention a CVE ID that affects a product developed by Palemoon — matched by CVE ID, not by vendor name.