CVE tracker
393 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-62280 - OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page

CVE ID :CVE-2026-62280
Published : Sept. 15, 2026, 9:54 a.m. | 11 minutes ago
Description :Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an active OpenAM session to follow a crafted authorization link and execute JavaScript in the OpenAM origin, enabling session or cookie theft, CSRF-token disclosure, and actions with the victim's privileges. At least one registered OAuth2 client is required, but the attacker does not need to control that client. This issue is fixed in version 16.1.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92058 - Use-after-free in the Graphics component

CVE ID :CVE-2026-92058
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92059 - Incorrect boundary conditions in the DOM: Editor component

CVE ID :CVE-2026-92059
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92060 - Use-after-free in the Internationalization component

CVE ID :CVE-2026-92060
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92061 - Incorrect boundary conditions in the Security: Process Sandboxing component

CVE ID :CVE-2026-92061
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92062 - Privilege escalation in the Session Restore component

CVE ID :CVE-2026-92062
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92063 - Denial-of-service in the Audio/Video component

CVE ID :CVE-2026-92063
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92064 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

CVE ID :CVE-2026-92064
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92065 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

CVE ID :CVE-2026-92065
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92066 - Sandbox escape in the Profile Backup component

CVE ID :CVE-2026-92066
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92067 - Use-after-free in the Widget: Gtk component

CVE ID :CVE-2026-92067
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92068 - Site isolation issue in the Reader Mode component

CVE ID :CVE-2026-92068
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92069 - Spoofing issue in the DOM: Navigation component

CVE ID :CVE-2026-92069
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92070 - Information disclosure in the Networking component

CVE ID :CVE-2026-92070
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92071 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

CVE ID :CVE-2026-92071
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92072 - Incorrect boundary conditions in the Safe Browsing component

CVE ID :CVE-2026-92072
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92073 - Privilege escalation in the Enterprise Policies component

CVE ID :CVE-2026-92073
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92074 - Mitigation bypass in the Popup Blocker component

CVE ID :CVE-2026-92074
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92075 - Mitigation bypass in the Networking component

CVE ID :CVE-2026-92075
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92076 - Incorrect boundary conditions in the Networking component

CVE ID :CVE-2026-92076
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92077 - Denial-of-service in the SVG component

CVE ID :CVE-2026-92077
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...