Vulnerability index

Browse CVEs

34 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Firefox HIGH 8.8
CVE-2026-16401

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16396

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16379

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and T…

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16371

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderb…

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16372

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16366

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-12289

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thund…

Fix: 115.37.0 / 140.12.0+
Fix from $1,950 2026-06-16
Firefox HIGH 8.8
CVE-2026-8970

Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140…

Fix: 140.11 / 140.11.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-8972

Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-8957

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thun…

Fix: 140.11 / 140.11.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-8952

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-8955

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird…

Fix: 140.11 / 140.11.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-6761

Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 1…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 8.8
CVE-2026-6769

Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 8.8
CVE-2026-6750

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thund…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-21
Firefox CRITICAL 9.8
CVE-2026-2777

Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbi…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2780

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2782

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Vpn HIGH 7.8
CVE-2025-5687

A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other op…

Fix: 2.28.0+
Fix from $1,950 2025-06-11
Firefox HIGH 7.1
CVE-2025-4085

An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate priv…

Fix: 138.0+
Fix from $1,950 2025-04-29
Firefox HIGH 8.8
CVE-2024-0751

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde…

Fix: 115.7 / 122.0+
Fix from $1,950 2024-01-23
Firefox HIGH 8.8
CVE-2021-23999

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges t…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Firefox MEDIUM 6.5
CVE-2021-29951

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start …

Fix: 78.10.1 / 87.0+
Fix from $1,600 2021-06-24
Firefox MEDIUM 5.5
CVE-2017-7767

The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater,…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7782

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. No…

Fix: 52.3.0 / 55.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-5409

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parame…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Firefox HIGH 8.8
CVE-2014-1529

The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remo…

Fix: 24.5 / 29.0+
Fix from $1,950 2014-04-30
Firefox MEDIUM 6.9
CVE-2014-1520

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows l…

Fix: 24.5 / 29.0+
Fix from $1,600 2014-04-30
Firefox MEDIUM 6.8
CVE-2014-1526

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended acce…

Fix: 2.26 / 29.0+
Fix from $1,600 2014-04-30