Vulnerabilities (CVE)

Filtered by vendor Mozilla Subscribe
Total 3663 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-6758 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 7.5 HIGH
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6757 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 6.3 MEDIUM
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVE-2026-6756 1 Mozilla 1 Firefox 2026-06-17 N/A 7.5 HIGH
Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
CVE-2026-6755 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 6.5 MEDIUM
Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-4728 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 6.5 MEDIUM
Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
CVE-2026-4727 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 7.5 HIGH
Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
CVE-2026-4726 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 7.5 HIGH
Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
CVE-2026-4725 1 Mozilla 1 Firefox 2026-06-17 N/A 10.0 CRITICAL
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
CVE-2026-4724 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 9.1 CRITICAL
Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
CVE-2026-4723 1 Mozilla 1 Firefox 2026-06-17 N/A 9.8 CRITICAL
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
CVE-2026-4722 1 Mozilla 1 Firefox 2026-06-17 N/A 8.8 HIGH
Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
CVE-2026-4719 1 Mozilla 1 Firefox 2026-06-17 N/A 7.5 HIGH
Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4718 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 8.1 HIGH
Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4717 1 Mozilla 1 Firefox 2026-06-17 N/A 9.8 CRITICAL
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4716 1 Mozilla 1 Firefox 2026-06-17 N/A 9.1 CRITICAL
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4715 1 Mozilla 1 Firefox 2026-06-17 N/A 9.1 CRITICAL
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4714 1 Mozilla 1 Firefox 2026-06-17 N/A 7.5 HIGH
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4713 1 Mozilla 1 Firefox 2026-06-17 N/A 7.5 HIGH
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4712 1 Mozilla 1 Firefox 2026-06-17 N/A 7.5 HIGH
Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
CVE-2026-4711 1 Mozilla 1 Firefox 2026-06-17 N/A 9.8 CRITICAL
Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.