mozilla

3,564 tracked vulnerabilities.

CVE-2026-8706 MEDIUM
Sensitive user data could be leaked to other applications through Reader mode
May 19, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-8975 HIGH
Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8974 HIGH
Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8973 HIGH
Firefox and Thunderbird < 151 - Memory Corruption
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8972 HIGH
Privilege escalation in the WebRTC: Audio/Video component
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8971 MEDIUM
Same-origin policy bypass in the Networking: JAR component
May 19, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-8970 HIGH
Firefox < 140.11 and 140.11-150.0 - Privilege Escalation
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8969 HIGH
Mitigation bypass in the DOM: Security component
May 19, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-8968 HIGH
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8967 HIGH
Information disclosure in the Graphics: WebGPU component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8966 HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Information Disclosure in IP Protection Component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8965 HIGH
Information disclosure in the DOM: Security component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8964 HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Spoofing via Popup Blocker
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8963 HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing in Web Speech Component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8962 HIGH
Mitigation bypass in the DOM: Security component
May 19, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-8961 MEDIUM
Firefox and Thunderbird < 140.11 and >=151 - Authentication Bypass by Spoofing in Form Autofill
May 19, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-8960 HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Authentication Bypass by Spoofing via WebExtensions
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8959 CRITICAL
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
May 19, 2026
CVSS 9.6
EPSS 0.00
CVE-2026-8958 HIGH
Information disclosure, sandbox escape in the Security: Process Sandboxing component
May 19, 2026
CVSS 8.6
EPSS 0.00
CVE-2026-8957 HIGH
Firefox < 140.11 and 140.11-140.* and >=151 - Privilege Escalation in Enterprise Policies
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8956 CRITICAL
Integer overflow in the Networking: JAR component
May 19, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-8955 HIGH
Privilege escalation in the DOM: Workers component
May 19, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-8954 HIGH
Incorrect boundary conditions, integer overflow in the Audio/Video component
May 19, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-8953 CRITICAL
Sandbox escape due to use-after-free in the Disability Access APIs component
May 19, 2026
CVSS 9.6
EPSS 0.00
CVE-2026-8952 HIGH
Firefox < 151.0.0 and Thunderbird < 151.0.0 - Privilege Escalation in Application Update Component
May 19, 2026
CVSS 8.8
EPSS 0.00