Patch & vulnerability status
Mozilla Firefox 148.0.2
Latest tracked version 148.0.2. Release status, tracked CVEs, and automated cross-platform patching for Mozilla Firefox.
Category: Browsers
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 148.0.2 | 2772 | 2024-12-06 |
Known vulnerabilities (CVEs) in Mozilla Firefox
Lavawall tracks 2772 published CVEs affecting Mozilla Firefox, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2026-9309 | 2026-06-01 13:16:34 | MEDIUM (5) | Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2. | NETWORK |
| CVE-2026-9308 | 2026-06-01 13:16:34 | MEDIUM (5) | Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2. | NETWORK |
| CVE-2026-9078 | 2026-05-25 15:16:23 | MEDIUM (5) | Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1. | NETWORK |
| CVE-2026-8975 | 2026-05-19 14:16:54 | HIGH (9) | Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8974 | 2026-05-19 14:16:54 | HIGH (9) | Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8973 | 2026-05-19 14:16:54 | HIGH (9) | Memory safety bugs present in Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8972 | 2026-05-19 14:16:54 | HIGH (9) | Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8971 | 2026-05-19 14:16:54 | MEDIUM (7) | Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8970 | 2026-05-19 14:16:54 | HIGH (9) | Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8969 | 2026-05-19 14:16:53 | HIGH (8) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8968 | 2026-05-19 14:16:53 | HIGH (8) | Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8967 | 2026-05-19 14:16:53 | HIGH (8) | Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8966 | 2026-05-19 14:16:53 | HIGH (8) | Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8965 | 2026-05-19 14:16:53 | HIGH (8) | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8964 | 2026-05-19 14:16:53 | HIGH (8) | Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8963 | 2026-05-19 14:16:53 | HIGH (8) | Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8962 | 2026-05-19 14:16:53 | HIGH (8) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8961 | 2026-05-19 14:16:52 | MEDIUM (7) | Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8960 | 2026-05-19 14:16:52 | HIGH (8) | Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8959 | 2026-05-19 14:16:52 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8958 | 2026-05-19 14:16:52 | HIGH (9) | Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8957 | 2026-05-19 14:16:52 | HIGH (9) | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8956 | 2026-05-19 14:16:52 | CRITICAL (10) | Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8955 | 2026-05-19 14:16:52 | HIGH (9) | Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8954 | 2026-05-19 14:16:52 | HIGH (8) | Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8953 | 2026-05-19 14:16:52 | CRITICAL (10) | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8952 | 2026-05-19 14:16:51 | HIGH (9) | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8951 | 2026-05-19 14:16:51 | MEDIUM (7) | Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151. | NETWORK |
| CVE-2026-8950 | 2026-05-19 14:16:51 | CRITICAL (9) | Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8949 | 2026-05-19 14:16:51 | HIGH (8) | Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8948 | 2026-05-19 14:16:51 | CRITICAL (9) | Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. | NETWORK |
| CVE-2026-8947 | 2026-05-19 14:16:51 | HIGH (7) | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8946 | 2026-05-19 14:16:51 | HIGH (8) | Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. | NETWORK |
| CVE-2026-8945 | 2026-05-19 14:16:51 | HIGH (8) | Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151. | NETWORK |
| CVE-2026-8706 | 2026-05-19 16:16:23 | MEDIUM (7) | Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0. | ADJACENT_NETWORK |
| CVE-2026-8401 | 2026-05-12 15:16:20 | CRITICAL (10) | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3. | NETWORK |
| CVE-2026-8391 | 2026-05-12 14:17:12 | MEDIUM (5) | Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3. | NETWORK |
| CVE-2026-8390 | 2026-05-12 14:17:12 | HIGH (7) | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. | NETWORK |
| CVE-2026-8389 | 2026-05-12 14:17:12 | HIGH (9) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. | NETWORK |
| CVE-2026-8388 | 2026-05-12 14:17:12 | MEDIUM (7) | Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. | NETWORK |
| CVE-2026-8094 | 2026-05-07 13:16:14 | CRITICAL (10) | Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2. | NETWORK |
| CVE-2026-8093 | 2026-05-07 13:16:14 | HIGH (8) | Memory safety bugs present in Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2. | NETWORK |
| CVE-2026-8092 | 2026-05-07 13:16:14 | HIGH (8) | Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2. | NETWORK |
| CVE-2026-8091 | 2026-05-07 13:16:14 | CRITICAL (10) | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2. | NETWORK |
| CVE-2026-8090 | 2026-05-07 13:16:14 | HIGH (7) | Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2. | NETWORK |
| CVE-2026-7324 | 2026-04-28 15:16:38 | HIGH (7) | Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1. | NETWORK |
| CVE-2026-7323 | 2026-04-28 15:16:38 | HIGH (7) | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1. | NETWORK |
| CVE-2026-7322 | 2026-04-28 15:16:38 | HIGH (7) | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1. | NETWORK |
| CVE-2026-7321 | 2026-04-28 15:16:38 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1. | NETWORK |
| CVE-2026-7320 | 2026-04-28 15:16:37 | HIGH (8) | Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1. | NETWORK |
| CVE-2026-6786 | 2026-04-26 19:53:40 | HIGH (8) | Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6785 | 2026-04-26 19:53:39 | HIGH (8) | Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6784 | 2026-04-21 13:16:24 | HIGH (8) | Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6783 | 2026-04-21 13:16:24 | MEDIUM (5) | Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6782 | 2026-04-21 13:16:24 | HIGH (8) | Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6781 | 2026-04-21 13:16:24 | HIGH (8) | Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6780 | 2026-04-21 13:16:24 | HIGH (8) | Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6779 | 2026-04-21 13:16:24 | MEDIUM (5) | Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6778 | 2026-04-21 13:16:24 | MEDIUM (5) | Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6777 | 2026-04-21 13:16:23 | MEDIUM (5) | Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6776 | 2026-04-21 13:16:23 | HIGH (8) | Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | LOCAL |
| CVE-2026-6775 | 2026-04-21 13:16:23 | MEDIUM (5) | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6774 | 2026-04-21 13:16:23 | MEDIUM (5) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6773 | 2026-04-21 13:16:23 | HIGH (8) | Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6772 | 2026-04-21 13:16:23 | HIGH (8) | Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6771 | 2026-04-21 13:16:23 | CRITICAL (10) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6770 | 2026-04-21 13:16:23 | MEDIUM (7) | Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6769 | 2026-04-21 13:16:23 | HIGH (9) | Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6768 | 2026-04-21 13:16:23 | CRITICAL (10) | Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6767 | 2026-04-21 13:16:23 | MEDIUM (5) | Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6766 | 2026-04-21 13:16:22 | HIGH (8) | Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6765 | 2026-04-21 13:16:22 | MEDIUM (5) | Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6764 | 2026-04-21 13:16:22 | MEDIUM (7) | Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6763 | 2026-04-21 13:16:22 | MEDIUM (7) | Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6762 | 2026-04-21 13:16:22 | MEDIUM (6) | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6761 | 2026-04-21 13:16:22 | HIGH (9) | Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6760 | 2026-04-21 13:16:22 | CRITICAL (10) | Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6759 | 2026-04-21 13:16:22 | HIGH (8) | Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6758 | 2026-04-21 13:16:22 | HIGH (8) | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6757 | 2026-04-21 13:16:22 | MEDIUM (6) | Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6756 | 2026-04-21 13:16:22 | HIGH (8) | Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150. | NETWORK |
| CVE-2026-6755 | 2026-04-21 13:16:22 | MEDIUM (7) | Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. | NETWORK |
| CVE-2026-6754 | 2026-04-21 13:16:21 | HIGH (8) | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6753 | 2026-04-21 13:16:21 | HIGH (7) | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6752 | 2026-04-21 13:16:21 | HIGH (7) | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6751 | 2026-04-21 13:16:21 | HIGH (7) | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6750 | 2026-04-21 13:16:21 | HIGH (9) | Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6749 | 2026-04-21 13:16:21 | HIGH (8) | Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6748 | 2026-04-21 13:16:21 | CRITICAL (10) | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6747 | 2026-04-21 13:16:21 | HIGH (8) | Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-6746 | 2026-04-21 13:16:21 | HIGH (8) | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. | NETWORK |
| CVE-2026-5735 | 2026-04-07 13:16:48 | CRITICAL (10) | Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2. | NETWORK |
| CVE-2026-5734 | 2026-04-07 13:16:48 | CRITICAL (10) | Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1. | NETWORK |
| CVE-2026-5733 | 2026-04-07 13:16:48 | HIGH (9) | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2. | NETWORK |
| CVE-2026-5732 | 2026-04-07 13:16:47 | HIGH (9) | Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1. | NETWORK |
| CVE-2026-5731 | 2026-04-07 13:16:47 | CRITICAL (10) | Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1. | NETWORK |
| CVE-2026-4729 | 2026-03-24 13:16:09 | CRITICAL (10) | Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | NETWORK |
| CVE-2026-4728 | 2026-03-24 13:16:09 | MEDIUM (7) | Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | NETWORK |
| CVE-2026-4727 | 2026-03-24 13:16:09 | HIGH (8) | Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | NETWORK |
| CVE-2026-4726 | 2026-03-24 13:16:08 | HIGH (8) | Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | NETWORK |
| CVE-2026-4725 | 2026-03-24 13:16:08 | CRITICAL (10) | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | NETWORK |
| CVE-2026-4724 | 2026-03-24 13:16:08 | CRITICAL (9) | Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | NETWORK |
| CVE-2026-4723 | 2026-03-24 13:16:08 | CRITICAL (10) | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | NETWORK |
| CVE-2026-4722 | 2026-03-24 13:16:08 | HIGH (9) | Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | NETWORK |
| CVE-2026-4721 | 2026-03-24 13:16:08 | CRITICAL (10) | Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4720 | 2026-03-24 13:16:08 | CRITICAL (10) | Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4719 | 2026-03-24 13:16:08 | HIGH (8) | Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4718 | 2026-03-24 13:16:08 | HIGH (8) | Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4717 | 2026-03-24 13:16:08 | CRITICAL (10) | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4716 | 2026-03-24 13:16:08 | CRITICAL (9) | Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4715 | 2026-03-24 13:16:07 | CRITICAL (9) | Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4714 | 2026-03-24 13:16:07 | HIGH (8) | Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4713 | 2026-03-24 13:16:07 | HIGH (8) | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4712 | 2026-03-24 13:16:07 | HIGH (8) | Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4711 | 2026-03-24 13:16:07 | CRITICAL (10) | Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4710 | 2026-03-24 13:16:07 | CRITICAL (10) | Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4709 | 2026-03-24 13:16:07 | HIGH (8) | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4708 | 2026-03-24 13:16:07 | HIGH (8) | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4707 | 2026-03-24 13:16:07 | HIGH (8) | Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4706 | 2026-03-24 13:16:07 | HIGH (8) | Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4705 | 2026-03-24 13:16:06 | CRITICAL (10) | Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4704 | 2026-03-24 13:16:06 | HIGH (8) | Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4702 | 2026-03-24 13:16:06 | CRITICAL (10) | JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4701 | 2026-03-24 13:16:06 | CRITICAL (10) | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4700 | 2026-03-24 13:16:06 | CRITICAL (10) | Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4699 | 2026-03-24 13:16:06 | HIGH (8) | Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4698 | 2026-03-24 13:16:06 | CRITICAL (10) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4697 | 2026-03-24 13:16:06 | HIGH (8) | Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4696 | 2026-03-24 13:16:06 | CRITICAL (10) | Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4695 | 2026-03-24 13:16:05 | HIGH (8) | Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4694 | 2026-03-24 13:16:05 | HIGH (8) | Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4693 | 2026-03-24 13:16:05 | HIGH (8) | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4692 | 2026-03-24 13:16:05 | CRITICAL (10) | Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4691 | 2026-03-24 13:16:05 | CRITICAL (10) | Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4690 | 2026-03-24 13:16:05 | HIGH (9) | Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4689 | 2026-03-24 13:16:05 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4688 | 2026-03-24 13:16:05 | CRITICAL (10) | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4687 | 2026-03-24 13:16:05 | HIGH (9) | Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4686 | 2026-03-24 13:16:04 | HIGH (8) | Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4685 | 2026-03-24 13:16:04 | HIGH (8) | Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-4684 | 2026-03-24 13:16:04 | HIGH (8) | Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | NETWORK |
