CVE-2026-100801
- EPSS 0.25%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 30.09.2026 18:18:09
Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100803
- EPSS 0.17%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 01.10.2026 16:17:29
Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100808
- EPSS 0.16%
- Veröffentlicht 29.09.2026 13:17:45
- Zuletzt bearbeitet 05.10.2026 14:52:50
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100790
- EPSS 0.34%
- Veröffentlicht 29.09.2026 13:17:44
- Zuletzt bearbeitet 30.09.2026 18:18:07
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100791
- EPSS 0.34%
- Veröffentlicht 29.09.2026 13:17:44
- Zuletzt bearbeitet 30.09.2026 18:18:07
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100792
- EPSS 0.16%
- Veröffentlicht 29.09.2026 13:17:44
- Zuletzt bearbeitet 01.10.2026 15:17:18
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100798
- EPSS 0.15%
- Veröffentlicht 29.09.2026 13:17:44
- Zuletzt bearbeitet 01.10.2026 16:17:28
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100787
- EPSS 0.15%
- Veröffentlicht 29.09.2026 13:17:43
- Zuletzt bearbeitet 05.10.2026 13:34:07
Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-100788
- EPSS 0.16%
- Veröffentlicht 29.09.2026 13:17:43
- Zuletzt bearbeitet 01.10.2026 15:17:18
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100779
- EPSS 0.34%
- Veröffentlicht 29.09.2026 13:17:42
- Zuletzt bearbeitet 05.10.2026 15:18:50
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.