| Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 140.17, Thunderbird… CVE-2026-100832 | Severity high |
| Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100820 | Severity high |
| Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird… CVE-2026-100819 | Severity critical |
| firefox: thunderbird: Sandbox escape due to use-after-free in the Widget: Gtk component CVE-2026-100818 | Severity critical |
| Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird… CVE-2026-100816 | Severity high |
| firefox: Use-after-free in the CSS Parsing and Computation component CVE-2026-100815 | Severity high |
| Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157… CVE-2026-100814 | Severity high |
| Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. CVE-2026-100813 | Severity high |
| Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and… CVE-2026-100812 | Severity medium |
| firefox: firefox: Sandbox escape via use-after-free in DOM component CVE-2026-100811 | Severity critical |
| Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. CVE-2026-100810 | Severity critical |
| Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4… CVE-2026-100809 | Severity high |
| Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird… CVE-2026-100808 | Severity high |
| Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. CVE-2026-100787 | Severity critical |
| firefox: Sandbox escape due to use-after-free in the Graphics component CVE-2026-100786 | Severity critical |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100785 | Severity high |
| firefox: Use-after-free in the Layout: Text and Fonts component CVE-2026-100784 | Severity high |
| Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100783 | Severity medium |
| Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4… CVE-2026-100782 | Severity high |
| Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR… CVE-2026-100781 | Severity critical |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100780 | Severity high |
| Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird… CVE-2026-100779 | Severity high |
| firefox: Sandbox escape due to use-after-free in the DOM: Core & HTML component CVE-2026-100778 | Severity critical |
| Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-100777 | Severity high |
| Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17… CVE-2026-96869 | Severity medium |
| thunderbird: Out-of-bounds read in IMAP response parser CVE-2026-92240 | Severity critical |
| thunderbird: Thunderbird: Out-of-bounds read via maliciously constructed IMAP line CVE-2026-92239 | Severity high |
| thunderbird: Thunderbird: Memory safety violations via maliciously crafted mail headers CVE-2026-92238 | Severity critical |
| firefox: thunderbird: Mitigation bypass in the Widget: Win32 component CVE-2026-92079 | Severity critical |
| firefox: thunderbird: Denial-of-service in the Security component CVE-2026-92078 | Severity medium |
| firefox: thunderbird: Denial-of-service in the SVG component CVE-2026-92077 | Severity medium |
| firefox: thunderbird: Incorrect boundary conditions in the Networking component CVE-2026-92076 | Severity high |
| firefox: thunderbird: Mitigation bypass in the Networking component CVE-2026-92075 | Severity critical |
| firefox: thunderbird: Mitigation bypass in the Popup Blocker component CVE-2026-92074 | Severity high |
| firefox: thunderbird: Privilege escalation in the Enterprise Policies component CVE-2026-92073 | Severity high |
| firefox: thunderbird: Incorrect boundary conditions in the Safe Browsing component CVE-2026-92072 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92071 | Severity critical |
| firefox: thunderbird: Information disclosure in the Networking component CVE-2026-92070 | Severity medium |
| firefox: thunderbird: Spoofing issue in the DOM: Navigation component CVE-2026-92069 | Severity medium |
| firefox: Site isolation issue in the Reader Mode component CVE-2026-92068 | Severity medium |
| firefox: thunderbird: Use-after-free in the Widget: Gtk component CVE-2026-92067 | Severity high |
| firefox: thunderbird: Sandbox escape in the Profile Backup component CVE-2026-92066 | Severity critical |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92065 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92064 | Severity high |
| firefox: thunderbird: Denial-of-service in the Audio/Video component CVE-2026-92063 | Severity medium |
| firefox: thunderbird: Privilege escalation in the Session Restore component CVE-2026-92062 | Severity high |
| firefox: thunderbird: Incorrect boundary conditions in the Security: Process Sandboxing component CVE-2026-92061 | Severity critical |
| firefox: thunderbird: Use-after-free in the Internationalization component CVE-2026-92060 | Severity high |
| firefox: thunderbird: Incorrect boundary conditions in the DOM: Editor component CVE-2026-92059 | Severity critical |
| firefox: thunderbird: Use-after-free in the Graphics component CVE-2026-92058 | Severity high |
| firefox: thunderbird: Mitigation bypass in the Enterprise Policies component CVE-2026-92057 | Severity critical |
