Filtered by vendor Mozilla
Subscriptions
Total
3787 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16381 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.1 Critical |
| Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16358 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16377 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16375 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16374 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 7.5 High |
| Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16370 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.1 Critical |
| Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16357 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16356 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16355 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16369 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16368 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16354 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 7.5 High |
| Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16353 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16363 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16352 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16351 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16362 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 8.8 High |
| Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16350 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16349 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-07-22 | 9.8 Critical |
| Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-57962 | 1 Mozilla | 1 Thunderbird | 2026-07-21 | 5.3 Medium |
| A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1. | ||||