vendor

mozilla

227 thingsrelated by NVD

Its products

firefox 221 thunderbird 168 firefox mobile 3 firefox focus 1

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 140.17, Thunderbird…
CVE-2026-100832
Severity high
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
CVE-2026-100823
Severity medium
Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17…
CVE-2026-100820
Severity high
Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird…
CVE-2026-100819
Severity critical
firefox: thunderbird: Sandbox escape due to use-after-free in the Widget: Gtk component
CVE-2026-100818
Severity critical
Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
CVE-2026-100816
Severity high
firefox: Use-after-free in the CSS Parsing and Computation component
CVE-2026-100815
Severity high
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157…
CVE-2026-100814
Severity high
Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100813
Severity high
Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and…
CVE-2026-100812
Severity medium
firefox: firefox: Sandbox escape via use-after-free in DOM component
CVE-2026-100811
Severity critical
Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100810
Severity critical
Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4…
CVE-2026-100809
Severity high
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird…
CVE-2026-100808
Severity high
Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100787
Severity critical
firefox: Sandbox escape due to use-after-free in the Graphics component
CVE-2026-100786
Severity critical
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17…
CVE-2026-100785
Severity high
firefox: Use-after-free in the Layout: Text and Fonts component
CVE-2026-100784
Severity high
Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17…
CVE-2026-100783
Severity medium
Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4…
CVE-2026-100782
Severity high
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR…
CVE-2026-100781
Severity critical
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17…
CVE-2026-100780
Severity high
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird…
CVE-2026-100779
Severity high
firefox: Sandbox escape due to use-after-free in the DOM: Core & HTML component
CVE-2026-100778
Severity critical
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17…
CVE-2026-100777
Severity high
Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17…
CVE-2026-96869
Severity medium
thunderbird: Out-of-bounds read in IMAP response parser
CVE-2026-92240
Severity critical
thunderbird: Thunderbird: Out-of-bounds read via maliciously constructed IMAP line
CVE-2026-92239
Severity high
thunderbird: Thunderbird: Memory safety violations via maliciously crafted mail headers
CVE-2026-92238
Severity critical
firefox: thunderbird: Mitigation bypass in the Widget: Win32 component
CVE-2026-92079
Severity critical
firefox: thunderbird: Denial-of-service in the Security component
CVE-2026-92078
Severity medium
firefox: thunderbird: Denial-of-service in the SVG component
CVE-2026-92077
Severity medium
firefox: thunderbird: Incorrect boundary conditions in the Networking component
CVE-2026-92076
Severity high
firefox: thunderbird: Mitigation bypass in the Networking component
CVE-2026-92075
Severity critical
firefox: thunderbird: Mitigation bypass in the Popup Blocker component
CVE-2026-92074
Severity high
firefox: thunderbird: Privilege escalation in the Enterprise Policies component
CVE-2026-92073
Severity high
firefox: thunderbird: Incorrect boundary conditions in the Safe Browsing component
CVE-2026-92072
Severity high
firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92071
Severity critical
firefox: thunderbird: Information disclosure in the Networking component
CVE-2026-92070
Severity medium
firefox: thunderbird: Spoofing issue in the DOM: Navigation component
CVE-2026-92069
Severity medium
firefox: Site isolation issue in the Reader Mode component
CVE-2026-92068
Severity medium
firefox: thunderbird: Use-after-free in the Widget: Gtk component
CVE-2026-92067
Severity high
firefox: thunderbird: Sandbox escape in the Profile Backup component
CVE-2026-92066
Severity critical
firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92065
Severity high
firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92064
Severity high
firefox: thunderbird: Denial-of-service in the Audio/Video component
CVE-2026-92063
Severity medium
firefox: thunderbird: Privilege escalation in the Session Restore component
CVE-2026-92062
Severity high
firefox: thunderbird: Incorrect boundary conditions in the Security: Process Sandboxing component
CVE-2026-92061
Severity critical
firefox: thunderbird: Use-after-free in the Internationalization component
CVE-2026-92060
Severity high
firefox: thunderbird: Incorrect boundary conditions in the DOM: Editor component
