← Browse

Mozilla

95 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-84117 HIGH 8.8 Firefox — Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. 2026-09-01 CVE-2026-84118 MEDIUM 5.4 Firefox — Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2… 2026-09-01 CVE-2026-84119 CRITICAL 9.6 Firefox — Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox… 2026-09-01 CVE-2026-84120 MEDIUM 5.4 Firefox — Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, … 2026-09-01 CVE-2026-84121 CRITICAL 9.6 Firefox — Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 1… 2026-09-01 CVE-2026-84122 MEDIUM 5.4 Firefox — Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, … 2026-09-01 CVE-2026-84123 HIGH 8.8 Firefox — Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in … 2026-09-01 CVE-2026-84124 MEDIUM 5.4 Firefox — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140… 2026-09-01 CVE-2026-84125 MEDIUM 5.4 Firefox — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153… 2026-09-01 CVE-2026-84126 MEDIUM 4.3 Firefox — Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and T… 2026-09-01 CVE-2026-84127 MEDIUM 4.3 Firefox — Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in … 2026-09-01 CVE-2026-84128 HIGH 8.8 Firefox — Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderb… 2026-09-01 CVE-2026-84129 CRITICAL 9.8 Firefox — Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ES… 2026-09-01 CVE-2026-84130 HIGH 7.5 Firefox — Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox… 2026-09-01 CVE-2026-84131 HIGH 8.8 Firefox — Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox… 2026-09-01 CVE-2026-84132 HIGH 7.5 Firefox — Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox… 2026-09-01 CVE-2026-84133 CRITICAL 9.8 Firefox — Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Fi… 2026-09-01 CVE-2026-84134 CRITICAL 9.8 Firefox — Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, T… 2026-09-01 CVE-2026-84135 CRITICAL 9.8 Firefox — Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. 2026-09-01 CVE-2026-84136 CRITICAL 9.8 Firefox — Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, … 2026-09-01 CVE-2026-84137 CRITICAL 9.8 Firefox — Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153… 2026-09-01 CVE-2026-84138 HIGH 7.5 Firefox — Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155… 2026-09-01 CVE-2026-84139 CRITICAL 9.8 Firefox — Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.… 2026-09-01 CVE-2026-84140 CRITICAL 9.8 Firefox — Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ES… 2026-09-01 CVE-2026-84141 CRITICAL 9.8 Firefox — Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR… 2026-09-01 CVE-2026-84142 CRITICAL 9.8 Firefox — Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or a… 2026-09-01 CVE-2026-84143 CRITICAL 9.8 Firefox — Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of th… 2026-09-01 CVE-2026-84144 HIGH 7.5 Firefox — Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence… 2026-09-01 CVE-2026-84145 HIGH 7.5 Firefox — Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of th… 2026-09-01 CVE-2026-84637 CRITICAL 9.8 Thunderbird — Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on… 2026-09-01 CVE-2026-84639 CRITICAL 9.1 Thunderbird — Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnera… 2026-09-01 CVE-2026-84640 HIGH 7.5 Thunderbird — A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerabili… 2026-09-01 CVE-2026-84641 HIGH 7.5 Thunderbird — A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response… 2026-09-01 CVE-2026-84642 HIGH 7.5 Thunderbird — The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression … 2026-09-01 CVE-2026-81267 MEDIUM 5.4 Firefox For Ios — A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to dis… 2026-08-31 CVE-2026-74934 HIGH 7.5 Firefox — Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Fire… 2026-08-18 CVE-2026-74935 HIGH 8.8 Firefox — Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ES… 2026-08-18 CVE-2026-74936 CRITICAL 9.8 Firefox — Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox … 2026-08-18 CVE-2026-74937 HIGH 8.8 Firefox — Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1… 2026-08-18 CVE-2026-74938 CRITICAL 9.1 Firefox — Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 15… 2026-08-18 CVE-2026-74939 HIGH 8.8 Firefox — Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ES… 2026-08-18 CVE-2026-74940 CRITICAL 9.8 Firefox — Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.3… 2026-08-18 CVE-2026-74941 HIGH 8.8 Firefox — Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Fire… 2026-08-18 CVE-2026-74942 HIGH 8.8 Firefox — Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Fir… 2026-08-18 CVE-2026-74943 CRITICAL 9.8 Firefox — Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 1… 2026-08-18 CVE-2026-74944 CRITICAL 9.8 Firefox — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140… 2026-08-18 CVE-2026-74945 MEDIUM 6.5 Firefox — Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox E… 2026-08-18 CVE-2026-74946 HIGH 8.8 Firefox — Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnera… 2026-08-18 CVE-2026-74947 HIGH 8.8 Firefox — Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox… 2026-08-18 CVE-2026-74948 MEDIUM 6.5 Firefox — Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115… 2026-08-18 CVE-2026-74949 HIGH 8.8 Firefox — Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed i… 2026-08-18 CVE-2026-74950 HIGH 8.8 Firefox — Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR … 2026-08-18 CVE-2026-74951 MEDIUM 6.5 Firefox — Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. 