mozilla
239 known vulnerabilities affecting mozilla products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-74942 | Medium | 0.3% | 8.8 | Privilege escalation in the Remote Settings Client component. This vulnerability… | |
| CVE-2026-84142 | Medium | 0.3% | 9.8 | Internally found bugs present in Thunderbird 154. Some of these bugs showed evid… | |
| CVE-2026-8963 | Medium | 0.3% | 7.5 | Spoofing issue in the Web Speech component. This vulnerability was fixed in Fire… | |
| CVE-2026-8964 | Medium | 0.3% | 7.5 | Spoofing issue in the Popup Blocker component. This vulnerability was fixed in F… | |
| CVE-2026-10701 | Medium | 0.3% | 7.5 | Incorrect boundary conditions in the Graphics: Text component. This vulnerabilit… | |
| CVE-2026-74957 | Medium | 0.3% | 8.1 | Mitigation bypass in the Safe Browsing component. This vulnerability was fixed i… | |
| CVE-2026-16393 | Medium | 0.3% | 9.1 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerabil… | |
| CVE-2026-16371 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-74953 | Medium | 0.3% | 8.8 | Privilege escalation in the Networking: Cookies component. This vulnerability wa… | |
| CVE-2026-74965 | Medium | 0.3% | 8.8 | Privilege escalation in the Shell Integration component. This vulnerability was … | |
| CVE-2026-16372 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Content Processes component. This vulnerability… | |
| CVE-2026-16362 | Medium | 0.3% | 8.8 | Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixe… | |
| CVE-2026-74937 | Medium | 0.3% | 8.8 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in … | |
| CVE-2026-8969 | Medium | 0.3% | 8.1 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed i… | |
| CVE-2026-16409 | Medium | 0.3% | 7.5 | Invalid pointer in the Security: PSM component. This vulnerability was fixed in … | |
| CVE-2026-74956 | Medium | 0.3% | 9.1 | Same-origin policy bypass in the DOM: Service Workers component. This vulnerabil… | |
| CVE-2026-16407 | Medium | 0.3% | 9.8 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was … | |
| CVE-2026-16365 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Workers component. This vulnerability was fixed… | |
| CVE-2026-16379 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Content Processes component. This vulnerability… | |
| CVE-2024-7523 | Medium | 0.3% | 8.1 | A select option could partially obscure security prompts. This could be used by … | |
| CVE-2026-14899 | Medium | 0.3% | 7.5 | The code to parse MIME headers for display when forwarding a message (if the set… | |
| CVE-2026-16373 | Medium | 0.3% | 7.5 | Information disclosure in the Privacy component in Firefox for Android. This vul… | |
| CVE-2026-16366 | Medium | 0.3% | 8.8 | Privilege escalation in the DOM: Navigation component. This vulnerability was fi… | |
| CVE-2026-84641 | Medium | 0.3% | 7.5 | A malicious IMAP server can trigger use-after-free and heap-memory disclosure by… | |
| CVE-2026-74958 | Medium | 0.3% | 7.5 | Information disclosure in the WebRTC component. This vulnerability was fixed in … | |
| CVE-2026-16359 | Medium | 0.3% | 9.1 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerabil… | |
| CVE-2026-84640 | Medium | 0.3% | 7.5 | A maliciously constructed mail header could lead to a one byte read past the end… | |
| CVE-2026-16405 | Medium | 0.3% | 7.5 | Information disclosure in the Networking: WebSockets component. This vulnerabili… | |
| CVE-2026-74954 | Medium | 0.3% | 7.5 | Information disclosure due to side-channel in the Storage: Cache API component. … | |
| CVE-2026-74966 | Medium | 0.3% | 7.5 | Information disclosure in the Form Autofill component. This vulnerability was fi… | |
| CVE-2026-84130 | Medium | 0.3% | 7.5 | Information disclosure in the Graphics: WebGPU component. This vulnerability was… | |
| CVE-2026-84132 | Medium | 0.3% | 7.5 | Information disclosure in the Networking: HTTP component. This vulnerability was… | |
| CVE-2026-84642 | Medium | 0.3% | 7.5 | The values of the mail.allowed_attachment_hostnames advanced config setting were… | |
| CVE-2026-84135 | Medium | 0.3% | 9.8 | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefo… | |
| CVE-2026-74961 | Medium | 0.3% | 9.1 | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox… | |
| CVE-2026-16394 | Medium | 0.3% | 9.1 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed i… | |
| CVE-2026-16406 | Medium | 0.3% | 9.1 | Mitigation bypass in the Networking component. This vulnerability was fixed in F… | |
| CVE-2026-16400 | Medium | 0.2% | 7.5 | Information disclosure in the DOM: Security component. This vulnerability was fi… | |
| CVE-2026-74947 | Medium | 0.2% | 8.8 | Privilege escalation due to invalid pointer in the Graphics component. This vuln… | |
| CVE-2026-16396 | Medium | 0.2% | 8.8 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 1… | |
| CVE-2026-84144 | Medium | 0.2% | 7.5 | Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some… | |
| CVE-2026-84117 | Medium | 0.2% | 8.8 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Fir… | |
| CVE-2026-84123 | Medium | 0.2% | 8.8 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. Th… | |
| CVE-2026-84128 | Medium | 0.2% | 8.8 | Privilege escalation in the WebDriver BiDi component. This vulnerability was fix… | |
| CVE-2026-74978 | Medium | 0.2% | 8.1 | Clickjacking issue in the Widget component. This vulnerability was fixed in Fire… | |
| CVE-2026-74952 | Medium | 0.2% | 8.8 | Privilege escalation in the Application Update component. This vulnerability was… | |
| CVE-2026-74950 | Medium | 0.2% | 8.8 | Privilege escalation in the Downloads API component. This vulnerability was fixe… | |
| CVE-2026-74955 | Medium | 0.2% | 8.8 | Privilege escalation in the Request Handling component. This vulnerability was f… | |
| CVE-2026-11799 | Medium | 0.2% | 7.5 | UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in … | |
| CVE-2026-16358 | Medium | 0.2% | 9.8 | Site isolation issue in the Graphics: WebRender component. This vulnerability wa… |