| CVE-2026-45173 | 2026-06-11 22:16:57 | HIGH (8) | Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21 | NETWORK |
| CVE-2026-3847 | 2026-03-10 18:19:06 | HIGH (9) | Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148.0.2. | NETWORK |
| CVE-2026-3846 | 2026-03-10 18:19:06 | MEDIUM (7) | Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2. | NETWORK |
| CVE-2026-3845 | 2026-03-10 18:19:06 | HIGH (9) | Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Firefox 148.0.2. | NETWORK |
| CVE-2026-2807 | 2026-02-24 14:16:29 | CRITICAL (10) | Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2806 | 2026-02-24 14:16:29 | CRITICAL (9) | Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2805 | 2026-02-24 14:16:29 | CRITICAL (10) | Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2804 | 2026-02-24 14:16:29 | MEDIUM (5) | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2803 | 2026-02-24 14:16:29 | HIGH (8) | Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2802 | 2026-02-24 14:16:29 | MEDIUM (4) | Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2801 | 2026-02-24 14:16:29 | HIGH (8) | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2800 | 2026-02-24 14:16:29 | CRITICAL (10) | Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2799 | 2026-02-24 14:16:28 | CRITICAL (10) | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2798 | 2026-02-24 14:16:28 | HIGH (9) | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2797 | 2026-02-24 14:16:28 | CRITICAL (10) | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2796 | 2026-02-24 14:16:28 | CRITICAL (10) | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2795 | 2026-02-24 14:16:28 | CRITICAL (10) | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | NETWORK |
| CVE-2026-2794 | 2026-02-24 14:16:28 | HIGH (8) | Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148. | NETWORK |
| CVE-2026-2793 | 2026-02-24 14:16:28 | CRITICAL (10) | Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2792 | 2026-02-24 14:16:28 | CRITICAL (10) | Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2791 | 2026-02-24 14:16:28 | CRITICAL (10) | Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2790 | 2026-02-24 14:16:27 | CRITICAL (10) | Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2789 | 2026-02-24 14:16:27 | CRITICAL (10) | Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2788 | 2026-02-24 14:16:27 | CRITICAL (10) | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2787 | 2026-02-24 14:16:27 | CRITICAL (10) | Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2786 | 2026-02-24 14:16:27 | CRITICAL (10) | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2785 | 2026-02-24 14:16:27 | CRITICAL (10) | Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2784 | 2026-02-24 14:16:27 | CRITICAL (10) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2783 | 2026-02-24 14:16:27 | HIGH (8) | Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2782 | 2026-02-24 14:16:27 | CRITICAL (10) | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2781 | 2026-02-24 14:16:27 | CRITICAL (10) | Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, Thunderbird 140.8, and Firefox ESR 115.35. | NETWORK |
| CVE-2026-2780 | 2026-02-24 14:16:26 | CRITICAL (10) | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2779 | 2026-02-24 14:16:26 | CRITICAL (10) | Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2778 | 2026-02-24 14:16:26 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2777 | 2026-02-24 14:16:26 | CRITICAL (10) | Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2776 | 2026-02-24 14:16:26 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2775 | 2026-02-24 14:16:26 | CRITICAL (10) | Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2774 | 2026-02-24 14:16:26 | CRITICAL (10) | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2773 | 2026-02-24 14:16:26 | CRITICAL (10) | Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2772 | 2026-02-24 14:16:26 | CRITICAL (10) | Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2771 | 2026-02-24 14:16:25 | CRITICAL (10) | Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2770 | 2026-02-24 14:16:25 | CRITICAL (10) | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2769 | 2026-02-24 14:16:25 | HIGH (9) | Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2768 | 2026-02-24 14:16:25 | CRITICAL (10) | Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2767 | 2026-02-24 14:16:25 | CRITICAL (10) | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2766 | 2026-02-24 14:16:25 | CRITICAL (10) | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2765 | 2026-02-24 14:16:25 | CRITICAL (10) | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2764 | 2026-02-24 14:16:25 | CRITICAL (10) | JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2763 | 2026-02-24 14:16:25 | CRITICAL (10) | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2762 | 2026-02-24 14:16:24 | CRITICAL (10) | Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2761 | 2026-02-24 14:16:24 | CRITICAL (10) | Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2760 | 2026-02-24 14:16:24 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2759 | 2026-02-24 14:16:24 | CRITICAL (10) | Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2758 | 2026-02-24 14:16:24 | CRITICAL (10) | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2757 | 2026-02-24 14:16:24 | CRITICAL (10) | Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. | NETWORK |
| CVE-2026-2634 | 2026-02-24 14:16:24 | CRITICAL (10) | Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability was fixed in Firefox for iOS 147.4. | NETWORK |
| CVE-2026-24869 | 2026-01-27 16:16:36 | HIGH (9) | Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2. | NETWORK |
| CVE-2026-24868 | 2026-01-27 16:16:36 | MEDIUM (7) | Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2. | NETWORK |
| CVE-2026-2447 | 2026-02-16 15:18:35 | HIGH (9) | Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2. | NETWORK |
| CVE-2026-2032 | 2026-02-16 15:18:35 | MEDIUM (4) | Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1. | NETWORK |
