🚨 CVE-2026-100788
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2072413. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100789
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🎖@cveNotify
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2072429. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100790
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🎖@cveNotify
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2072432. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100791
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🎖@cveNotify
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2072433. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100792
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2073266. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100793
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2073268. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100794
Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2028871. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100795
Denial-of-service in the Networking component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
Denial-of-service in the Networking component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2048871. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100796
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2049604. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100798
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2055694. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100799
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2056217. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100800
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2056767. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100801
Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2057112. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100802
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2057833. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100803
Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🎖@cveNotify
Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2057988. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100804
Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2058647. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100805
Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2058785. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100806
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2060408. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100807
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2062740. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100808
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2063488. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-100809
Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2063658. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.