Mozilla Firefox是Mozilla基金会开源的一款网页浏览器。 Mozilla Firefox 154之前版本、Firefox ESR 115.39之前版本、Firefox ESR 140.14之前版本和Firefox ESR 153.1之前版本存在安全漏洞,该漏洞源于DOM Navigation组件问题,可能导致权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mozilla | Firefox | 115.39≤ 115.* |
unaffected |
140.14≤ 140.* |
unaffected | ||
153.1≤ 153.* |
unaffected | ||
154≤ * |
unaffected | ||
| Mozilla | Thunderbird | 140.14≤ 140.* |
unaffected |
153.1≤ 153.* |
unaffected | ||
154≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Firefox | 115.39 ~ 115.* | - |
|
| Mozilla | Thunderbird | 140.14 ~ 140.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74952 | Privilege escalation in the Application Update component | |
| CVE-2026-74979 | Mitigation bypass in the Add-ons Manager component | |
| CVE-2026-74982 | Denial-of-service in the Widget component | |
| CVE-2026-74985 | Privilege escalation in the Enterprise Policies component | |
| CVE-2026-74984 | Race condition in the JavaScript Engine component | |
| CVE-2026-74986 | Site isolation issue in the CSS Parsing and Computation component | |
| CVE-2026-74961 | Side-channel in the Web Audio component | |
| CVE-2026-74958 | Information disclosure in the WebRTC component | |
| CVE-2026-74966 | Information disclosure in the Form Autofill component | |
| CVE-2026-74956 | Same-origin policy bypass in the DOM: Service Workers component | |
| CVE-2026-74977 | Integer overflow in the Graphics component | |
| CVE-2026-74951 | Clickjacking issue in Firefox for Android | |
| CVE-2026-74955 | Privilege escalation in the Request Handling component | |
| CVE-2026-74954 | Information disclosure due to side-channel in the Storage: Cache API component | |
| CVE-2026-74937 | Use-after-free in the JavaScript: GC component | |
| CVE-2026-74938 | Mitigation bypass in the JavaScript: GC component | |
| CVE-2026-74950 | Privilege escalation in the Downloads API component | |
| CVE-2026-74947 | Privilege escalation due to invalid pointer in the Graphics component | |
| CVE-2026-74983 | Mitigation bypass in the Data Loss Prevention component | |
| CVE-2026-74990 | Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbi |
Showing top 20 of 58 CVEs. View all on vendor page → →
No comments yet