CVE-2026-92059
Severity critical
firefox: thunderbird: Use-after-free in the Graphics component
CVE-2026-92058
Severity high
firefox: thunderbird: Mitigation bypass in the Enterprise Policies component
CVE-2026-92057
Severity critical
firefox: thunderbird: Use-after-free in the Graphics: Text component
CVE-2026-92056
Severity high
firefox: thunderbird: Privilege escalation in the DevTools component
CVE-2026-92055
Severity high
firefox: thunderbird: Privilege escalation in the Memory component
CVE-2026-92054
Severity high
firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component
CVE-2026-92053
Severity high
firefox: thunderbird: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component
CVE-2026-92052
Severity high
Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92051
Severity critical
firefox: thunderbird: Sandbox escape due to race condition in the XPConnect component
CVE-2026-92050
Severity critical
firefox: thunderbird: Use-after-free in the Widget: Win32 component
CVE-2026-92049
Severity high
firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92048
Severity critical
firefox: thunderbird: Privilege escalation in the Crash Reporting component
CVE-2026-92047
Severity high
firefox: thunderbird: Use-after-free in the Graphics component
CVE-2026-92046
Severity high
firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the WebRTC component
CVE-2026-92045
Severity critical
firefox: thunderbird: Information disclosure in the Networking: HTTP component
CVE-2026-92044
Severity high
firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Audio/Video component
CVE-2026-92043
Severity high
firefox: thunderbird: Race condition in the DOM: Content Processes component
CVE-2026-92042
Severity high
firefox: thunderbird: Mitigation bypass in the DOM: Networking component
CVE-2026-92041
Severity critical
firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-92040
Severity high
firefox: thunderbird: Mitigation bypass in the DOM: Notifications component
CVE-2026-92039
Severity medium
firefox: thunderbird: Mitigation bypass in the Remote Settings Client component
CVE-2026-92038
Severity critical
firefox: thunderbird: Incorrect boundary conditions in the DOM: Animation component
CVE-2026-92037
Severity critical
firefox: thunderbird: Incorrect boundary conditions in the Networking: HTTP component
CVE-2026-92036
Severity critical
firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics component
CVE-2026-92035
Severity critical
firefox: thunderbird: Site isolation issue in the Graphics component
CVE-2026-92034
Severity critical
firefox: Privilege escalation in Firefox for Android
CVE-2026-92033
Severity high
firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component
CVE-2026-92032
Severity critical
A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make…
CVE-2026-86853
Severity medium
firefox: thunderbird: Undefined behavior in the DOM: Core & HTML component
CVE-2026-2771
Severity critical
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within…
CVE-2025-55031
Severity critical
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather…
CVE-2025-55030
Severity medium
Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability…
CVE-2025-55029
Severity high
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of…
CVE-2025-55028
Severity medium
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's…
CVE-2025-54145
Severity critical
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or…
CVE-2025-54144
Severity medium
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the…
CVE-2025-54143
Severity critical
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.
CVE-2025-49710
Severity critical
Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
CVE-2025-49709
Severity critical
Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a…
CVE-2025-27425
Severity medium
Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was…
CVE-2025-27424
Severity medium
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was…
CVE-2025-23109
Severity medium
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the…
CVE-2025-23108
Severity medium
Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2025-14861
Severity high
Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.
CVE-2025-14860
Severity critical
Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking…
CVE-2025-14744
Severity medium
firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
CVE-2025-14333
Severity high
firefox: Memory safety bugs fixed in Firefox 146 and Thunderbird 146
CVE-2025-14332
Severity high
firefox: thunderbird: Same-origin policy bypass in the Request Handling component
CVE-2025-14331
Severity medium
firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component
CVE-2025-14330
Severity critical
firefox: thunderbird: Privilege escalation in the Netmonitor component
CVE-2025-14329
Severity high

← Previous 1 of 3 Next →