Total
1916 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-74986 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 9.1 CRITICAL |
| Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74981 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 8.1 HIGH |
| Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74984 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 6.8 MEDIUM |
| Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74982 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 7.5 HIGH |
| Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74966 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 7.5 HIGH |
| Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74978 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 8.1 HIGH |
| Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74985 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 9.8 CRITICAL |
| Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74970 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 5.4 MEDIUM |
| Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74977 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 7.5 HIGH |
| Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74934 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 7.5 HIGH |
| Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74945 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 6.5 MEDIUM |
| Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74948 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 6.5 MEDIUM |
| Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74957 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 8.1 HIGH |
| Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74959 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 9.1 CRITICAL |
| Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74960 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 8.1 HIGH |
| Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74944 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 9.8 CRITICAL |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74943 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 9.8 CRITICAL |
| Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74940 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 9.8 CRITICAL |
| Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74936 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 9.8 CRITICAL |
| Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74965 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-21 | N/A | 8.8 HIGH |
| Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
