Mozilla Firefox Mobile — known CVE vulnerabilities
Every CVE whose affected-product data names Mozilla Firefox Mobile, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (78)
CVE-2012-1126 — CVSS 10.0 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2023-49060 — CVSS 9.8 (critical): An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute…
CVE-2012-1129 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1130 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1131 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to…
CVE-2012-1132 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1133 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1134 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1135 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1136 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1137 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1138 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1139 — CVSS 9.3 (critical): Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to…
CVE-2012-1140 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1142 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1144 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1141 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1127 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2012-1128 — CVSS 9.3 (critical): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2023-29534 — CVSS 9.1 (critical): Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential…
CVE-2023-29550 — CVSS 8.8 (high): Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume…
CVE-2023-29543 — CVSS 8.8 (high): An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger…
CVE-2023-29541 — CVSS 8.8 (high): Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled…
CVE-2023-29539 — CVSS 8.8 (high): When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL…
CVE-2023-29536 — CVSS 8.8 (high): An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an…
CVE-2020-15670 — CVSS 8.8 (high): Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption…
CVE-2023-29551 — CVSS 8.8 (high): Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2024-7523 — CVSS 8.1 (high): A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions…
CVE-2021-29993 — CVSS 8.1 (high): Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug…
CVE-2020-6830 — CVSS 7.5 (high): For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That…
CVE-2023-25747 — CVSS 7.5 (high): A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug…
CVE-2023-29537 — CVSS 7.5 (high): Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This…
CVE-2026-16373 — CVSS 7.5 (high): Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2012-3979 — CVSS 6.8 (medium): Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows…
CVE-2020-26964 — CVSS 6.8 (medium): If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could…
CVE-2020-26957 — CVSS 6.5 (medium): OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce…
CVE-2020-26955 — CVSS 6.5 (medium): When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download…
CVE-2020-15666 — CVSS 6.5 (medium): When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the…
CVE-2020-15664 — CVSS 6.5 (medium): By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the…
CVE-2022-31746 — CVSS 6.5 (medium): Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability…
CVE-2026-53899 — CVSS 6.5 (medium): Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to…
CVE-2024-38312 — CVSS 6.5 (medium): When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed…
CVE-2020-15662 — CVSS 6.5 (medium): A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an…
CVE-2023-29535 — CVSS 6.5 (medium): Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory…
CVE-2020-15661 — CVSS 6.5 (medium): A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for…
CVE-2020-12414 — CVSS 6.5 (medium): IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly…
CVE-2020-26975 — CVSS 6.5 (medium): When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been…
CVE-2023-29549 — CVSS 6.5 (medium): Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a…
CVE-2023-29544 — CVSS 6.5 (medium): If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and…
CVE-2023-29548 — CVSS 6.5 (medium): A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112…
CVE-2023-29546 — CVSS 6.5 (medium): When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially…
CVE-2020-26977 — CVSS 6.5 (medium): By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar…
CVE-2019-17003 — CVSS 6.1 (medium): Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
CVE-2023-29540 — CVSS 6.1 (medium): Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes…
CVE-2023-49061 — CVSS 6.1 (medium): An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects…
CVE-2023-5758 — CVSS 6.1 (medium): When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site…
CVE-2024-0953 — CVSS 6.1 (medium): When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the…
CVE-2024-43111 — CVSS 6.1 (medium): Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects…
CVE-2024-43112 — CVSS 6.1 (medium): Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS <…
CVE-2024-43113 — CVSS 6.1 (medium): The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS <…
CVE-2020-6829 — CVSS 5.3 (medium): When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about…
CVE-2026-14906 — CVSS 5.3 (medium): Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS…
CVE-2020-12400 — CVSS 4.7 (medium): When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible…
CVE-2020-12401 — CVSS 4.7 (medium): During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed…
CVE-2020-26954 — CVSS 4.3 (medium): When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed…
CVE-2022-38474 — CVSS 4.3 (medium): A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not…
CVE-2020-12404 — CVSS 4.3 (medium): For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That…
CVE-2023-29538 — CVSS 4.3 (medium): Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code>…
CVE-2026-53900 — CVSS 4.3 (medium): Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a…
CVE-2012-1143 — CVSS 4.3 (medium): FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of…
CVE-2020-15668 — CVSS 4.3 (medium): A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability…
CVE-2023-29533 — CVSS 4.3 (medium): A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests…
CVE-2024-38313 — CVSS 4.3 (medium): In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual…
CVE-2020-15671 — CVSS 3.1 (low): When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the…