Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-2761 Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird … Firefox 115.33.0 / 140.8.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2758 Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, … Firefox 115.33.0 / 140.8.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2759 Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8… Firefox 115.33.0 / 140.8.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2762 Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and … Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2763 Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 14… Firefox 115.33.0 / 140.8.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2764 JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox … Firefox 115.33.0 / 140.8.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2765 Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 1… Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2766 Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderb… Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2634 Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attack… Firefox 147.4+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2757 Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.… Firefox 115.33.0 / 140.8.0+ Fix from $2,3002026-02-24 HIGH 8.8 CVE-2026-2447 Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and … Firefox 115.32.1 / 140.7.1+ Fix from $1,9502026-02-16 HIGH 8.8 CVE-2026-24869 Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2. Firefox 147.0.2+ Fix from $1,9502026-01-27 MEDIUM 6.5 CVE-2026-24868 Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2. Firefox 147.0.2+ Fix from $1,6002026-01-27 CRITICAL 9.8 CVE-2026-0892 Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 147.0+ Fix from $2,3002026-01-13 HIGH 8.1 CVE-2026-0891 Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory… Firefox 140.7.0 / 147.0+ Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-0889 Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. Firefox 147.0+ Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2026-0885 Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.… Firefox 140.7.0 / 147.0+ Fix from $1,6002026-01-13 MEDIUM 5.4 CVE-2026-0890 Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, a… Firefox 140.7.0 / 147.0+ Fix from $1,6002026-01-13 MEDIUM 5.3 CVE-2026-0886 Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderb… Firefox 115.32.0 / 140.7.0+ Fix from $1,6002026-01-13 MEDIUM 5.3 CVE-2026-0888 Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. Firefox 147.0+ Fix from $1,6002026-01-13 CRITICAL 10.0 CVE-2026-0881 Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. Firefox 147.0+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-0879 Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firef… Firefox 115.32.0 / 140.7.0+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-0884 Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 1… Firefox 140.7.0 / 147.0+ Fix from $2,3002026-01-13 HIGH 8.8 CVE-2026-0880 Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7,… Firefox 115.32.0 / 140.7.0+ Fix from $1,9502026-01-13 HIGH 8.8 CVE-2026-0882 Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunder… Firefox 115.32.0 / 140.7.0+ Fix from $1,9502026-01-13 HIGH 8.1 CVE-2026-0877 Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147… Firefox 115.32.0 / 140.7.0+ Fix from $1,9502026-01-13 HIGH 8.0 CVE-2026-0878 Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR … Firefox 140.7.0 / 147.0+ Fix from $1,9502026-01-13 MEDIUM 5.3 CVE-2026-0883 Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird … Firefox 140.7.0 / 147.0+ Fix from $1,6002026-01-13 CRITICAL 9.8 CVE-2025-14860 Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. Firefox 146.0.1+ Fix from $2,3002025-12-18 HIGH 8.8 CVE-2025-14861 Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 146.0.1+ Fix from $1,9502025-12-18