2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74981 — Site: isolation issue in the Audio/Video: Web Codecs component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74981

Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 346TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74979 — Mitigation: bypass in the Add-ons Manager component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74979

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284VNDMitigationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74978 — Clickjacking: issue in the Widget component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74978

Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 1021VNDClickjackingTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74969 — Use: Use-after-free in the Layout: Text and Fonts component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74969

Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 359TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74965 — Privilege: escalation in the Shell Integration component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74965

Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74964 — Integer: overflow in the Graphics component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74964

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74962 — Site: isolation issue in the Networking: Cookies component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74962

Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 346TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74961 — Side: Side-channel in the Web Audio component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74961

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 203VNDSideTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74960 — Site: isolation issue in the WebExtensions component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74960

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 284CWECWE 346TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74959 — Mitigation: bypass in the Storage: Cache API component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74959

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 693VNDMitigationTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74957 — Mitigation: bypass in the Safe Browsing component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74957

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 8.1 (HIGH)

CWECWE 693VNDMitigationTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74956 — Same: Same-origin policy bypass in the DOM: Service Workers component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74956

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 9.1 (CRITICAL)

CWECWE 843TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74955 — Privilege: escalation in the Request Handling component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74955

Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74953 — Privilege: escalation in the Networking: Cookies component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74953

Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74952 — Privilege: escalation in the Application Update component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74952

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74950 — Privilege: escalation in the Downloads API component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74950

Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74949 — Privilege: escalation due to use-after-free in the Graphics: Canvas2D component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74949

Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74947 — Privilege: escalation due to invalid pointer in the Graphics component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74947

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 763TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74946 — Privilege: escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74946

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74944 — Mozilla Firefox: Use-after-free in the DOM: Core & HTML component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74944

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74943 — Mozilla Firefox: Use-after-free in the Graphics: ImageLib component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74943

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74942 — Privilege: escalation in the Remote Settings Client component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74942

Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74941 — Privilege: escalation in the Graphics: CanvasWebGL component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74941

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 13:17Z
CRIT

CVE-2026-74940 — Mozilla Firefox: Use-after-free in the Graphics: Text component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74940

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 13:17Z
HIGH

CVE-2026-74939 — Privilege: escalation in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-74939

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. CVSSv3.1 8.8 (HIGH)

CWECWE 269TYPVulnerability
8.8
CVSS v3.1
94
Edit Score