| CVE-2026-16412 | 2026-07-21 13:17:17 | CRITICAL (10) | Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16411 | 2026-07-21 13:17:17 | CRITICAL (10) | Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16410 | 2026-07-21 13:17:16 | CRITICAL (10) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16409 | 2026-07-21 13:17:16 | HIGH (8) | Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16408 | 2026-07-21 13:17:16 | CRITICAL (10) | Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16407 | 2026-07-21 13:17:16 | CRITICAL (10) | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16406 | 2026-07-21 13:17:16 | CRITICAL (9) | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16405 | 2026-07-21 13:17:16 | HIGH (8) | Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16403 | 2026-07-21 13:17:16 | MEDIUM (7) | Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16402 | 2026-07-21 13:17:16 | CRITICAL (10) | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16401 | 2026-07-21 13:17:15 | HIGH (9) | Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16400 | 2026-07-21 13:17:15 | HIGH (8) | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16399 | 2026-07-21 13:17:15 | HIGH (8) | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16398 | 2026-07-21 13:17:15 | HIGH (8) | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16397 | 2026-07-21 13:17:15 | MEDIUM (7) | Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153. | NETWORK |
| CVE-2026-16396 | 2026-07-21 13:17:15 | HIGH (9) | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16395 | 2026-07-21 13:17:15 | CRITICAL (10) | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16394 | 2026-07-21 13:17:15 | CRITICAL (9) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16393 | 2026-07-21 13:17:15 | CRITICAL (9) | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16392 | 2026-07-21 13:17:14 | CRITICAL (9) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16391 | 2026-07-21 13:17:14 | HIGH (8) | Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16390 | 2026-07-21 13:17:14 | CRITICAL (9) | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16389 | 2026-07-21 13:17:14 | CRITICAL (10) | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16388 | 2026-07-21 13:17:14 | CRITICAL (10) | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16387 | 2026-07-21 13:17:14 | CRITICAL (10) | Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16386 | 2026-07-21 13:17:14 | HIGH (8) | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16385 | 2026-07-21 13:17:14 | HIGH (8) | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16384 | 2026-07-21 13:17:14 | HIGH (8) | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16383 | 2026-07-21 13:17:13 | CRITICAL (10) | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16382 | 2026-07-21 13:17:13 | CRITICAL (10) | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16381 | 2026-07-21 13:17:13 | CRITICAL (9) | Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16380 | 2026-07-21 13:17:13 | CRITICAL (9) | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16379 | 2026-07-21 13:17:13 | HIGH (9) | Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16378 | 2026-07-21 13:17:13 | HIGH (8) | Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16377 | 2026-07-21 13:17:13 | CRITICAL (10) | Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16376 | 2026-07-21 13:17:13 | HIGH (8) | Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16375 | 2026-07-21 13:17:13 | CRITICAL (10) | Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16374 | 2026-07-21 13:17:13 | HIGH (8) | Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16372 | 2026-07-21 13:17:12 | HIGH (9) | Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16371 | 2026-07-21 13:17:12 | HIGH (9) | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16370 | 2026-07-21 13:17:07 | CRITICAL (9) | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16369 | 2026-07-21 13:17:07 | CRITICAL (10) | Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16368 | 2026-07-21 13:17:05 | CRITICAL (10) | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16367 | 2026-07-21 13:17:05 | CRITICAL (10) | Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16366 | 2026-07-21 13:17:05 | HIGH (9) | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16365 | 2026-07-21 13:17:05 | HIGH (9) | Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16364 | 2026-07-21 13:17:05 | CRITICAL (9) | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | NETWORK |
| CVE-2026-16363 | 2026-07-21 13:17:05 | CRITICAL (10) | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16362 | 2026-07-21 13:17:05 | HIGH (9) | Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16361 | 2026-07-21 13:17:05 | CRITICAL (10) | Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16360 | 2026-07-21 13:17:05 | CRITICAL (10) | Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16359 | 2026-07-21 13:17:04 | CRITICAL (9) | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16358 | 2026-07-21 13:17:04 | CRITICAL (10) | Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16357 | 2026-07-21 13:17:04 | CRITICAL (10) | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16356 | 2026-07-21 13:17:04 | CRITICAL (10) | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16355 | 2026-07-21 13:17:04 | CRITICAL (10) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16354 | 2026-07-21 13:17:04 | HIGH (8) | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16353 | 2026-07-21 13:17:04 | CRITICAL (10) | Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16352 | 2026-07-21 13:17:04 | CRITICAL (10) | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16351 | 2026-07-21 13:17:04 | CRITICAL (10) | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16350 | 2026-07-21 13:17:03 | CRITICAL (10) | Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-16349 | 2026-07-21 13:17:03 | CRITICAL (10) | Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | NETWORK |
| CVE-2026-15719 | 2026-07-14 13:18:20 | MEDIUM (5) | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13. | NETWORK |
| CVE-2026-15718 | 2026-07-14 13:18:20 | MEDIUM (4) | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13. | NETWORK |
| CVE-2026-14241 | 2026-06-30 14:16:26 | CRITICAL (10) | Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4. | NETWORK |
| CVE-2026-13356 | 2026-07-07 00:16:34 | MEDIUM (6) | A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3. | NETWORK |
| CVE-2026-12330 | 2026-06-16 13:16:34 | MEDIUM (5) | Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12329 | 2026-06-16 13:16:34 | MEDIUM (5) | Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. | NETWORK |
