Total
3337 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-16353 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16352 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16351 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16350 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16349 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16359 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.1 CRITICAL |
| Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16362 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 8.8 HIGH |
| Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16358 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16357 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16356 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16355 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16363 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16369 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16374 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 7.5 HIGH |
| Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16377 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16381 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.1 CRITICAL |
| Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16383 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16387 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.8 CRITICAL |
| Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16390 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 9.1 CRITICAL |
| Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
| CVE-2026-16391 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-24 | N/A | 7.5 HIGH |
| Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |||||
