mozilla

26 records · 1 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names mozilla as an affected vendor, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-100810

    Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.6CVE-2026-100819

    Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  3. CRITICAL 9.6CVE-2026-100818

    Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  4. CRITICAL 9.6CVE-2026-100811

    Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  5. CRITICAL 9.6CVE-2026-100787

    Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  6. CRITICAL 9.6CVE-2026-100786

    Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  7. CRITICAL 9.6CVE-2026-100781

    Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  8. CRITICAL 9.6CVE-2026-100778

    Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 8.8CVE-2026-100832

    Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 140.17, Thunderbird 153.4, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 8.8CVE-2026-100820

    Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  11. HIGH 8.8CVE-2026-100815

    Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  12. HIGH 8.8CVE-2026-100814

    Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  13. HIGH 8.8CVE-2026-100813

    Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  14. HIGH 8.8CVE-2026-100808

    Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  15. HIGH 8.8CVE-2026-100785

    Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  16. HIGH 8.8CVE-2026-100784

    Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  17. HIGH 8.8CVE-2026-100782

    Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  18. HIGH 8.8CVE-2026-100780

    Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  19. HIGH 8.8CVE-2026-100779

    Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  20. HIGH 8.8CVE-2026-100777

    Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  21. HIGH 8.1CVE-2026-100816

    Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  22. HIGH 8.1CVE-2026-100809

    Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  23. MEDIUM 6.5CVE-2026-100812

    Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  24. MEDIUM 5.4CVE-2026-100823public PoC

    Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.

    firefox mobile

    AI risk analysis on Exploit-DB.ai →

  25. MEDIUM 4.3CVE-2026-96869

    Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →

  26. MEDIUM 4.3CVE-2026-100783

    Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

    firefox · thunderbird

    AI risk analysis on Exploit-DB.ai →