Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2010-3765 | Mozilla | Multiple Products | Mozilla Multiple Products Remote Code Execution Vulnerability Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. | 9.8 CISA | 2025-10-06 | 2025-10-27 | Unknown |
| CVE-2024-9680 | Mozilla | Firefox | Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. | 9.8 CISA | 2024-10-15 | 2024-11-05 | Known |
| CVE-2016-9079 | Mozilla | Firefox, Firefox ESR, and Thunderbird | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. | 7.5 CISA | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2015-4495 | Mozilla | Firefox | Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. | 8.8 CISA | 2022-05-25 | 2022-06-15 | Unknown |
| CVE-2019-11708 | Mozilla | Firefox and Thunderbird | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. | 10.0 CISA | 2022-05-23 | 2022-06-13 | Unknown |
| CVE-2019-11707 | Mozilla | Firefox and Thunderbird | Mozilla Firefox and Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. | 8.8 CISA | 2022-05-23 | 2022-06-13 | Unknown |
| CVE-2013-1690 | Mozilla | Firefox and Thunderbird | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. | 8.8 CISA | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2022-26485 | Mozilla | Firefox | Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. | 8.8 CISA | 2022-03-07 | 2022-03-21 | Unknown |
| CVE-2022-26486 | Mozilla | Firefox | Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. | 9.6 CISA | 2022-03-07 | 2022-03-21 | Unknown |
| CVE-2013-1675 | Mozilla | Firefox | Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. | 6.5 CISA | 2022-03-03 | 2022-03-24 | Unknown |
| CVE-2019-17026 | Mozilla | Firefox and Thunderbird | Mozilla Firefox And Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-6820 | Mozilla | Firefox and Thunderbird | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. | 8.1 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-6819 | Mozilla | Firefox and Thunderbird | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. | 8.1 CISA | 2021-11-03 | 2022-05-03 | Unknown |