VulnSea

Firefox vulnerabilities

CVEs whose affected-version data names the Firefox package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

153 CVEsRSS

CVE-2026-12296Critical· 9.6
3mo ago

Sandbox escape in the Security: Process Sandboxing component

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Midnightmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-12295Critical· 9.6PoC
3mo ago

Sandbox escape in the DOM: Navigation component

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Abyssalmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-12294Critical· 9.6
3mo ago

Sandbox escape in the DOM: Workers component

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Midnightmozilla · firefoxEPSS 0.36%via NVD
CVE-2026-12292High· 8.1
3mo ago

Incorrect boundary conditions in the Web Audio component

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Twilightmozilla · firefoxEPSS 0.49%via NVD
CVE-2026-12291High· 8.8
3mo ago

Use-after-free in the Networking: HTTP component

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Twilightmozilla · firefoxEPSS 0.38%via NVD
CVE-2026-12290High· 8.1
3mo ago

Memory safety bug fixed in Firefox 152

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Twilightmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-12289High· 8.8
3mo ago

Privilege escalation in the Graphics: WebRender component

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Twilightmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-8706Medium· 6.5
4mo ago

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability …

Sunlitmozilla · firefoxEPSS 0.19%via NVD
CVE-2026-8975High· 8.8
4mo ago

Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150

Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary…

Twilightmozilla · firefoxEPSS 0.43%via NVD
CVE-2026-8974High· 8.8
4mo ago

Memory safety bugs present in Firefox ESR 140.10 and Firefox 150

Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerab…

Twilightmozilla · firefoxEPSS 0.33%via NVD
CVE-2026-8973High· 8.8
4mo ago

Memory safety bugs present in Firefox 150

Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Fire…

Twilightmozilla · firefoxEPSS 0.34%via NVD
CVE-2026-8972High· 8.8
4mo ago

Privilege escalation in the WebRTC: Audio/Video component

Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Twilightmozilla · firefoxEPSS 0.33%via NVD
CVE-2026-8971Medium· 6.5
4mo ago

Same-origin policy bypass in the Networking: JAR component

Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Sunlitmozilla · firefoxEPSS 0.21%via NVD
CVE-2026-8970High· 8.8
4mo ago

Privilege escalation in the Security component

Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Twilightmozilla · firefoxEPSS 0.31%via NVD
CVE-2026-8969High· 8.1
4mo ago

Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Twilightmozilla · firefoxEPSS 0.29%via NVD
CVE-2026-8968High· 7.5
4mo ago

Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component

Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Twilightmozilla · firefoxEPSS 0.41%via NVD
CVE-2026-8967High· 7.5
4mo ago

Information disclosure in the Graphics: WebGPU component

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Twilightmozilla · firefoxEPSS 0.33%via NVD
CVE-2026-8966High· 7.5
4mo ago

Information disclosure in the IP Protection component

Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Twilightmozilla · firefoxEPSS 0.33%via NVD
CVE-2026-8965High· 7.5
4mo ago

Information disclosure in the DOM: Security component

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Twilightmozilla · firefoxEPSS 0.32%via NVD
CVE-2026-8964High· 7.5
4mo ago

Spoofing issue in the Popup Blocker component

Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Twilightmozilla · firefoxEPSS 0.30%via NVD
CVE-2026-8963High· 7.5
4mo ago

Spoofing issue in the Web Speech component

Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Twilightmozilla · firefoxEPSS 0.30%via NVD
CVE-2026-8962High· 8.1
4mo ago

Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Twilightmozilla · firefoxEPSS 0.37%via NVD
CVE-2026-8961Medium· 6.5
4mo ago

Spoofing issue in the Form Autofill component

Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Sunlitmozilla · firefoxEPSS 0.32%via NVD
CVE-2026-8946High· 7.5
4mo ago

Incorrect boundary conditions in the Audio/Video: Web Codecs component

Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Twilightmozilla · firefoxEPSS 0.56%via NVD
CVE-2026-8094Critical· 9.8
4mo ago

Other issue in the WebRTC component

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

Midnightmozilla · firefoxEPSS 0.45%via NVD
CVE-2026-8092High· 8.1
4mo ago

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run a…

Twilightmozilla · firefoxEPSS 0.38%via NVD
CVE-2026-8090High· 7.3
4mo ago

Use-after-free in the DOM: Networking component

Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

Twilightmozilla · firefoxEPSS 0.32%via NVD
CVE-2026-8091Critical· 9.8
4mo ago

Incorrect boundary conditions in the Audio/Video: Playback component

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

Midnightmozilla · firefoxEPSS 0.47%via NVD
CVE-2026-2771Critical· 9.8
7mo ago

Undefined behavior in the DOM: Core & HTML component

Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

Midnightmozilla · firefoxEPSS 0.48%via NVD
CVE-2026-2447High· 8.8
7mo ago

Heap buffer overflow in libvpx

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.

Twilightmozilla · firefoxEPSS 0.62%via NVD
Firefox vulnerabilities (CVEs) — page 4 · VulnSea