2026-08-18 CVE-2026-74952 HIGH 8.8 Firefox — Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunder… 2026-08-18 CVE-2026-74953 HIGH 8.8 Firefox — Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefo… 2026-08-18 CVE-2026-74954 HIGH 7.5 Firefox — Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed i… 2026-08-18 CVE-2026-74955 HIGH 8.8 Firefox — Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox E… 2026-08-18 CVE-2026-74956 CRITICAL 9.1 Firefox — Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, … 2026-08-18 CVE-2026-74957 HIGH 8.1 Firefox — Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140… 2026-08-18 CVE-2026-74958 HIGH 7.5 Firefox — Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1… 2026-08-18 CVE-2026-74959 CRITICAL 9.1 Firefox — Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ES… 2026-08-18 CVE-2026-74960 HIGH 8.1 Firefox — Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR … 2026-08-18 CVE-2026-74961 CRITICAL 9.1 Firefox — Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thund… 2026-08-18 CVE-2026-74962 HIGH 8.1 Firefox — Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefo… 2026-08-18 CVE-2026-74963 MEDIUM 5.4 Firefox — Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, F… 2026-08-18 CVE-2026-74964 CRITICAL 9.8 Firefox — Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, F… 2026-08-18 CVE-2026-74965 HIGH 8.8 Firefox — Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox … 2026-08-18 CVE-2026-74966 HIGH 7.5 Firefox — Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ES… 2026-08-18 CVE-2026-74967 MEDIUM 5.4 Firefox — Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154,… 2026-08-18 CVE-2026-74968 MEDIUM 5.4 Firefox — Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefo… 2026-08-18 CVE-2026-74969 HIGH 8.8 Firefox — Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox E… 2026-08-18 CVE-2026-74970 MEDIUM 5.4 Firefox — Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1… 2026-08-18 CVE-2026-74971 MEDIUM 4.3 Firefox — Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firef… 2026-08-18 CVE-2026-74972 MEDIUM 4.3 Firefox — Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, … 2026-08-18 CVE-2026-74973 MEDIUM 4.2 Firefox — Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox… 2026-08-18 CVE-2026-74974 MEDIUM 5.4 Firefox — Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Fi… 2026-08-18 CVE-2026-74975 MEDIUM 5.4 Firefox — Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. 2026-08-18 CVE-2026-74976 MEDIUM 6.5 Firefox — JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firef… 2026-08-18 CVE-2026-74977 HIGH 7.5 Firefox — Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Th… 2026-08-18 CVE-2026-74978 HIGH 8.1 Firefox — Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Th… 2026-08-18 CVE-2026-74979 CRITICAL 9.8 Firefox — Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 1… 2026-08-18 CVE-2026-74980 MEDIUM 6.5 Firefox — Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox … 2026-08-18 CVE-2026-74981 HIGH 8.1 Firefox — Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Fi… 2026-08-18 CVE-2026-74982 HIGH 7.5 Firefox — Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thu… 2026-08-18 CVE-2026-74983 HIGH 8.1 Firefox — Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox … 2026-08-18 CVE-2026-74984 MEDIUM 6.8 Firefox — Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 15… 2026-08-18 CVE-2026-74985 CRITICAL 9.8 Firefox — Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefo… 2026-08-18 CVE-2026-74986 CRITICAL 9.1 Firefox — Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154… 2026-08-18 CVE-2026-74987 CRITICAL 9.8 Firefox — Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of th… 2026-08-18 CVE-2026-74988 CRITICAL 9.8 Firefox — Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence… 2026-08-18 CVE-2026-74989 CRITICAL 9.8 Firefox — Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or a… 2026-08-18 CVE-2026-74990 CRITICAL 9.8 Firefox — Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of th… 2026-08-18 CVE-2026-75874 CRITICAL 10 Firefox — Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbi… 2026-08-18 CVE-2026-18809 MEDIUM 6.5 Firefox — Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in F… 2026-08-04 CVE-2026-14899 HIGH 7.5 Thunderbird — The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was e… 2026-07-22