| CVE-2026-12328 | 2026-06-16 13:16:34 | HIGH (8) | Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12327 | 2026-06-16 13:16:33 | HIGH (8) | Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12326 | 2026-06-16 13:16:33 | HIGH (8) | Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12325 | 2026-06-16 13:16:33 | MEDIUM (7) | Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12324 | 2026-06-16 13:16:33 | HIGH (7) | Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12323 | 2026-06-16 13:16:33 | MEDIUM (5) | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12322 | 2026-06-16 13:16:33 | MEDIUM (5) | Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12321 | 2026-06-16 13:16:33 | MEDIUM (5) | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12320 | 2026-06-16 13:16:33 | MEDIUM (4) | Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12319 | 2026-06-16 13:16:33 | MEDIUM (7) | Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12318 | 2026-06-16 13:16:32 | HIGH (7) | Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12317 | 2026-06-16 13:16:32 | HIGH (8) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12316 | 2026-06-16 13:16:32 | CRITICAL (9) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12315 | 2026-06-16 13:16:32 | CRITICAL (9) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12314 | 2026-06-16 13:16:32 | HIGH (8) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12313 | 2026-06-16 13:16:32 | MEDIUM (5) | Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12312 | 2026-06-16 13:16:32 | HIGH (8) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12311 | 2026-06-16 13:16:32 | MEDIUM (5) | Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12310 | 2026-06-16 13:16:31 | HIGH (8) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12309 | 2026-06-16 13:16:31 | MEDIUM (7) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12308 | 2026-06-16 13:16:31 | MEDIUM (5) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12307 | 2026-06-16 13:16:31 | MEDIUM (5) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12306 | 2026-06-16 13:16:31 | MEDIUM (5) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12305 | 2026-06-16 13:16:31 | HIGH (8) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12304 | 2026-06-16 13:16:31 | CRITICAL (9) | Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12303 | 2026-06-16 13:16:31 | MEDIUM (4) | Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12302 | 2026-06-16 13:16:30 | MEDIUM (7) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12301 | 2026-06-16 13:16:30 | MEDIUM (5) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12300 | 2026-06-16 13:16:30 | MEDIUM (5) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12299 | 2026-06-16 13:16:30 | MEDIUM (5) | JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12298 | 2026-06-16 13:16:30 | MEDIUM (5) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12297 | 2026-06-16 13:16:30 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12296 | 2026-06-16 13:16:30 | CRITICAL (10) | Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12295 | 2026-06-16 13:16:30 | CRITICAL (10) | Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12294 | 2026-06-16 13:16:30 | CRITICAL (10) | Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12293 | 2026-06-16 13:16:30 | CRITICAL (10) | Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | NETWORK |
| CVE-2026-12292 | 2026-06-16 13:16:29 | HIGH (8) | Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12291 | 2026-06-16 13:16:29 | HIGH (9) | Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12290 | 2026-06-16 13:16:29 | HIGH (8) | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-12289 | 2026-06-16 13:16:29 | HIGH (9) | Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | NETWORK |
| CVE-2026-10702 | 2026-06-02 20:16:33 | MEDIUM (4) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. | NETWORK |
| CVE-2026-10701 | 2026-06-02 20:16:33 | HIGH (8) | Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3. | NETWORK |
| CVE-2026-0892 | 2026-01-13 14:16:40 | CRITICAL (10) | Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147 and Thunderbird 147. | NETWORK |
| CVE-2026-0891 | 2026-01-13 14:16:40 | HIGH (8) | Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0890 | 2026-01-13 14:16:40 | MEDIUM (5) | Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0889 | 2026-01-13 14:16:39 | HIGH (8) | Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. | NETWORK |
| CVE-2026-0888 | 2026-01-13 14:16:39 | MEDIUM (5) | Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. | NETWORK |
| CVE-2026-0887 | 2026-01-13 14:16:39 | MEDIUM (4) | Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0886 | 2026-01-13 14:16:39 | MEDIUM (5) | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0885 | 2026-01-13 14:16:39 | MEDIUM (7) | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0884 | 2026-01-13 14:16:39 | CRITICAL (10) | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0883 | 2026-01-13 14:16:39 | MEDIUM (5) | Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0882 | 2026-01-13 14:16:39 | HIGH (9) | Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0881 | 2026-01-13 14:16:39 | CRITICAL (10) | Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. | NETWORK |
| CVE-2026-0880 | 2026-01-13 14:16:39 | HIGH (9) | Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0879 | 2026-01-13 14:16:38 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0878 | 2026-01-13 14:16:38 | HIGH (8) | Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2026-0877 | 2026-01-13 14:16:38 | HIGH (8) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. | NETWORK |
| CVE-2025-9187 | 2025-08-19 21:15:31 | CRITICAL (10) | Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142 and Thunderbird < 142. | NETWORK |
| CVE-2025-9186 | 2025-08-19 21:15:31 | MEDIUM (7) | Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142. | NETWORK |
| CVE-2025-9185 | 2025-08-19 21:15:31 | HIGH (8) | Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. | NETWORK |
| CVE-2025-9184 | 2025-08-19 21:15:31 | HIGH (8) | Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2. | NETWORK |
| CVE-2025-9183 | 2025-08-19 21:15:31 | MEDIUM (7) | Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2. | NETWORK |
| CVE-2025-9182 | 2025-08-19 21:15:31 | HIGH (8) | Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2. | NETWORK |
| CVE-2025-9181 | 2025-08-19 21:15:31 | MEDIUM (7) | Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. | NETWORK |
| CVE-2025-9180 | 2025-08-19 21:15:30 | HIGH (8) | Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. | NETWORK |
| CVE-2025-9179 | 2025-08-19 21:15:30 | CRITICAL (10) | An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. | NETWORK |
| CVE-2025-8364 | 2025-08-19 21:15:30 | MEDIUM (4) | A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141. | NETWORK |
| CVE-2025-8044 | 2025-07-22 21:15:51 | CRITICAL (10) | Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141 and Thunderbird < 141. | NETWORK |
| CVE-2025-8043 | 2025-07-22 21:15:51 | CRITICAL (10) | Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability affects Firefox < 141 and Thunderbird < 141. | NETWORK |
| CVE-2025-8042 | 2025-08-19 21:15:29 | CRITICAL (10) | Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141. | NETWORK |
