Mozilla Firefox等都是美国Mozilla基金会的产品。Mozilla Firefox是一款开源Web浏览器。Mozilla Firefox ESR是Firefox(Web浏览器)的一个延长支持版本。Mozilla Thunderbird是一套从Mozilla Application Suite独立出来的电子邮件客户端软件。 Mozilla多款产品存在输入验证错误漏洞,该漏洞源于NSS的Libraries组件存在整数溢出。以下产品及版本受到影响:Firefox 148之前版本、Firefox
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Firefox | 115.35 ~ 115.* | - |
|
| Mozilla | Thunderbird | 140.8 ~ 140.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-2772 | Use-after-free in the Audio/Video: Playback component | |
| CVE-2026-2757 | Incorrect boundary conditions in the WebRTC: Audio/Video component | |
| CVE-2026-2758 | Use-after-free in the JavaScript: GC component | |
| CVE-2026-2764 | JIT miscompilation, use-after-free in the JavaScript Engine: JIT component | |
| CVE-2026-2760 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component | |
| CVE-2026-2761 | Sandbox escape in the Graphics: WebRender component | |
| CVE-2026-2762 | Integer overflow in the JavaScript: Standard Library component | |
| CVE-2026-2759 | Incorrect boundary conditions in the Graphics: ImageLib component | |
| CVE-2026-2770 | Use-after-free in the DOM: Bindings (WebIDL) component | |
| CVE-2026-2771 | Undefined behavior in the DOM: Core & HTML component | |
| CVE-2026-2769 | Use-after-free in the Storage: IndexedDB component | |
| CVE-2026-2773 | Incorrect boundary conditions in the Web Audio component | |
| CVE-2026-2774 | Integer overflow in the Audio/Video component | |
| CVE-2026-2775 | Mitigation bypass in the DOM: HTML Parser component | |
| CVE-2026-2776 | Sandbox escape due to incorrect boundary conditions in the Telemetry component in External | |
| CVE-2026-2777 | Privilege escalation in the Messaging System component | |
| CVE-2026-2778 | Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component | |
| CVE-2026-2779 | Incorrect boundary conditions in the Networking: JAR component | |
| CVE-2026-2780 | Privilege escalation in the Netmonitor component | |
| CVE-2026-2782 | Privilege escalation in the Netmonitor component |
Showing top 20 of 52 CVEs. View all on vendor page → →
No comments yet