Filtered by vendor Mozilla
Subscribe
Total
3821 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-74952 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-01 | N/A | 8.8 HIGH |
| Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2. | |||||
| CVE-2026-74949 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-01 | N/A | 8.8 HIGH |
| Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-16371 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-01 | N/A | 8.8 HIGH |
| Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, Thunderbird 140.13, Firefox ESR 140.15, and Thunderbird 140.15. | |||||
| CVE-2026-16365 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-01 | N/A | 8.8 HIGH |
| Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird 140.15. | |||||
| CVE-2026-74986 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 9.1 CRITICAL |
| Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74981 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 8.1 HIGH |
| Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74984 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 6.8 MEDIUM |
| Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74982 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 7.5 HIGH |
| Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74966 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 7.5 HIGH |
| Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74978 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 8.1 HIGH |
| Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74980 | 1 Mozilla | 1 Firefox Mobile | 2026-08-25 | N/A | 6.5 MEDIUM |
| Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |||||
| CVE-2026-74975 | 1 Mozilla | 1 Firefox Mobile | 2026-08-25 | N/A | 5.4 MEDIUM |
| Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |||||
| CVE-2026-74985 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 9.8 CRITICAL |
| Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74970 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 5.4 MEDIUM |
| Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74977 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-25 | N/A | 7.5 HIGH |
| Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |||||
| CVE-2026-74934 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 7.5 HIGH |
| Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74945 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 6.5 MEDIUM |
| Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74948 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 6.5 MEDIUM |
| Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74957 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 8.1 HIGH |
| Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
| CVE-2026-74959 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-24 | N/A | 9.1 CRITICAL |
| Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |||||