| CVE-2025-8041 | 2025-08-19 21:15:29 | MEDIUM (5) | In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141. | NETWORK |
| CVE-2025-8040 | 2025-07-22 21:15:51 | HIGH (9) | Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8039 | 2025-07-22 21:15:51 | HIGH (8) | In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8038 | 2025-07-22 21:15:51 | CRITICAL (10) | Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8037 | 2025-07-22 21:15:51 | CRITICAL (9) | Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8036 | 2025-07-22 21:15:51 | HIGH (8) | Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8035 | 2025-07-22 21:15:51 | HIGH (9) | Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8034 | 2025-07-22 21:15:51 | HIGH (9) | Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8033 | 2025-07-22 21:15:50 | MEDIUM (7) | The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8032 | 2025-07-22 21:15:50 | HIGH (8) | XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8031 | 2025-07-22 21:15:50 | CRITICAL (10) | The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8030 | 2025-07-22 21:15:50 | HIGH (8) | Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8029 | 2025-07-22 21:15:50 | HIGH (8) | Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8028 | 2025-07-22 21:15:50 | CRITICAL (10) | On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-8027 | 2025-07-22 21:15:50 | MEDIUM (7) | On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | NETWORK |
| CVE-2025-6436 | 2025-06-24 13:15:25 | HIGH (8) | Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 140 and Thunderbird < 140. | NETWORK |
| CVE-2025-6435 | 2025-06-24 13:15:25 | HIGH (8) | If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability affects Firefox < 140 and Thunderbird < 140. | NETWORK |
| CVE-2025-6434 | 2025-06-24 13:15:24 | MEDIUM (4) | The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140. | NETWORK |
| CVE-2025-6433 | 2025-06-24 13:15:24 | CRITICAL (10) | If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140 and Thunderbird < 140. | NETWORK |
| CVE-2025-6432 | 2025-06-24 13:15:24 | HIGH (9) | When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox < 140 and Thunderbird < 140. | NETWORK |
| CVE-2025-6431 | 2025-06-24 13:15:24 | MEDIUM (7) | When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140. | NETWORK |
| CVE-2025-6430 | 2025-06-24 13:15:24 | MEDIUM (6) | When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | NETWORK |
| CVE-2025-6429 | 2025-06-24 13:15:24 | MEDIUM (7) | Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | NETWORK |
| CVE-2025-6428 | 2025-06-24 13:15:24 | MEDIUM (4) | When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140. | NETWORK |
| CVE-2025-6427 | 2025-06-24 13:15:24 | CRITICAL (9) | An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140. | NETWORK |
| CVE-2025-6426 | 2025-06-24 13:15:24 | HIGH (9) | The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | NETWORK |
| CVE-2025-6425 | 2025-06-24 13:15:23 | MEDIUM (4) | An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | NETWORK |
| CVE-2025-6424 | 2025-06-24 13:15:23 | CRITICAL (10) | A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. | NETWORK |
| CVE-2025-55031 | 2025-08-19 21:15:28 | CRITICAL (10) | Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142. | NETWORK |
| CVE-2025-55030 | 2025-08-19 21:15:28 | MEDIUM (6) | Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks This vulnerability affects Firefox for iOS < 142. | NETWORK |
| CVE-2025-55029 | 2025-08-19 21:15:28 | HIGH (8) | Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks This vulnerability affects Firefox for iOS < 142. | NETWORK |
| CVE-2025-55028 | 2025-08-19 21:15:28 | MEDIUM (7) | Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks This vulnerability affects Firefox for iOS < 142. | NETWORK |
| CVE-2025-54145 | 2025-08-19 21:15:28 | CRITICAL (9) | The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme This vulnerability affects Firefox for iOS < 141. | NETWORK |
| CVE-2025-54144 | 2025-08-19 21:15:28 | MEDIUM (5) | The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141. | NETWORK |
| CVE-2025-54143 | 2025-08-19 21:15:28 | CRITICAL (10) | Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141. | NETWORK |
| CVE-2025-5272 | 2025-05-27 13:15:23 | HIGH (7) | Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139 and Thunderbird < 139. | NETWORK |
| CVE-2025-5271 | 2025-05-27 13:15:23 | MEDIUM (7) | Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability affects Firefox < 139 and Thunderbird < 139. | NETWORK |
| CVE-2025-5270 | 2025-05-27 13:15:23 | HIGH (8) | In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139 and Thunderbird < 139. | NETWORK |
| CVE-2025-5269 | 2025-05-27 13:15:23 | MEDIUM (8) | Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.11 and Thunderbird < 128.11. | NETWORK |
| CVE-2025-5268 | 2025-05-27 13:15:23 | MEDIUM (8) | Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. | NETWORK |
| CVE-2025-5267 | 2025-05-27 13:15:23 | MEDIUM (5) | A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. | NETWORK |
| CVE-2025-5266 | 2025-05-27 13:15:22 | MEDIUM (7) | Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. | NETWORK |
| CVE-2025-5265 | 2025-05-27 13:15:22 | MEDIUM (5) | Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. | LOCAL |
| CVE-2025-5264 | 2025-05-27 13:15:22 | MEDIUM (5) | Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. | LOCAL |
| CVE-2025-5263 | 2025-05-27 13:15:22 | MEDIUM (4) | Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. | NETWORK |
| CVE-2025-5020 | 2025-05-21 18:15:54 | MEDIUM (4) | Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client This vulnerability affects Firefox for iOS < 139. | NETWORK |
| CVE-2025-49710 | 2025-06-11 12:15:27 | CRITICAL (10) | An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4. | NETWORK |
| CVE-2025-49709 | 2025-06-11 12:15:27 | CRITICAL (10) | Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4. | NETWORK |
| CVE-2025-4919 | 2025-05-17 22:15:20 | HIGH (9) | An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2. | NETWORK |
| CVE-2025-4918 | 2025-05-17 22:15:20 | CRITICAL (10) | An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2. | NETWORK |
| CVE-2025-4093 | 2025-04-29 14:15:36 | HIGH (8) | Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.10 and Thunderbird < 128.10. | NETWORK |
| CVE-2025-4092 | 2025-04-29 14:15:36 | MEDIUM (7) | Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138 and Thunderbird < 138. | NETWORK |
| CVE-2025-4091 | 2025-04-29 14:15:36 | HIGH (8) | Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10. | NETWORK |
| CVE-2025-4090 | 2025-04-29 14:15:36 | MEDIUM (5) | A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability affects Firefox < 138 and Thunderbird < 138. | NETWORK |
| CVE-2025-4089 | 2025-04-29 14:15:36 | MEDIUM (5) | Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 138 and Thunderbird < 138. | LOCAL |
