CVE-2026-100821
- EPSS 0.16%
- Veröffentlicht 29.09.2026 13:17:47
- Zuletzt bearbeitet 01.10.2026 16:17:30
Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100822
- EPSS 0.24%
- Veröffentlicht 29.09.2026 13:17:47
- Zuletzt bearbeitet 30.09.2026 21:16:54
Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100823
- EPSS 0.16%
- Veröffentlicht 29.09.2026 13:17:47
- Zuletzt bearbeitet 05.10.2026 16:58:57
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
CVE-2026-100824
- EPSS 0.24%
- Veröffentlicht 29.09.2026 13:17:47
- Zuletzt bearbeitet 30.09.2026 18:18:12
Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100825
- EPSS 0.25%
- Veröffentlicht 29.09.2026 13:17:47
- Zuletzt bearbeitet 30.09.2026 18:18:12
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100826
- EPSS 0.23%
- Veröffentlicht 29.09.2026 13:17:47
- Zuletzt bearbeitet 30.09.2026 18:18:12
Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100809
- EPSS 0.16%
- Veröffentlicht 29.09.2026 13:17:46
- Zuletzt bearbeitet 05.10.2026 14:30:57
Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100810
- EPSS 0.15%
- Veröffentlicht 29.09.2026 13:17:46
- Zuletzt bearbeitet 05.10.2026 17:02:20
Other issue in the DevTools component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100811
- EPSS 0.28%
- Veröffentlicht 29.09.2026 13:17:46
- Zuletzt bearbeitet 05.10.2026 17:02:02
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100812
- EPSS 0.29%
- Veröffentlicht 29.09.2026 13:17:46
- Zuletzt bearbeitet 05.10.2026 17:01:24
Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.