CVE-2026-62280 - OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
CVE ID :CVE-2026-62280
Published : Sept. 15, 2026, 9:54 a.m. | 11 minutes ago
Description :Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an active OpenAM session to follow a crafted authorization link and execute JavaScript in the OpenAM origin, enabling session or cookie theft, CSRF-token disclosure, and actions with the victim's privileges. At least one registered OAuth2 client is required, but the attacker does not need to control that client. This issue is fixed in version 16.1.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-62280
Published : Sept. 15, 2026, 9:54 a.m. | 11 minutes ago
Description :Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an active OpenAM session to follow a crafted authorization link and execute JavaScript in the OpenAM origin, enabling session or cookie theft, CSRF-token disclosure, and actions with the victim's privileges. At least one registered OAuth2 client is required, but the attacker does not need to control that client. This issue is fixed in version 16.1.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92058 - Use-after-free in the Graphics component
CVE ID :CVE-2026-92058
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92058
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92059 - Incorrect boundary conditions in the DOM: Editor component
CVE ID :CVE-2026-92059
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92059
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92060 - Use-after-free in the Internationalization component
CVE ID :CVE-2026-92060
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92060
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92061 - Incorrect boundary conditions in the Security: Process Sandboxing component
CVE ID :CVE-2026-92061
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92061
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92062 - Privilege escalation in the Session Restore component
CVE ID :CVE-2026-92062
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92062
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92063 - Denial-of-service in the Audio/Video component
CVE ID :CVE-2026-92063
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92063
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92064 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE ID :CVE-2026-92064
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92064
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92065 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE ID :CVE-2026-92065
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92065
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92066 - Sandbox escape in the Profile Backup component
CVE ID :CVE-2026-92066
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92066
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92067 - Use-after-free in the Widget: Gtk component
CVE ID :CVE-2026-92067
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92067
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92068 - Site isolation issue in the Reader Mode component
CVE ID :CVE-2026-92068
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92068
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92069 - Spoofing issue in the DOM: Navigation component
CVE ID :CVE-2026-92069
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92069
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92070 - Information disclosure in the Networking component
CVE ID :CVE-2026-92070
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92070
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92071 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE ID :CVE-2026-92071
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92071
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92072 - Incorrect boundary conditions in the Safe Browsing component
CVE ID :CVE-2026-92072
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92072
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92073 - Privilege escalation in the Enterprise Policies component
CVE ID :CVE-2026-92073
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92073
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92074 - Mitigation bypass in the Popup Blocker component
CVE ID :CVE-2026-92074
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92074
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92075 - Mitigation bypass in the Networking component
CVE ID :CVE-2026-92075
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92075
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92076 - Incorrect boundary conditions in the Networking component
CVE ID :CVE-2026-92076
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92076
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92077 - Denial-of-service in the SVG component
CVE ID :CVE-2026-92077
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92077
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...