| CVE-2025-4088 | 2025-04-29 14:15:35 | MEDIUM (7) | A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138. | NETWORK |
| CVE-2025-4087 | 2025-04-29 14:15:35 | MEDIUM (5) | A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10. | NETWORK |
| CVE-2025-4086 | 2025-04-29 14:15:35 | MEDIUM (7) | A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138. | NETWORK |
| CVE-2025-4085 | 2025-04-29 14:15:35 | HIGH (7) | An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138. | NETWORK |
| CVE-2025-4084 | 2025-04-29 14:15:35 | MEDIUM (6) | Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox ESR < 128.10, Firefox ESR < 115.23, and Thunderbird < 128.10. | NETWORK |
| CVE-2025-4083 | 2025-04-29 14:15:35 | CRITICAL (9) | A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10. | NETWORK |
| CVE-2025-4082 | 2025-04-29 14:15:35 | MEDIUM (6) | Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10. | NETWORK |
| CVE-2025-3608 | 2025-04-15 13:15:56 | MEDIUM (7) | A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2. | NETWORK |
| CVE-2025-3035 | 2025-04-01 13:15:42 | MEDIUM (5) | By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability affects Firefox < 137. | NETWORK |
| CVE-2025-3034 | 2025-04-01 13:15:42 | HIGH (8) | Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137 and Thunderbird < 137. | NETWORK |
| CVE-2025-3033 | 2025-04-01 13:15:42 | HIGH (8) | After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137. | LOCAL |
| CVE-2025-3032 | 2025-04-01 13:15:42 | HIGH (7) | Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137. | NETWORK |
| CVE-2025-3031 | 2025-04-01 13:15:41 | MEDIUM (7) | An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability affects Firefox < 137 and Thunderbird < 137. | NETWORK |
| CVE-2025-3030 | 2025-04-01 13:15:41 | HIGH (8) | Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9. | NETWORK |
| CVE-2025-3029 | 2025-04-01 13:15:41 | HIGH (7) | A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9. | NETWORK |
| CVE-2025-3028 | 2025-04-01 13:15:41 | MEDIUM (7) | JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9. | NETWORK |
| CVE-2025-2857 | 2025-03-27 14:15:56 | CRITICAL (10) | Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 136.0.4, Firefox ESR < 128.8.1, and Firefox ESR < 115.21.1. | NETWORK |
| CVE-2025-2817 | 2025-04-29 14:15:32 | HIGH (9) | Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10. | NETWORK |
| CVE-2025-27426 | 2025-03-04 14:15:40 | MEDIUM (5) | Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox for iOS < 136. | NETWORK |
| CVE-2025-27425 | 2025-03-04 14:15:39 | MEDIUM (4) | Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136. | NETWORK |
| CVE-2025-27424 | 2025-03-04 14:15:39 | MEDIUM (4) | Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136. | NETWORK |
| CVE-2025-23109 | 2025-01-11 04:15:06 | MEDIUM (7) | Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134. | NETWORK |
| CVE-2025-23108 | 2025-01-11 04:15:06 | MEDIUM (4) | Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134. | NETWORK |
| CVE-2025-1943 | 2025-03-04 14:15:39 | HIGH (8) | Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Thunderbird < 136. | NETWORK |
| CVE-2025-1942 | 2025-03-04 14:15:39 | CRITICAL (10) | When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136. | NETWORK |
| CVE-2025-1941 | 2025-03-04 14:15:39 | CRITICAL (9) | Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136. | NETWORK |
| CVE-2025-1940 | 2025-03-04 14:15:39 | HIGH (7) | A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 136. | NETWORK |
| CVE-2025-1939 | 2025-03-04 14:15:39 | LOW (4) | Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136. | LOCAL |
| CVE-2025-1938 | 2025-03-04 14:15:39 | MEDIUM (7) | Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-1937 | 2025-03-04 14:15:39 | HIGH (8) | Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-1936 | 2025-03-04 14:15:39 | HIGH (7) | jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-1935 | 2025-03-04 14:15:38 | MEDIUM (4) | A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-1934 | 2025-03-04 14:15:38 | MEDIUM (7) | It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-1933 | 2025-03-04 14:15:38 | HIGH (8) | On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-1932 | 2025-03-04 14:15:38 | HIGH (8) | An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-1931 | 2025-03-04 14:15:38 | HIGH (8) | It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-1930 | 2025-03-04 14:15:38 | HIGH (9) | On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. | NETWORK |
| CVE-2025-14861 | 2025-12-18 15:15:53 | HIGH (9) | Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146.0.1. | NETWORK |
| CVE-2025-14860 | 2025-12-18 15:15:53 | CRITICAL (10) | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. | NETWORK |
| CVE-2025-14744 | 2025-12-18 15:15:53 | MEDIUM (7) | Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0. | NETWORK |
| CVE-2025-14333 | 2025-12-09 16:17:41 | HIGH (8) | Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14332 | 2025-12-09 16:17:41 | HIGH (7) | Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146 and Thunderbird 146. | NETWORK |
| CVE-2025-14331 | 2025-12-09 16:17:41 | MEDIUM (7) | Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14330 | 2025-12-09 16:17:41 | CRITICAL (10) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14329 | 2025-12-09 16:17:41 | HIGH (9) | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14328 | 2025-12-09 16:17:40 | HIGH (9) | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14327 | 2025-12-09 16:17:40 | HIGH (8) | Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7. | NETWORK |
| CVE-2025-14326 | 2025-12-09 16:17:40 | CRITICAL (10) | Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146. | NETWORK |
| CVE-2025-14325 | 2025-12-09 16:17:40 | HIGH (7) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14324 | 2025-12-09 16:17:40 | CRITICAL (10) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14323 | 2025-12-09 16:17:40 | HIGH (9) | Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14322 | 2025-12-09 16:17:40 | HIGH (8) | Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-14321 | 2025-12-09 16:17:39 | CRITICAL (10) | Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. | NETWORK |
| CVE-2025-1414 | 2025-02-18 14:15:29 | MEDIUM (7) | Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135.0.1. | NETWORK |
| CVE-2025-13027 | 2025-11-11 16:15:40 | HIGH (8) | Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 145 and Thunderbird 145. | NETWORK |
| CVE-2025-13026 | 2025-11-11 16:15:40 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. | NETWORK |
| CVE-2025-13025 | 2025-11-11 16:15:40 | HIGH (8) | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. | NETWORK |
| CVE-2025-13024 | 2025-11-11 16:15:40 | CRITICAL (10) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. | NETWORK |
| CVE-2025-13023 | 2025-11-11 16:15:39 | CRITICAL (10) | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. | NETWORK |
