Vulnerability index

Browse CVEs

259 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Firefox CRITICAL 10.0
CVE-2026-16367

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16356

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefo…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox HIGH 8.8
CVE-2026-16362

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbir…

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16351

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 1…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16352

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefo…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16353

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunder…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox MEDIUM 5.3
CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

Fix: 140.12.0+
Fix from $1,600 2026-06-16
Firefox HIGH 7.5
CVE-2026-12314

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0.0+
Fix from $1,950 2026-06-16
Firefox HIGH 7.5
CVE-2026-12310

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0.0+
Fix from $1,950 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12298

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0+
Fix from $1,600 2026-06-16
Firefox CRITICAL 9.8
CVE-2026-12293

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $2,300 2026-06-16
Firefox HIGH 8.8
CVE-2026-12291

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 15…

Fix: 115.37.0 / 140.12.0+
Fix from $1,950 2026-06-16
Firefox CRITICAL 9.6
CVE-2026-8953

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefo…

Fix: 115.36.0 / 140.11+
Fix from $2,300 2026-05-19
Firefox HIGH 7.3
CVE-2026-8947

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderb…

Fix: 115.36.0 / 140.11+
Fix from $1,950 2026-05-19
Firefox HIGH 7.3
CVE-2026-8390

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.

Fix: 150.0.3+
Fix from $1,950 2026-05-12
Firefox HIGH 8.1
CVE-2026-8092

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption…

Fix: 115.35.2 / 140.10.2+
Fix from $1,950 2026-05-07
Firefox HIGH 7.3
CVE-2026-8090

Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunder…

Fix: 115.35.2 / 140.10.2+
Fix from $1,950 2026-05-07
Firefox HIGH 7.3
CVE-2026-7322

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum…

Fix: 115.35.1 / 140.10.1+
Fix from $1,950 2026-04-28
Firefox HIGH 7.5
CVE-2026-6785

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showe…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-26
Firefox HIGH 7.5
CVE-2026-6786

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-26
Firefox HIGH 7.5
CVE-2026-6784

Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6754

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 1…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6758

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6759

Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6746

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 15…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6747

Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-21
Thin Vec MEDIUM 5.1
CVE-2026-6654

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skip…

No fix yet
Fix from $1,600 2026-04-20
Firefox CRITICAL 10.0
CVE-2026-4725

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4723

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4711

Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24