Mozilla Firefox是Mozilla基金会开源的一款网页浏览器。 Mozilla Firefox 155之前版本、Mozilla Firefox ESR 153.2之前版本、Mozilla Thunderbird 155之前版本和Mozilla Thunderbird 153.2之前版本存在安全漏洞,该漏洞源于Graphics: ImageLib组件存在整数溢出。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mozilla | Firefox | 153.2≤ 153.* |
unaffected |
155≤ * |
unaffected | ||
| Mozilla | Thunderbird | 153.2≤ 153.* |
unaffected |
155≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Firefox | 153.2 ~ 153.* | - |
|
| Mozilla | Thunderbird | 153.2 ~ 153.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84122 | Use-after-free in the Audio/Video component | |
| CVE-2026-84130 | Information disclosure in the Graphics: WebGPU component | |
| CVE-2026-84129 | Site isolation issue in the DOM: Navigation component | |
| CVE-2026-84128 | Privilege escalation in the WebDriver BiDi component | |
| CVE-2026-84127 | Information disclosure in the WebExtensions component in Firefox for Android | |
| CVE-2026-84126 | Incorrect boundary conditions in the Layout: Grid component | |
| CVE-2026-84125 | Use-after-free in the DOM: Core & HTML component | |
| CVE-2026-84124 | Use-after-free in the DOM: Core & HTML component | |
| CVE-2026-84123 | Privilege escalation due to use-after-free in the Graphics: WebGPU component | |
| CVE-2026-84132 | Information disclosure in the Networking: HTTP component | |
| CVE-2026-84118 | Use-after-free in the JavaScript: GC component | |
| CVE-2026-84117 | Privilege escalation in Firefox for Android | |
| CVE-2026-84145 | Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR | |
| CVE-2026-84131 | Privilege escalation due to invalid pointer in the Graphics component | |
| CVE-2026-84121 | Sandbox escape due to use-after-free in the DOM: Security component | |
| CVE-2026-84120 | Use-after-free in the Audio/Video component | |
| CVE-2026-84119 | Sandbox escape due to use-after-free in the DOM: Navigation component | |
| CVE-2026-84642 | Allowed UNC hostnames for attachments interpreted as a regular expression | |
| CVE-2026-84133 | Site isolation issue in the DOM: Push Subscriptions component | |
| CVE-2026-84134 | Other issue in the Profile Backup component |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet