mozilla
239 known vulnerabilities affecting mozilla products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-8962 | Medium | 0.4% | 8.1 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed i… | |
| CVE-2026-84145 | Medium | 0.4% | 7.5 | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thun… | |
| CVE-2026-16376 | Medium | 0.4% | 7.5 | Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixe… | |
| CVE-2026-16392 | Medium | 0.4% | 9.1 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… | |
| CVE-2026-74988 | Medium | 0.4% | 9.8 | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some… | |
| CVE-2026-74977 | Medium | 0.4% | 7.5 | Integer overflow in the Graphics component. This vulnerability was fixed in Fire… | |
| CVE-2026-74959 | Medium | 0.3% | 9.1 | Mitigation bypass in the Storage: Cache API component. This vulnerability was fi… | |
| CVE-2026-84141 | Medium | 0.3% | 9.8 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fix… | |
| CVE-2026-16354 | Medium | 0.3% | 7.5 | Information disclosure in the Graphics: ImageLib component. This vulnerability w… | |
| CVE-2026-84637 | Medium | 0.3% | 9.8 | Malicious calendar invitations could use file URI attachments to launch local or… | |
| CVE-2026-16395 | Medium | 0.3% | 9.8 | Integer overflow in the Audio/Video component. This vulnerability was fixed in F… | |
| CVE-2026-16402 | Medium | 0.3% | 9.8 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fix… | |
| CVE-2026-8973 | Medium | 0.3% | 8.8 | Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of… | |
| CVE-2026-8966 | Medium | 0.3% | 7.5 | Information disclosure in the IP Protection component. This vulnerability was fi… | |
| CVE-2026-74989 | Medium | 0.3% | 9.8 | Internally found bugs present in Thunderbird 153. Some of these bugs showed evid… | |
| CVE-2026-8974 | Medium | 0.3% | 8.8 | Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these … | |
| CVE-2026-8967 | Medium | 0.3% | 7.5 | Information disclosure in the Graphics: WebGPU component. This vulnerability was… | |
| CVE-2026-8972 | Medium | 0.3% | 8.8 | Privilege escalation in the WebRTC: Audio/Video component. This vulnerability wa… | |
| CVE-2026-74946 | Medium | 0.3% | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: Canva… | |
| CVE-2026-84131 | Medium | 0.3% | 8.8 | Privilege escalation due to invalid pointer in the Graphics component. This vuln… | |
| CVE-2026-74983 | Medium | 0.3% | 8.1 | Mitigation bypass in the Data Loss Prevention component. This vulnerability was … | |
| CVE-2026-8965 | Medium | 0.3% | 7.5 | Information disclosure in the DOM: Security component. This vulnerability was fi… | |
| CVE-2026-74986 | Medium | 0.3% | 9.1 | Site isolation issue in the CSS Parsing and Computation component. This vulnerab… | |
| CVE-2026-84639 | Medium | 0.3% | 9.1 | Triggering an error condition in certain MIME bodies would cause uninitialized m… | |
| CVE-2026-74941 | Medium | 0.3% | 8.8 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability … | |
| CVE-2026-16391 | Medium | 0.3% | 7.5 | Information disclosure in the Storage: IndexedDB component. This vulnerability w… | |
| CVE-2026-74938 | Medium | 0.3% | 9.1 | Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed … | |
| CVE-2026-16374 | Medium | 0.3% | 7.5 | Information disclosure in the Framework component in DevTools. This vulnerabilit… | |
| CVE-2026-74969 | Medium | 0.3% | 8.8 | Use-after-free in the Layout: Text and Fonts component. This vulnerability was f… | |
| CVE-2026-84119 | Medium | 0.3% | 9.6 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vuln… | |
| CVE-2026-84121 | Medium | 0.3% | 9.6 | Sandbox escape due to use-after-free in the DOM: Security component. This vulner… | |
| CVE-2026-8090 | Medium | 0.3% | 7.3 | Use-after-free in the DOM: Networking component. This vulnerability was fixed in… | |
| CVE-2026-16390 | Medium | 0.3% | 9.1 | Mitigation bypass in the Enterprise Policies component. This vulnerability was f… | |
| CVE-2026-16361 | Medium | 0.3% | 9.8 | Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed … | |
| CVE-2026-74949 | Medium | 0.3% | 8.8 | Privilege escalation due to use-after-free in the Graphics: Canvas2D component. … | |
| CVE-2026-16384 | Medium | 0.3% | 7.5 | Information disclosure due to uninitialized memory in the Graphics: WebGPU compo… | |
| CVE-2026-74982 | Medium | 0.3% | 7.5 | Denial-of-service in the Widget component. This vulnerability was fixed in Firef… | |
| CVE-2026-16385 | Medium | 0.3% | 7.5 | Information disclosure due to uninitialized memory in the Graphics: WebGPU compo… | |
| CVE-2026-16386 | Medium | 0.3% | 7.5 | Information disclosure due to uninitialized memory in the Graphics: WebGPU compo… | |
| CVE-2026-74935 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Networking component. This vulnerability was fi… | |
| CVE-2026-84134 | Medium | 0.3% | 9.8 | Other issue in the Profile Backup component. This vulnerability was fixed in Fir… | |
| CVE-2026-16370 | Medium | 0.3% | 9.1 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed… | |
| CVE-2026-16380 | Medium | 0.3% | 9.1 | Mitigation bypass in the Networking component. This vulnerability was fixed in F… | |
| CVE-2026-74985 | Medium | 0.3% | 9.8 | Privilege escalation in the Enterprise Policies component. This vulnerability wa… | |
| CVE-2026-8970 | Medium | 0.3% | 8.8 | Privilege escalation in the Security component. This vulnerability was fixed in … | |
| CVE-2026-16378 | Medium | 0.3% | 7.5 | Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerabili… | |
| CVE-2026-74979 | Medium | 0.3% | 9.8 | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed… | |
| CVE-2026-16364 | Medium | 0.3% | 9.1 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulne… | |
| CVE-2026-16410 | Medium | 0.3% | 9.8 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w… | |
| CVE-2026-74942 | Medium | 0.3% | 8.8 | Privilege escalation in the Remote Settings Client component. This vulnerability… |