Vulnerability index

Browse CVEs

34 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2026-16401 Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-16396 Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. Firefox 140.13.0 / 153.0+ Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-16379 Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and T… Firefox 140.13.0 / 153.0+ Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-16371 Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderb… Firefox 140.13.0 / 153.0+ Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-16372 Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-16365 Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-16366 Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-12289 Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thund… Firefox 115.37.0 / 140.12.0+ Fix from $1,9502026-06-16 HIGH 8.8 CVE-2026-8970 Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140… Firefox 140.11 / 140.11.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-8972 Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-8957 Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thun… Firefox 140.11 / 140.11.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-8952 Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-8955 Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird… Firefox 140.11 / 140.11.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-6761 Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 1… Firefox 140.10.0 / 150.0+ Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-6769 Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140… Firefox 140.10.0 / 150.0+ Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-6750 Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thund… Firefox 115.35.0 / 140.10.0+ Fix from $1,9502026-04-21 CRITICAL 9.8 CVE-2026-2777 Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbi… Firefox 115.33.0 / 140.8.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2780 Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14… Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2782 Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14… Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 HIGH 7.8 CVE-2025-5687 A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other op… Vpn 2.28.0+ Fix from $1,9502025-06-11 HIGH 7.1 CVE-2025-4085 An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate priv… Firefox 138.0+ Fix from $1,9502025-04-29 HIGH 8.8 CVE-2024-0751 A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde… Firefox 115.7 / 122.0+ Fix from $1,9502024-01-23 HIGH 8.8 CVE-2021-23999 If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges t… Firefox 78.10 / 88.0+ Fix from $1,9502021-06-24 MEDIUM 6.5 CVE-2021-29951 The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start … Firefox 78.10.1 / 87.0+ Fix from $1,6002021-06-24 MEDIUM 5.5 CVE-2017-7767 The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater,… Firefox 52.2.0 / 54.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7782 An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. No… Firefox 52.3.0 / 55.0+ Fix from $1,6002018-06-11 MEDIUM 5.5 CVE-2017-5409 The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parame… Firefox 45.8.0 / 52.0+ Fix from $1,6002018-06-11 HIGH 8.8 CVE-2014-1529 The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remo… Firefox 24.5 / 29.0+ Fix from $1,9502014-04-30 MEDIUM 6.9 CVE-2014-1520 maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows l… Firefox 24.5 / 29.0+ Fix from $1,6002014-04-30 MEDIUM 6.8 CVE-2014-1526 The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended acce… Firefox 2.26 / 29.0+ Fix from $1,6002014-04-30