Mozilla vendor intelligence
Mozilla Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Mozilla products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 14
- Known exploited vulnerabilities affecting Mozilla products
- In CISA KEV
- 13
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Mozilla KEVs with sensor-observed exploitation activity
The catalog gap matters for Mozilla exposure
One of the fourteen exploited Mozilla CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 7% of this vendor portfolio.
- 93%
- Covered by CISA
- 7%
- Beyond CISA
- 8
- Product families
Attested Mozilla CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before... |
Firefox, Thunderbird, SeaMonkey | Confirmed | In CISA | 27 Oct 2010 |
|
CVE-2009-1308
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary... |
Firefox, Thunderbird, SeaMonkey | High | Beyond CISA | 22 Apr 2009 |
|
CVE-2019-17026
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks... |
Firefox ESR, Thunderbird, Firefox | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-6820
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild... |
Thunderbird, Firefox, Firefox ESR | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-6819
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in... |
Thunderbird, Firefox, Firefox ESR | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2013-1675
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly... |
Firefox, Firefox ESR, Thunderbird, Thunderbird ESR | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-26485
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing... |
Firefox, Firefox ESR, Firefox for Android, Thunderbird, Focus | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2022-26486
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in... |
Firefox, Firefox ESR, Firefox for Android, Thunderbird, Focus | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2013-1690
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly... |
Firefox, Firefox ESR, Thunderbird, Thunderbird ESR | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2019-11708
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed... |
Firefox ESR, Firefox, Thunderbird | Confirmed | In CISA | 23 May 2022 |
|
CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash.... |
Firefox ESR, Firefox, Thunderbird | Confirmed | In CISA | 23 May 2022 |
|
CVE-2015-4495
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the... |
Firefox | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild... |
Firefox, Firefox ESR, Thunderbird | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of... |
Firefox, Firefox ESR, Thunderbird | Confirmed | In CISA | 15 Oct 2024 |
No Mozilla CVEs match this search or filter.
Showing 14 of 14 Mozilla known exploited vulnerabilities.
Recurring weakness patterns
Use after free, access, and restriction account for nine mapped occurrences across this Mozilla KEV portfolio.
CWE-416
Use After Free
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-20
Improper Input Validation
CWE-665
Improper Initialization
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-346
Origin Validation Error
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.