PatchSiren

Mozilla CVE debriefs · Page 10

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2786

CVE-2026-2786 is a critical use-after-free vulnerability in Mozilla’s JavaScript Engine component. Mozilla fixed it in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. Based on the NVD CVSS vector, the issue is reachable over the network, requires no privileges, and needs no user interaction, making timely patching important for both browser and mail client deployments.

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2777

CVE-2026-2777 is a critical vulnerability in the Messaging System component of Firefox, allowing for privilege escalation. The vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The CVSS score for this vulnerability is 9.8, indicating a high severity. The vulnerability was published on February 24, 2026, and modified on June 30, 2026. The [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2776

CVE-2026-2776 is a critical vulnerability in Mozilla Firefox, allowing for sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 10 and a severity of CRITICAL. The CVE was published on 2026-02-24T14:16:26.023Z and last m [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2774

CVE-2026-2774 is a critical vulnerability in the Audio/Video component of Firefox, caused by an integer overflow. The vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.8, indicating a critical severity. The vulnerability was publicly disclosed on February 24 [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2772

CVE-2026-2772 is a critical use-after-free vulnerability in the Audio/Video: Playback component of Firefox. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE record was published on February 24, 2026, and last modified on June 30, 2026.

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2771

A critical vulnerability was found in the DOM: Core & HTML component of Firefox, which could lead to undefined behavior. This issue was addressed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability's impact on the browser's functionality and potential exploitation pathways should be assessed by defenders to prioritize updates and mitigate risks [truncated]

HIGH Mozilla CVE published 2026-02-24

CVE-2026-2769

CVE-2026-2769 is a high-severity vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird, caused by a use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. The CVE record was published on 2026-02-24T14:16:25.28 [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2768

CVE-2026-2768 is a critical vulnerability in the Storage: IndexedDB component of Mozilla Firefox and Thunderbird, allowing for a sandbox escape. The vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. This vulnerability has a CVSS score of 10 and a severity of CRITICAL. The CVE was published on 2026-02-24T14:16:25.183Z and last modified on 2026-06-30T03:18:17.470Z.

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2767

CVE-2026-2767 is a critical use-after-free vulnerability in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 9.8 and a severity of CRITICAL. The CVE was published on 2026-02-24T14:16:25.080Z and last modified on 2026-06-30T03:18:17.227Z. The vendor, Mozilla, has provided advi [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2766

CVE-2026-2766 is a critical use-after-free vulnerability in the JavaScript Engine's JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE was published on February 24, 2026, and last modified on June 30, 2026. The vulnerability affects multiple products from Mozill [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2763

CVE-2026-2763 is a critical use-after-free vulnerability in the JavaScript Engine component of Mozilla Firefox. The vulnerability was publicly disclosed on February 24, 2026, and was modified on June 30, 2026. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. The vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2759

CVE-2026-2759 is a critical vulnerability in the Mozilla Firefox browser, specifically affecting the Graphics: ImageLib component. The vulnerability was publicly disclosed on February 24, 2026, and has a CVSS score of 9.8, indicating a high severity level. The issue was addressed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. Users are advised to update to t [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2758

CVE-2026-2758 is a critical use-after-free vulnerability in the JavaScript: GC component of Mozilla Firefox. The vulnerability was publicly disclosed on February 24, 2026, and was modified on June 30, 2026. It affects multiple versions of Firefox, including Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The CVSS score for this vulnerability is 9.8, indicating a [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2757

CVE-2026-2757 is a critical vulnerability in the WebRTC: Audio/Video component of Firefox. The vulnerability is caused by incorrect boundary conditions, which can lead to severe consequences. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.8, indicati [truncated]

HIGH Mozilla CVE published 2026-02-16

CVE-2026-2447

CVE-2026-2447 is a high-severity vulnerability in libvpx, a library used in Mozilla products. The vulnerability is a heap buffer overflow, which can be exploited by attackers to execute arbitrary code. It was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2. Users of these products should update to the latest versions to mitigate the vulnera [truncated]

