Mozilla Firefox是Mozilla基金会开源的一款Web浏览器。 Mozilla Firefox 153之前版本存在安全漏洞,该漏洞源于Disability Access APIs组件中存在无效指针,可能导致沙箱逃逸。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mozilla | Firefox | 153≤ * |
unaffected |
| Mozilla | Thunderbird | 153≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Firefox | 153 ~ * | - |
|
| Mozilla | Thunderbird | 153 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16375 | Site isolation issue in the Networking: HTTP component | |
| CVE-2026-16364 | Incorrect boundary conditions in the Audio/Video: Playback component | |
| CVE-2026-16362 | Use-after-free in the WebRTC: Audio/Video component | |
| CVE-2026-16352 | Sandbox escape due to use-after-free in the Disability Access APIs component | |
| CVE-2026-16363 | JIT miscompilation in the JavaScript: WebAssembly component | |
| CVE-2026-16370 | Mitigation bypass in the DOM: Networking component | |
| CVE-2026-16371 | Privilege escalation in the DOM: Navigation component | |
| CVE-2026-16372 | Privilege escalation in the DOM: Content Processes component | |
| CVE-2026-16373 | Information disclosure in the Privacy component in Firefox for Android | |
| CVE-2026-16374 | Information disclosure in the Framework component in DevTools | |
| CVE-2026-16356 | Sandbox escape due to use-after-free in the Disability Access APIs component | |
| CVE-2026-16376 | Denial-of-service in the Graphics: WebGPU component | |
| CVE-2026-16377 | Mitigation bypass in the PDF Viewer component | |
| CVE-2026-16378 | Other issue in the DOM: Copy & Paste and Drag & Drop component | |
| CVE-2026-16379 | Privilege escalation in the DOM: Content Processes component | |
| CVE-2026-16358 | Site isolation issue in the Graphics: WebRender component | |
| CVE-2026-16381 | Same-origin policy bypass in the Networking: DNS component | |
| CVE-2026-16380 | Mitigation bypass in the Networking component | |
| CVE-2026-16382 | Mitigation bypass in the DOM: Service Workers component | |
| CVE-2026-16383 | Mitigation bypass in the DOM: Networking component |
Showing top 20 of 64 CVEs. View all on vendor page → →
No comments yet