Mozilla

Firefox ESR

985 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 29.09.2026 13:17:45
  • Zuletzt bearbeitet 30.09.2026 18:18:09

Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.

  • EPSS 0.17%
  • Veröffentlicht 29.09.2026 13:17:45
  • Zuletzt bearbeitet 01.10.2026 16:17:29

Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

  • EPSS 0.16%
  • Veröffentlicht 29.09.2026 13:17:45
  • Zuletzt bearbeitet 05.10.2026 14:52:50

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

  • EPSS 0.34%
  • Veröffentlicht 29.09.2026 13:17:44
  • Zuletzt bearbeitet 30.09.2026 18:18:07

Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

  • EPSS 0.34%
  • Veröffentlicht 29.09.2026 13:17:44
  • Zuletzt bearbeitet 30.09.2026 18:18:07

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

  • EPSS 0.16%
  • Veröffentlicht 29.09.2026 13:17:44
  • Zuletzt bearbeitet 01.10.2026 15:17:18

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.

  • EPSS 0.15%
  • Veröffentlicht 29.09.2026 13:17:44
  • Zuletzt bearbeitet 01.10.2026 16:17:28

Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

  • EPSS 0.15%
  • Veröffentlicht 29.09.2026 13:17:43
  • Zuletzt bearbeitet 05.10.2026 13:34:07

Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

  • EPSS 0.16%
  • Veröffentlicht 29.09.2026 13:17:43
  • Zuletzt bearbeitet 01.10.2026 15:17:18

Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.

  • EPSS 0.34%
  • Veröffentlicht 29.09.2026 13:17:42
  • Zuletzt bearbeitet 05.10.2026 15:18:50

Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.