Mozilla
95 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-84117
HIGH 8.8
Firefox — Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
2026-09-01
CVE-2026-84118
MEDIUM 5.4
Firefox — Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2…
2026-09-01
CVE-2026-84119
CRITICAL 9.6
Firefox — Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox…
2026-09-01
CVE-2026-84120
MEDIUM 5.4
Firefox — Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, …
2026-09-01
CVE-2026-84121
CRITICAL 9.6
Firefox — Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 1…
2026-09-01
CVE-2026-84122
MEDIUM 5.4
Firefox — Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, …
2026-09-01
CVE-2026-84123
HIGH 8.8
Firefox — Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in …
2026-09-01
CVE-2026-84124
MEDIUM 5.4
Firefox — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140…
2026-09-01
CVE-2026-84125
MEDIUM 5.4
Firefox — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153…
2026-09-01
CVE-2026-84126
MEDIUM 4.3
Firefox — Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and T…
2026-09-01
CVE-2026-84127
MEDIUM 4.3
Firefox — Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in …
2026-09-01
CVE-2026-84128
HIGH 8.8
Firefox — Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderb…
2026-09-01
CVE-2026-84129
CRITICAL 9.8
Firefox — Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ES…
2026-09-01
CVE-2026-84130
HIGH 7.5
Firefox — Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox…
2026-09-01
CVE-2026-84131
HIGH 8.8
Firefox — Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox…
2026-09-01
CVE-2026-84132
HIGH 7.5
Firefox — Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox…
2026-09-01
CVE-2026-84133
CRITICAL 9.8
Firefox — Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Fi…
2026-09-01
CVE-2026-84134
CRITICAL 9.8
Firefox — Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, T…
2026-09-01
CVE-2026-84135
CRITICAL 9.8
Firefox — Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
2026-09-01
CVE-2026-84136
CRITICAL 9.8
Firefox — Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, …
2026-09-01
CVE-2026-84137
CRITICAL 9.8
Firefox — Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153…
2026-09-01
CVE-2026-84138
HIGH 7.5
Firefox — Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155…
2026-09-01
CVE-2026-84139
CRITICAL 9.8
Firefox — Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.…
2026-09-01
CVE-2026-84140
CRITICAL 9.8
Firefox — Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ES…
2026-09-01
CVE-2026-84141
CRITICAL 9.8
Firefox — Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR…
2026-09-01
CVE-2026-84142
CRITICAL 9.8
Firefox — Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or a…
2026-09-01
CVE-2026-84143
CRITICAL 9.8
Firefox — Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of th…
2026-09-01
CVE-2026-84144
HIGH 7.5
Firefox — Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence…
2026-09-01
CVE-2026-84145
HIGH 7.5
Firefox — Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of th…
2026-09-01
CVE-2026-84637
CRITICAL 9.8
Thunderbird — Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on…
2026-09-01
CVE-2026-84639
CRITICAL 9.1
Thunderbird — Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnera…
2026-09-01
CVE-2026-84640
HIGH 7.5
Thunderbird — A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerabili…
2026-09-01
CVE-2026-84641
HIGH 7.5
Thunderbird — A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response…
2026-09-01
CVE-2026-84642
HIGH 7.5
Thunderbird — The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression …
2026-09-01
CVE-2026-81267
MEDIUM 5.4
Firefox For Ios — A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to dis…
2026-08-31
CVE-2026-74934
HIGH 7.5
Firefox — Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Fire…
2026-08-18
CVE-2026-74935
HIGH 8.8
Firefox — Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ES…
2026-08-18
CVE-2026-74936
CRITICAL 9.8
Firefox — Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox …
2026-08-18
CVE-2026-74937
HIGH 8.8
Firefox — Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1…
2026-08-18
CVE-2026-74938
CRITICAL 9.1
Firefox — Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 15…
2026-08-18
CVE-2026-74939
HIGH 8.8
Firefox — Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ES…
2026-08-18
CVE-2026-74940
CRITICAL 9.8
Firefox — Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.3…
2026-08-18
CVE-2026-74941
HIGH 8.8
Firefox — Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Fire…
2026-08-18
CVE-2026-74942
HIGH 8.8
Firefox — Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Fir…
2026-08-18
CVE-2026-74943
CRITICAL 9.8
Firefox — Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 1…
2026-08-18
CVE-2026-74944
CRITICAL 9.8
Firefox — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140…
2026-08-18
CVE-2026-74945
MEDIUM 6.5
Firefox — Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox E…
2026-08-18
