Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mozilla — Vulnerabilities & Security Advisories 1991

Browse all 1991 CVE security advisories affecting Mozilla. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Mozilla operates as a non-profit organization primarily known for developing the Firefox web browser and maintaining the Gecko rendering engine. Its software portfolio serves millions of users globally, focusing on open-source web technologies and privacy-centric browsing solutions. Historically, the codebase has been susceptible to a wide array of vulnerabilities, including remote code execution, cross-site scripting, and memory corruption issues such as buffer overflows. These flaws often stem from complex JavaScript engines and network stack implementations. While Mozilla maintains a robust security response team and regularly issues patches, the sheer volume of recorded Common Vulnerabilities and Exposures highlights the challenges inherent in maintaining large-scale, cross-platform applications. The organization continues to prioritize security audits and community-driven bug bounty programs to mitigate risks associated with its extensive feature set and widespread adoption.

Found 1447 results / 1991Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-74988 Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 — Firefox--2026-08-18
CVE-2026-74989 Internally found bugs fixed in Thunderbird 154 — Firefox--2026-08-18
CVE-2026-74984 Race condition in the JavaScript Engine component — Firefox--2026-08-18
CVE-2026-74985 Privilege escalation in the Enterprise Policies component — Firefox--2026-08-18
CVE-2026-74982 Denial-of-service in the Widget component — Firefox--2026-08-18
CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component — Firefox--2026-08-18
CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component — Firefox--2026-08-18
CVE-2026-74980 Clickjacking issue in the Downloads component in Firefox for Android — Firefox--2026-08-18
CVE-2026-74978 Clickjacking issue in the Widget component — Firefox--2026-08-18
CVE-2026-74979 Mitigation bypass in the Add-ons Manager component — Firefox--2026-08-18
CVE-2026-74977 Integer overflow in the Graphics component — Firefox--2026-08-18
CVE-2026-74975 Spoofing issue in the Downloads component in Firefox for Android — Firefox--2026-08-18
CVE-2026-74970 Site isolation issue in the Graphics component — Firefox--2026-08-18
CVE-2026-74968 Site isolation issue in the Graphics: WebRender component — Firefox--2026-08-18
CVE-2026-74958 Information disclosure in the WebRTC component — Firefox--2026-08-18
CVE-2026-74961 Side-channel in the Web Audio component — Firefox--2026-08-18
CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component — Firefox--2026-08-18
CVE-2026-74966 Information disclosure in the Form Autofill component — Firefox--2026-08-18
CVE-2026-74951 Clickjacking issue in Firefox for Android — Firefox--2026-08-18
CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component — Firefox--2026-08-18
CVE-2026-74952 Privilege escalation in the Application Update component — Firefox--2026-08-18
CVE-2026-74955 Privilege escalation in the Request Handling component — Firefox--2026-08-18
CVE-2026-74937 Use-after-free in the JavaScript: GC component — Firefox--2026-08-18
CVE-2026-74938 Mitigation bypass in the JavaScript: GC component — Firefox--2026-08-18
CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component — Firefox--2026-08-18
CVE-2026-74950 Privilege escalation in the Downloads API component — Firefox--2026-08-18
CVE-2026-74990 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 — Firefox--2026-08-18
CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component — Firefox--2026-08-18
CVE-2026-75874 Sandbox escape in the Remote Settings Client component — Firefox--2026-08-18
CVE-2026-74987 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 — Firefox--2026-08-18

This page lists every published CVE security advisory associated with Mozilla. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.