Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-16387 Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1… Firefox 140.13.0 / 153.0+ Fix from $2,3002026-07-21 HIGH 8.8 CVE-2026-16365 Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 CRITICAL 10.0 CVE-2026-2768 Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird … Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 CRITICAL 10.0 CVE-2026-0881 Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. Firefox 147.0+ Fix from $2,3002026-01-13 MEDIUM 6.5 CVE-2025-11716 Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 1… Firefox 144.0+ Fix from $1,6002025-10-14 CRITICAL 9.1 CVE-2025-1941 Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE… Firefox 136.0+ Fix from $2,3002025-03-04 HIGH 8.1 CVE-2024-7525 It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of r… Firefox 115.14.0 / 129.0+ Fix from $1,9502024-08-06 MEDIUM 5.3 CVE-2024-5687 If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. … Firefox 127.0+ Fix from $1,6002024-06-11 HIGH 8.8 CVE-2016-5283 Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFR… Firefox after 48.0.2 Fix from $1,9502016-09-22 HIGH 8.8 CVE-2016-5273 The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote atta… Firefox after 48.0.2 Fix from $1,9502016-09-22 MEDIUM 6.5 CVE-2016-2816 Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replac… Firefox after 45.0.2 Fix from $1,6002016-04-30 MEDIUM 6.8 CVE-2015-7184 The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user cre… Firefox after 41.0.1 Fix from $1,6002015-10-18 MEDIUM 6.8 CVE-2014-1589 Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypas… Firefox after 33.0 Fix from $1,6002014-12-11