CVE-2026-12289
- EPSS 0.4%
- Veröffentlicht 16.06.2026 11:52:22
- Zuletzt bearbeitet 15.07.2026 12:17:03
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
CVE-2026-12068
- EPSS 0.26%
- Veröffentlicht 12.06.2026 22:19:18
- Zuletzt bearbeitet 23.07.2026 09:10:00
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection....
CVE-2026-10702
- EPSS 0.72%
- Veröffentlicht 02.06.2026 17:16:00
- Zuletzt bearbeitet 22.07.2026 19:10:00
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-10701
- EPSS 0.3%
- Veröffentlicht 02.06.2026 17:15:59
- Zuletzt bearbeitet 22.07.2026 19:10:00
Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-9309
- EPSS 0.16%
- Veröffentlicht 01.06.2026 11:24:10
- Zuletzt bearbeitet 22.07.2026 07:10:00
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal page...
CVE-2026-9308
- EPSS 0.16%
- Veröffentlicht 01.06.2026 11:24:09
- Zuletzt bearbeitet 22.07.2026 07:10:00
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary ...
CVE-2026-9078
- EPSS 0.2%
- Veröffentlicht 25.05.2026 14:05:47
- Zuletzt bearbeitet 23.07.2026 11:10:00
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-contro...
CVE-2026-8706
- EPSS 0.19%
- Veröffentlicht 19.05.2026 14:27:38
- Zuletzt bearbeitet 23.07.2026 20:10:00
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in ...
CVE-2026-8975
- EPSS 0.43%
- Veröffentlicht 19.05.2026 12:30:24
- Zuletzt bearbeitet 23.07.2026 20:10:00
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This v...
CVE-2026-8974
- EPSS 0.33%
- Veröffentlicht 19.05.2026 12:30:23
- Zuletzt bearbeitet 23.07.2026 20:10:00
Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fix...