| firefox: thunderbird: Use-after-free in the Graphics: Text component CVE-2026-92056 | Severity high |
| firefox: thunderbird: Privilege escalation in the DevTools component CVE-2026-92055 | Severity high |
| firefox: thunderbird: Privilege escalation in the Memory component CVE-2026-92054 | Severity high |
| firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component CVE-2026-92053 | Severity high |
| firefox: thunderbird: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component CVE-2026-92052 | Severity high |
| Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. CVE-2026-92051 | Severity critical |
| firefox: thunderbird: Sandbox escape due to race condition in the XPConnect component CVE-2026-92050 | Severity critical |
| firefox: thunderbird: Use-after-free in the Widget: Win32 component CVE-2026-92049 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92048 | Severity critical |
| firefox: thunderbird: Privilege escalation in the Crash Reporting component CVE-2026-92047 | Severity high |
| firefox: thunderbird: Use-after-free in the Graphics component CVE-2026-92046 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the WebRTC component CVE-2026-92045 | Severity critical |
| firefox: thunderbird: Information disclosure in the Networking: HTTP component CVE-2026-92044 | Severity high |
| firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Audio/Video component CVE-2026-92043 | Severity high |
| firefox: thunderbird: Race condition in the DOM: Content Processes component CVE-2026-92042 | Severity high |
| firefox: thunderbird: Mitigation bypass in the DOM: Networking component CVE-2026-92041 | Severity critical |
| firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component CVE-2026-92040 | Severity high |
| firefox: thunderbird: Mitigation bypass in the DOM: Notifications component CVE-2026-92039 | Severity medium |
| firefox: thunderbird: Mitigation bypass in the Remote Settings Client component CVE-2026-92038 | Severity critical |
| firefox: thunderbird: Incorrect boundary conditions in the DOM: Animation component CVE-2026-92037 | Severity critical |
| firefox: thunderbird: Incorrect boundary conditions in the Networking: HTTP component CVE-2026-92036 | Severity critical |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics component CVE-2026-92035 | Severity critical |
| firefox: thunderbird: Site isolation issue in the Graphics component CVE-2026-92034 | Severity critical |
| firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component CVE-2026-92032 | Severity critical |
| firefox: thunderbird: Undefined behavior in the DOM: Core & HTML component CVE-2026-2771 | Severity critical |
| firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146 CVE-2025-14333 | Severity high |
| firefox: Memory safety bugs fixed in Firefox 146 and Thunderbird 146 CVE-2025-14332 | Severity high |
| firefox: thunderbird: Same-origin policy bypass in the Request Handling component CVE-2025-14331 | Severity medium |
| firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component CVE-2025-14330 | Severity critical |
| firefox: thunderbird: Privilege escalation in the Netmonitor component CVE-2025-14329 | Severity high |
| firefox: thunderbird: Privilege escalation in the Netmonitor component CVE-2025-14328 | Severity high |
| firefox: Spoofing issue in the Downloads Panel component CVE-2025-14327 | Severity high |
| firefox: Use-after-free in the Audio/Video: GMP component CVE-2025-14326 | Severity critical |
| firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component CVE-2025-14325 | Severity high |
| firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component CVE-2025-14324 | Severity critical |
| firefox: thunderbird: Privilege escalation in the DOM: Notifications component CVE-2025-14323 | Severity high |
| firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2025-14322 | Severity high |
| firefox: thunderbird: Use-after-free in the WebRTC: Signaling component CVE-2025-14321 | Severity critical |
| firefox: thunderbird: Memory safety bugs fixed in Firefox 142 and Thunderbird 142 CVE-2025-9187 | Severity critical |
| thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2… CVE-2025-9185 | Severity high |
| thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 CVE-2025-9184 | Severity high |
| firefox: thunderbird: Denial-of-service due to out-of-memory in the Graphics: WebRender component CVE-2025-9182 | Severity high |
| thunderbird: firefox: Uninitialized memory in the JavaScript Engine component CVE-2025-9181 | Severity medium |
| thunderbird: firefox: Same-origin policy bypass in the Graphics: Canvas2D component CVE-2025-9180 | Severity high |
| thunderbird: firefox: Sandbox escape due to invalid pointer in the Audio/Video: GMP component CVE-2025-9179 | Severity critical |
| firefox: thunderbird: Memory safety bugs fixed in Firefox 141 and Thunderbird 141 CVE-2025-8044 | Severity critical |
| firefox: thunderbird: Incorrect URL truncation CVE-2025-8043 | Severity critical |
| firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141 CVE-2025-8040 | Severity high |
| firefox: Search terms persisted in URL bar CVE-2025-8039 | Severity high |