mozilla
3,564 tracked vulnerabilities.
CVE-2026-8706
MEDIUM
Sensitive user data could be leaked to other applications through Reader mode
May 19, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-8975
HIGH
Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8974
HIGH
Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8973
HIGH
Firefox and Thunderbird < 151 - Memory Corruption
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8972
HIGH
Privilege escalation in the WebRTC: Audio/Video component
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8971
MEDIUM
Same-origin policy bypass in the Networking: JAR component
May 19, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-8970
HIGH
Firefox < 140.11 and 140.11-150.0 - Privilege Escalation
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8969
HIGH
Mitigation bypass in the DOM: Security component
May 19, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-8968
HIGH
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8967
HIGH
Information disclosure in the Graphics: WebGPU component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8966
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Information Disclosure in IP Protection Component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8965
HIGH
Information disclosure in the DOM: Security component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8964
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Spoofing via Popup Blocker
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8963
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing in Web Speech Component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8962
HIGH
Mitigation bypass in the DOM: Security component
May 19, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-8961
MEDIUM
Firefox and Thunderbird < 140.11 and >=151 - Authentication Bypass by Spoofing in Form Autofill
May 19, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-8960
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing via WebExtensions
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8959
CRITICAL
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
May 19, 2026
CVSS 9.6
EPSS 0.00
CVE-2026-8958
HIGH
Information disclosure, sandbox escape in the Security: Process Sandboxing component
May 19, 2026
CVSS 8.6
EPSS 0.00
CVE-2026-8957
HIGH
Firefox < 140.11 and 140.11-140.* and >=151 - Privilege Escalation in Enterprise Policies
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8956
CRITICAL
Integer overflow in the Networking: JAR component
May 19, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-8955
HIGH
Privilege escalation in the DOM: Workers component
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8954
HIGH
Incorrect boundary conditions, integer overflow in the Audio/Video component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8953
CRITICAL
Sandbox escape due to use-after-free in the Disability Access APIs component
May 19, 2026
CVSS 9.6
EPSS 0.00
CVE-2026-8952
HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Privilege Escalation in Application Update Component
May 19, 2026
CVSS 8.8
EPSS 0.00
Products
firefox 3,130
thunderbird 1,729
seamonkey 704
firefox_esr 488
Firefox 387
Thunderbird 359
thunderbird_esr 228
bugzilla 145
mozilla 108
network_security_services 50
Firefox ESR 44
mozilla_suite 27
firefox_focus 20
firefox_mobile 20
Firefox for iOS 18
focus 15
firefox_os 14
nss 6
Focus for iOS 5
bleach 5
bonsai 4
camino 4
vpn 4
convict 3
netscape_portable_runtime 3
geckodriver 2
mozjpeg 2
nunjucks 2
pollbot 2
webthings_gateway 2
Quick Filters