Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Mozilla — Vulnerabilities & Security Advisories 2185

Browse all 2185 CVE security advisories affecting Mozilla. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Mozilla operates as a non-profit organization primarily known for developing the Firefox web browser and maintaining the Gecko rendering engine. Its software portfolio serves millions of users globally, focusing on open-source web technologies and privacy-centric browsing solutions. Historically, the codebase has been susceptible to a wide array of vulnerabilities, including remote code execution, cross-site scripting, and memory corruption issues such as buffer overflows. These flaws often stem from complex JavaScript engines and network stack implementations. While Mozilla maintains a robust security response team and regularly issues patches, the sheer volume of recorded Common Vulnerabilities and Exposures highlights the challenges inherent in maintaining large-scale, cross-platform applications. The organization continues to prioritize security audits and community-driven bug bounty programs to mitigate risks associated with its extensive feature set and widespread adoption.

CVE ID Title CVSS Severity Published
CVE-2026-106550 CVE-2026-106550 — Node-convict - - 2026-10-06
CVE-2026-106016 Mitigation bypass in the File Handling component — Firefox - - 2026-10-06
CVE-2026-103500 Heap buffer overflow opening large email — Thunderbird - - 2026-09-30
CVE-2026-100832 Use-after-free in the Graphics: Canvas2D component — Firefox - - 2026-09-29
CVE-2026-100830 Mitigation bypass in the DOM: Navigation component — Firefox - - 2026-09-29
CVE-2026-100831 Use-after-free in the DOM: UI Events & Focus Handling component — Firefox - - 2026-09-29
CVE-2026-100829 Mitigation bypass in the DOM: Security component — Firefox - - 2026-09-29
CVE-2026-100828 Mitigation bypass in the Bookmarks & History component — Firefox - - 2026-09-29
CVE-2026-100826 Denial-of-service in the Storage: StorageManager component — Firefox - - 2026-09-29
CVE-2026-100825 Use-after-free in the JavaScript Engine: JIT component — Firefox - - 2026-09-29
CVE-2026-100824 Privilege escalation in the Places component — Firefox - - 2026-09-29
CVE-2026-100823 Spoofing issue in the Downloads component in Firefox for Android — Firefox - - 2026-09-29
CVE-2026-100822 Spoofing issue in the Networking: HTTP component — Firefox - - 2026-09-29
CVE-2026-100820 Privilege escalation in the Address Bar component — Thunderbird - - 2026-09-29
CVE-2026-100821 Site isolation issue in the Panning and Zooming component — Firefox - - 2026-09-29
CVE-2026-100819 Sandbox escape due to incorrect boundary conditions in the XPCOM component — Firefox - - 2026-09-29
CVE-2026-100818 Sandbox escape due to use-after-free in the Widget: Gtk component — Thunderbird - - 2026-09-29
CVE-2026-100817 Other issue in the JavaScript: WebAssembly component — Thunderbird - - 2026-09-29
CVE-2026-100816 Site isolation issue in the DOM: Networking component — Firefox - - 2026-09-29
CVE-2026-100815 Use-after-free in the CSS Parsing and Computation component — Firefox - - 2026-09-29
CVE-2026-100814 Incorrect boundary conditions in the JavaScript Engine: JIT component — Firefox - - 2026-09-29
CVE-2026-100813 Invalid pointer in the JavaScript Engine: JIT component — Thunderbird - - 2026-09-29
CVE-2026-100812 Denial-of-service in the Graphics component — Firefox - - 2026-09-29
CVE-2026-100811 Sandbox escape due to use-after-free in the DOM: Core & HTML component — Thunderbird - - 2026-09-29
CVE-2026-100810 Other issue in the DevTools component — Thunderbird - - 2026-09-29
CVE-2026-100809 Same-origin policy bypass in the DevTools component — Firefox - - 2026-09-29
CVE-2026-100808 Mitigation bypass in the DOM: Service Workers component — Firefox - - 2026-09-29
CVE-2026-100806 Uninitialized memory in the Graphics: WebGPU component — Firefox - - 2026-09-29
CVE-2026-100807 Privilege escalation in the DOM: Service Workers component — Thunderbird - - 2026-09-29
CVE-2026-100805 Race condition, use-after-free in the Audio/Video component — Thunderbird - - 2026-09-29

This page lists every published CVE security advisory associated with Mozilla. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.