CVE-2026-74946
HIGH 8.8
Firefox — Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnera…
2026-08-18
CVE-2026-74947
HIGH 8.8
Firefox — Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox…
2026-08-18
CVE-2026-74948
MEDIUM 6.5
Firefox — Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115…
2026-08-18
CVE-2026-74949
HIGH 8.8
Firefox — Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed i…
2026-08-18
CVE-2026-74950
HIGH 8.8
Firefox — Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR …
2026-08-18
CVE-2026-74951
MEDIUM 6.5
Firefox — Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
2026-08-18
CVE-2026-74952
HIGH 8.8
Firefox — Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunder…
2026-08-18
CVE-2026-74953
HIGH 8.8
Firefox — Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefo…
2026-08-18
CVE-2026-74954
HIGH 7.5
Firefox — Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed i…
2026-08-18
CVE-2026-74955
HIGH 8.8
Firefox — Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox E…
2026-08-18
CVE-2026-74956
CRITICAL 9.1
Firefox — Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, …
2026-08-18
CVE-2026-74957
HIGH 8.1
Firefox — Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140…
2026-08-18
CVE-2026-74958
HIGH 7.5
Firefox — Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1…
2026-08-18
CVE-2026-74959
CRITICAL 9.1
Firefox — Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ES…
2026-08-18
CVE-2026-74960
HIGH 8.1
Firefox — Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR …
2026-08-18
CVE-2026-74961
CRITICAL 9.1
Firefox — Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thund…
2026-08-18
CVE-2026-74962
HIGH 8.1
Firefox — Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefo…
2026-08-18
CVE-2026-74963
MEDIUM 5.4
Firefox — Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, F…
2026-08-18
CVE-2026-74964
CRITICAL 9.8
Firefox — Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, F…
2026-08-18
CVE-2026-74965
HIGH 8.8
Firefox — Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox …
2026-08-18
CVE-2026-74966
HIGH 7.5
Firefox — Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ES…
2026-08-18
CVE-2026-74967
MEDIUM 5.4
Firefox — Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154,…
2026-08-18
CVE-2026-74968
MEDIUM 5.4
Firefox — Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefo…
2026-08-18
CVE-2026-74969
HIGH 8.8
Firefox — Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox E…
2026-08-18
CVE-2026-74970
MEDIUM 5.4
Firefox — Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1…
2026-08-18
CVE-2026-74971
MEDIUM 4.3
Firefox — Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firef…
2026-08-18
CVE-2026-74972
MEDIUM 4.3
Firefox — Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, …
2026-08-18
CVE-2026-74973
MEDIUM 4.2
Firefox — Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox…
2026-08-18
CVE-2026-74974
MEDIUM 5.4
Firefox — Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Fi…
2026-08-18
CVE-2026-74975
MEDIUM 5.4
Firefox — Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
2026-08-18
CVE-2026-74976
MEDIUM 6.5
Firefox — JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firef…
2026-08-18
CVE-2026-74977
HIGH 7.5
Firefox — Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Th…
2026-08-18
CVE-2026-74978
HIGH 8.1
Firefox — Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Th…
2026-08-18
CVE-2026-74979
CRITICAL 9.8
Firefox — Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 1…
2026-08-18
CVE-2026-74980
MEDIUM 6.5
Firefox — Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox …
2026-08-18
CVE-2026-74981
HIGH 8.1
Firefox — Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Fi…
2026-08-18
CVE-2026-74982
HIGH 7.5
Firefox — Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thu…
2026-08-18
CVE-2026-74983
HIGH 8.1
Firefox — Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox …
2026-08-18
CVE-2026-74984
MEDIUM 6.8
Firefox — Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 15…
2026-08-18
CVE-2026-74985
CRITICAL 9.8
Firefox — Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefo…
2026-08-18
CVE-2026-74986
CRITICAL 9.1
Firefox — Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154…
2026-08-18
CVE-2026-74987
CRITICAL 9.8
Firefox — Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of th…
2026-08-18
CVE-2026-74988
CRITICAL 9.8
Firefox — Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence…
2026-08-18
CVE-2026-74989
CRITICAL 9.8
Firefox — Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or a…
2026-08-18
CVE-2026-74990
CRITICAL 9.8
Firefox — Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of th…
2026-08-18
CVE-2026-75874
CRITICAL 10
Firefox — Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbi…
2026-08-18
CVE-2026-18809
MEDIUM 6.5
Firefox — Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in F…
2026-08-04
CVE-2026-14899
HIGH 7.5
Thunderbird — The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was e…
2026-07-22