| Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 140.17, Thunderbird… CVE-2026-100832 | Severity high |
| Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100820 | Severity high |
| Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird… CVE-2026-100819 | Severity critical |
| firefox: thunderbird: Sandbox escape due to use-after-free in the Widget: Gtk component CVE-2026-100818 | Severity critical |
| Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird… CVE-2026-100816 | Severity high |
| firefox: Use-after-free in the CSS Parsing and Computation component CVE-2026-100815 | Severity high |
| Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157… CVE-2026-100814 | Severity high |
| Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. CVE-2026-100813 | Severity high |
| Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and… CVE-2026-100812 | Severity medium |
| firefox: firefox: Sandbox escape via use-after-free in DOM component CVE-2026-100811 | Severity critical |
| Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. CVE-2026-100810 | Severity critical |
| Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4… CVE-2026-100809 | Severity high |
| Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird… CVE-2026-100808 | Severity high |
| Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. CVE-2026-100787 | Severity critical |
| firefox: Sandbox escape due to use-after-free in the Graphics component CVE-2026-100786 | Severity critical |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100785 | Severity high |
| firefox: Use-after-free in the Layout: Text and Fonts component CVE-2026-100784 | Severity high |
| Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100783 | Severity medium |
| Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4… CVE-2026-100782 | Severity high |
| Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR… CVE-2026-100781 | Severity critical |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100780 | Severity high |
| Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird… CVE-2026-100779 | Severity high |
| firefox: Sandbox escape due to use-after-free in the DOM: Core & HTML component CVE-2026-100778 | Severity critical |
| Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100777 | Severity high |
| Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-96869 | Severity medium |
| firefox: thunderbird: Mitigation bypass in the Widget: Win32 component CVE-2026-92079 | Severity critical |
| firefox: thunderbird: Denial-of-service in the Security component CVE-2026-92078 | Severity medium |
| firefox: thunderbird: Denial-of-service in the SVG component CVE-2026-92077 | Severity medium |
| firefox: thunderbird: Incorrect boundary conditions in the Networking component CVE-2026-92076 | Severity high |
| firefox: thunderbird: Mitigation bypass in the Networking component CVE-2026-92075 | Severity critical |
| firefox: thunderbird: Mitigation bypass in the Popup Blocker component CVE-2026-92074 | Severity high |
| firefox: thunderbird: Privilege escalation in the Enterprise Policies component CVE-2026-92073 | Severity high |
| firefox: thunderbird: Incorrect boundary conditions in the Safe Browsing component CVE-2026-92072 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92071 | Severity critical |
| firefox: thunderbird: Information disclosure in the Networking component CVE-2026-92070 | Severity medium |
| firefox: thunderbird: Spoofing issue in the DOM: Navigation component CVE-2026-92069 | Severity medium |
| firefox: Site isolation issue in the Reader Mode component CVE-2026-92068 | Severity medium |
| firefox: thunderbird: Use-after-free in the Widget: Gtk component CVE-2026-92067 | Severity high |
| firefox: thunderbird: Sandbox escape in the Profile Backup component CVE-2026-92066 | Severity critical |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92065 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92064 | Severity high |
| firefox: thunderbird: Denial-of-service in the Audio/Video component CVE-2026-92063 | Severity medium |
| firefox: thunderbird: Privilege escalation in the Session Restore component CVE-2026-92062 | Severity high |
| firefox: thunderbird: Incorrect boundary conditions in the Security: Process Sandboxing component CVE-2026-92061 | Severity critical |
| firefox: thunderbird: Use-after-free in the Internationalization component CVE-2026-92060 | Severity high |
| firefox: thunderbird: Incorrect boundary conditions in the DOM: Editor component CVE-2026-92059 | Severity critical |
| firefox: thunderbird: Use-after-free in the Graphics component CVE-2026-92058 | Severity high |
| firefox: thunderbird: Mitigation bypass in the Enterprise Policies component CVE-2026-92057 | Severity critical |
| firefox: thunderbird: Use-after-free in the Graphics: Text component CVE-2026-92056 | Severity high |
| firefox: thunderbird: Privilege escalation in the DevTools component CVE-2026-92055 | Severity high |
| firefox: thunderbird: Privilege escalation in the Memory component CVE-2026-92054 | Severity high |
| firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component CVE-2026-92053 | Severity high |
| firefox: thunderbird: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component CVE-2026-92052 | Severity high |
| Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. CVE-2026-92051 | Severity critical |
| firefox: thunderbird: Sandbox escape due to race condition in the XPConnect component CVE-2026-92050 | Severity critical |
| firefox: thunderbird: Use-after-free in the Widget: Win32 component CVE-2026-92049 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92048 | Severity critical |
| firefox: thunderbird: Privilege escalation in the Crash Reporting component CVE-2026-92047 | Severity high |
| firefox: thunderbird: Use-after-free in the Graphics component CVE-2026-92046 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the WebRTC component CVE-2026-92045 | Severity critical |
| firefox: thunderbird: Information disclosure in the Networking: HTTP component CVE-2026-92044 | Severity high |
| firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Audio/Video component CVE-2026-92043 | Severity high |
| firefox: thunderbird: Race condition in the DOM: Content Processes component CVE-2026-92042 | Severity high |
| firefox: thunderbird: Mitigation bypass in the DOM: Networking component CVE-2026-92041 | Severity critical |
| firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component CVE-2026-92040 | Severity high |
| firefox: thunderbird: Mitigation bypass in the DOM: Notifications component CVE-2026-92039 | Severity medium |
| firefox: thunderbird: Mitigation bypass in the Remote Settings Client component CVE-2026-92038 | Severity critical |
| firefox: thunderbird: Incorrect boundary conditions in the DOM: Animation component CVE-2026-92037 | Severity critical |
| firefox: thunderbird: Incorrect boundary conditions in the Networking: HTTP component CVE-2026-92036 | Severity critical |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics component CVE-2026-92035 | Severity critical |
| firefox: thunderbird: Site isolation issue in the Graphics component CVE-2026-92034 | Severity critical |
| firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component CVE-2026-92032 | Severity critical |
| firefox: thunderbird: Undefined behavior in the DOM: Core & HTML component CVE-2026-2771 | Severity critical |
| Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within… CVE-2025-55031 | Severity critical |
| Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather… CVE-2025-55030 | Severity medium |
| Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability… CVE-2025-55029 | Severity high |
| Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of… CVE-2025-55028 | Severity medium |
| The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's… CVE-2025-54145 | Severity critical |
| The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or… CVE-2025-54144 | Severity medium |
| Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the… CVE-2025-54143 | Severity critical |
| An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4. CVE-2025-49710 | Severity critical |
| Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4. CVE-2025-49709 | Severity critical |
| Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a… CVE-2025-27425 | Severity medium |
| Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was… CVE-2025-27424 | Severity medium |
| Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was… CVE-2025-23109 | Severity medium |
| Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the… CVE-2025-23108 | Severity medium |
| Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort… CVE-2025-14861 | Severity high |
| Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. CVE-2025-14860 | Severity critical |
| Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking… CVE-2025-14744 | Severity medium |
| firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146 CVE-2025-14333 | Severity high |
| firefox: Memory safety bugs fixed in Firefox 146 and Thunderbird 146 CVE-2025-14332 | Severity high |
| firefox: thunderbird: Same-origin policy bypass in the Request Handling component CVE-2025-14331 | Severity medium |
| firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component CVE-2025-14330 | Severity critical |
| firefox: thunderbird: Privilege escalation in the Netmonitor component CVE-2025-14329 | Severity high |
| firefox: thunderbird: Privilege escalation in the Netmonitor component CVE-2025-14328 | Severity high |
| firefox: Spoofing issue in the Downloads Panel component CVE-2025-14327 | Severity high |
| firefox: Use-after-free in the Audio/Video: GMP component CVE-2025-14326 | Severity critical |
| firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component CVE-2025-14325 | Severity high |
| firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component CVE-2025-14324 | Severity critical |
| firefox: thunderbird: Privilege escalation in the DOM: Notifications component CVE-2025-14323 | Severity high |