mozilla

3,564 tracked vulnerabilities.

CVE-2026-2778 CRITICAL
Firefox < 115.33.0, 140.8-140.*, >=148 - Sandbox Escape via DOM Core & HTML Boundary Condition Mismanagement
Feb 24, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-2777 CRITICAL
Firefox <148 - Privilege Escalation
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2776 CRITICAL
Firefox < 115.33.0 and 140.8-148.0 - Sandbox Escape via Telemetry Boundary Condition Flaw
Feb 24, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-2775 CRITICAL
Firefox <115.33.0, 115.33-115.*, <148.0, >=148; Thunderbird <140.8.0, 140.8-140.*, >=148 - Authentication Bypass
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2774 CRITICAL
Firefox and Thunderbird - Integer Overflow in Audio/Video Component
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2773 CRITICAL
Firefox <115.33.0, 115.33-115.*, <148.0, >=148; Thunderbird <140.8.0, 140.8-140.*, >=148 - Memory Corruption
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2772 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Use-After-Free in Audio/Video Playback
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2771 CRITICAL
Firefox <115.33.0, 140.8-140.*, <148.0, >=148; Thunderbird <140.8.0, <148.0, >=148 - Out-of-bounds Read
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2770 CRITICAL
Firefox <115.33.0, 115.33-115.*, <148.0, >=148; Thunderbird <140.8.0, 140.8-140.*, >=148 Use-After-Free
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2769 HIGH
Firefox < 115.33.0, 140.8-140.*, >=148 - Use-After-Free in IndexedDB
Feb 24, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-2768 CRITICAL
Firefox < 148 and Firefox ESR < 140.8 - Sandbox Escape via IndexedDB Storage
Feb 24, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-2767 CRITICAL
Firefox < 148.0 and Firefox ESR < 140.8.0 - Use-After-Free in JavaScript WebAssembly Component
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2766 CRITICAL
Firefox < 148 and Firefox ESR < 140.8 - Use-After-Free in JavaScript Engine JIT
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2765 CRITICAL
Firefox < 148.0 and < 140.8.0 - Use-After-Free in JavaScript Engine
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2764 CRITICAL
Firefox <148 - Use After Free
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2763 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Use-After-Free in JavaScript Engine
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2762 CRITICAL
Firefox < 148.0 and < 140.8.0 - Integer Overflow in JavaScript Standard Library
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2761 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Sandbox Escape in WebRender Component
Feb 24, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-2760 CRITICAL
Firefox <115.33.0, 115.33-115.*, <148.0, >=148; Thunderbird <140.8.0, >=140.8 <140.*, >=148 Sandbox Escape via WebRender
Feb 24, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-2759 CRITICAL
Firefox < 115.33.0, 140.8-140.*, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Denial of Service in ImageLib
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2758 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Use-After-Free in JavaScript GC
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2757 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - WebRTC Audio/Video Boundary Error
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2634 CRITICAL
Firefox for iOS < 147.4 - Address Bar Spoofing via Desynchronization
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-2447 HIGH
Firefox < 115.32.1, 140.7.1-140.*, < 147.0.4 and Thunderbird < 140.7.2, 147.0.2 - Heap-based Buffer Overflow in libvpx
Feb 16, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-2032 MEDIUM
Firefox < 147.2.1 and Firefox for iOS >= 147.2.1 - Address Bar Spoofing via New Tab Page Loading Interruption
Feb 16, 2026
CVSS 4.3
EPSS 0.00