Total
3337 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-74978 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 8.1 HIGH |
| Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74985 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 9.8 CRITICAL |
| Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74970 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 5.4 MEDIUM |
| Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74977 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 7.5 HIGH |
| Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74934 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 7.5 HIGH |
| Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74945 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 6.5 MEDIUM |
| Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74948 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 6.5 MEDIUM |
| Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74957 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 8.1 HIGH |
| Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74959 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 9.1 CRITICAL |
| Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74960 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 8.1 HIGH |
| Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74944 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 9.8 CRITICAL |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74943 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 9.8 CRITICAL |
| Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74940 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 9.8 CRITICAL |
| Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74936 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 9.8 CRITICAL |
| Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74965 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 8.8 HIGH |
| Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74955 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 8.8 HIGH |
| Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74953 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 8.8 HIGH |
| Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74950 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 8.8 HIGH |
| Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74947 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 8.8 HIGH |
| Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74946 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 8.8 HIGH |
| Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
