CVE-2026-100814
- EPSS 0.26%
- Veröffentlicht 29.09.2026 13:17:46
- Zuletzt bearbeitet 05.10.2026 17:00:48
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100815
- EPSS 0.25%
- Veröffentlicht 29.09.2026 13:17:46
- Zuletzt bearbeitet 05.10.2026 17:00:24
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100816
- EPSS 0.15%
- Veröffentlicht 29.09.2026 13:17:46
- Zuletzt bearbeitet 05.10.2026 16:59:58
Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100817
- EPSS 0.15%
- Veröffentlicht 29.09.2026 13:17:46
- Zuletzt bearbeitet 06.10.2026 14:35:41
Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100800
- EPSS 0.31%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 30.09.2026 18:18:09
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100801
- EPSS 0.25%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 30.09.2026 18:18:09
Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100802
- EPSS 0.26%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 30.09.2026 18:18:09
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100803
- EPSS 0.17%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 01.10.2026 16:17:29
Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100804
- EPSS 0.3%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 30.09.2026 18:18:09
Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-100805
- EPSS 0.22%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 30.09.2026 18:18:09
Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.