| CVE-2025-13022 | 2025-11-11 16:15:39 | CRITICAL (10) | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. | NETWORK |
| CVE-2025-13021 | 2025-11-11 16:15:39 | CRITICAL (10) | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. | NETWORK |
| CVE-2025-13020 | 2025-11-11 16:15:39 | HIGH (9) | Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5. | NETWORK |
| CVE-2025-13019 | 2025-11-11 16:15:39 | HIGH (8) | Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5. | NETWORK |
| CVE-2025-13018 | 2025-11-11 16:15:39 | HIGH (8) | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5. | NETWORK |
| CVE-2025-13017 | 2025-11-11 16:15:39 | HIGH (8) | Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5. | NETWORK |
| CVE-2025-13016 | 2025-11-11 16:15:39 | HIGH (8) | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5. | NETWORK |
| CVE-2025-13015 | 2025-11-11 16:15:39 | LOW (3) | Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30. | NETWORK |
| CVE-2025-13014 | 2025-11-11 16:15:38 | HIGH (9) | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5. | NETWORK |
| CVE-2025-13013 | 2025-11-11 16:15:38 | MEDIUM (6) | Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5. | NETWORK |
| CVE-2025-13012 | 2025-11-11 16:15:38 | HIGH (8) | Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5. | NETWORK |
| CVE-2025-12380 | 2025-10-28 14:15:58 | CRITICAL (10) | Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-related IPC calls. This may have been usable to escape the child process sandbox. This vulnerability was fixed in Firefox 144.0.2. | NETWORK |
| CVE-2025-11721 | 2025-10-14 13:15:39 | CRITICAL (10) | Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | NETWORK |
| CVE-2025-11720 | 2025-10-14 13:15:38 | HIGH (8) | The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144. | NETWORK |
| CVE-2025-11719 | 2025-10-14 13:15:38 | CRITICAL (10) | Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | NETWORK |
| CVE-2025-11718 | 2025-10-14 13:15:38 | MEDIUM (7) | When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144. | NETWORK |
| CVE-2025-11717 | 2025-10-14 13:15:38 | CRITICAL (9) | When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability was fixed in Firefox 144. | NETWORK |
| CVE-2025-11716 | 2025-10-14 13:15:38 | MEDIUM (7) | Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | NETWORK |
| CVE-2025-11715 | 2025-10-14 13:15:38 | HIGH (9) | Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | NETWORK |
| CVE-2025-11714 | 2025-10-14 13:15:38 | HIGH (9) | Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | NETWORK |
| CVE-2025-11713 | 2025-10-14 13:15:38 | HIGH (8) | Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | NETWORK |
| CVE-2025-11712 | 2025-10-14 13:15:37 | MEDIUM (6) | A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | NETWORK |
| CVE-2025-11711 | 2025-10-14 13:15:37 | MEDIUM (7) | There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | NETWORK |
| CVE-2025-11710 | 2025-10-14 13:15:37 | CRITICAL (10) | A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | NETWORK |
| CVE-2025-11709 | 2025-10-14 13:15:37 | CRITICAL (10) | A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | NETWORK |
| CVE-2025-11708 | 2025-10-14 13:15:37 | CRITICAL (10) | Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. | NETWORK |
| CVE-2025-11153 | 2025-09-30 13:15:49 | HIGH (8) | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 143.0.3. | NETWORK |
| CVE-2025-11152 | 2025-09-30 13:15:49 | HIGH (9) | Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143.0.3. | NETWORK |
| CVE-2025-10859 | 2025-09-30 13:15:49 | MEDIUM (4) | Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143.1. | LOCAL |
| CVE-2025-10537 | 2025-09-16 13:15:49 | HIGH (9) | Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | NETWORK |
| CVE-2025-10536 | 2025-09-16 13:15:49 | MEDIUM (6) | Information disclosure in the Networking: Cache component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | LOCAL |
| CVE-2025-10535 | 2025-09-16 13:15:49 | HIGH (8) | Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability affects Firefox < 143. | NETWORK |
| CVE-2025-10534 | 2025-09-16 13:15:48 | HIGH (8) | Spoofing issue in the Site Permissions component. This vulnerability affects Firefox < 143 and Thunderbird < 143. | NETWORK |
| CVE-2025-10533 | 2025-09-16 13:15:48 | HIGH (9) | Integer overflow in the SVG component. This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | NETWORK |
| CVE-2025-10532 | 2025-09-16 13:15:47 | MEDIUM (7) | Incorrect boundary conditions in the JavaScript: GC component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | NETWORK |
| CVE-2025-10531 | 2025-09-16 13:15:47 | MEDIUM (5) | Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability affects Firefox < 143 and Thunderbird < 143. | NETWORK |
| CVE-2025-10530 | 2025-09-16 13:15:46 | MEDIUM (7) | Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability affects Firefox < 143 and Thunderbird < 143. | NETWORK |
| CVE-2025-10529 | 2025-09-16 13:15:46 | MEDIUM (7) | Same-origin policy bypass in the Layout component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | NETWORK |
| CVE-2025-10528 | 2025-09-16 13:15:45 | HIGH (7) | Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | NETWORK |
| CVE-2025-10527 | 2025-09-16 13:15:44 | HIGH (7) | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. | NETWORK |
| CVE-2025-1020 | 2025-02-04 14:15:33 | CRITICAL (10) | Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135 and Thunderbird < 135. | NETWORK |
| CVE-2025-1019 | 2025-02-04 14:15:33 | MEDIUM (4) | The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135. | NETWORK |
| CVE-2025-1018 | 2025-02-04 14:15:33 | MEDIUM (5) | The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135. | NETWORK |
| CVE-2025-1017 | 2025-02-04 14:15:33 | CRITICAL (10) | Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135. | NETWORK |
| CVE-2025-1016 | 2025-02-04 14:15:32 | CRITICAL (10) | Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135. | NETWORK |
| CVE-2025-1014 | 2025-02-04 14:15:32 | HIGH (9) | Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135. | NETWORK |
Showing the 500 most recent of 2772 tracked CVEs.
Why keeping Mozilla Firefox patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Mozilla Firefox release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Mozilla Firefox
Lavawall® watches Mozilla Firefox releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Mozilla Firefox, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Mozilla Firefox at version 148.0.2 (last checked 2024-12-06). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 2772 CVEs for Mozilla Firefox and remediates them automatically as part of patching.
Deploy the Lavawall® agent and Mozilla Firefox updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Mozilla Firefox through public information and proprietary statistical analysis, and can patch it automatically across your fleet.