HIGH Mozilla CVE published 2026-01-27

CVE-2026-24869

CVE-2026-24869 is a high-severity vulnerability in the Mozilla Firefox browser. It is a use-after-free issue in the Layout: Scrolling and Overflow component. The vulnerability was publicly disclosed on January 27, 2026, and was modified on June 30, 2026. The issue was fixed in Firefox version 147.0.2. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.8, indicating a high sev [truncated]

HIGH Mozilla CVE published 2026-01-13

CVE-2026-0882

CVE-2026-0882 is a high-severity vulnerability in the IPC (Inter-Process Communication) component of Firefox, Thunderbird, and other Mozilla products. This use-after-free vulnerability, patched in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7, could allow attackers to execute arbitrary code. The vulnerability was publicly disclosed on January 13, 2026, and has [truncated]

HIGH Mozilla CVE published 2026-01-13

CVE-2026-0880

CVE-2026-0880 is a HIGH severity vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird. The vulnerability is caused by an integer overflow in the Graphics component, which can lead to a sandbox escape. The vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. Users should update to the latest version to mitigate the vulnerability. T [truncated]

CRITICAL Mozilla CVE published 2026-01-13

CVE-2026-0879

CVE-2026-0879 is a critical vulnerability in Mozilla Firefox, allowing for sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE record was published on January 13, 2026, and last m [truncated]

HIGH Mozilla CVE published 2026-01-13

CVE-2026-0878

CVE-2026-0878 is a HIGH-severity vulnerability affecting Mozilla products. The issue is a sandbox escape caused by incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. The CVE was published on 2026-01-13 and modified on 2026-06-30. The CVSS score is 8, indicating a high severity level. [truncated]

HIGH Mozilla CVE published 2026-01-13

CVE-2026-0877

CVE-2026-0877 is a high-severity vulnerability in Mozilla's Firefox, Firefox ESR, and Thunderbird products. This mitigation bypass issue in the DOM: Security component was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. The vulnerability has a CVSS score of 8.1 and is considered HIGH. It allows attackers to bypass mitigations in the DOM: Security compon [truncated]

Known exploited Mozilla CVE published 2025-10-06

CVE-2010-3765

CVE-2010-3765 is tracked by CISA as a Known Exploited Vulnerability affecting Mozilla Multiple Products and categorized as a remote code execution issue. In the supplied corpus, the KEV entry and CVE record are both dated 2025-10-06, with remediation due by 2025-10-27. Because only curated metadata is provided here, use Mozilla’s security advisory and the NVD record to confirm affected versions and exact fixes.

Known exploited Mozilla CVE published 2024-10-15

CVE-2024-9680

CVE-2024-9680 is a Mozilla Firefox use-after-free vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is already associated with known exploitation, it should be treated as urgent for anyone running Firefox in environments where rapid update and mitigation are possible.

Known exploited Mozilla CVE published 2023-06-22

CVE-2016-9079

CVE-2016-9079 is a Mozilla use-after-free vulnerability affecting Firefox, Firefox ESR, and Thunderbird. In the supplied corpus, CISA includes it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as a patch-priority issue and follow vendor update guidance without delay.

Known exploited Mozilla CVE published 2022-05-25

CVE-2015-4495

CVE-2015-4495 is a Mozilla Firefox security feature bypass vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is a KEV-listed issue, defenders should treat it as a patching priority and follow the vendor’s update guidance. The provided official metadata does not include a CVSS score or deeper technical detail, so the safest response is to verify exposure and apply the [truncated]

Known exploited Mozilla CVE published 2022-05-23

CVE-2019-11708

CVE-2019-11708 is described as a sandbox escape vulnerability affecting Mozilla Firefox and Thunderbird. CISA includes it in the Known Exploited Vulnerabilities catalog, so it should be treated as a high-priority remediation item for any environment running these products. The supplied corpus does not provide CVSS data or exploit details, so the safest defensive response is to apply vendor updates and ver [truncated]

Known exploited Mozilla CVE published 2022-05-23

CVE-2019-11707

CVE-2019-11707 is a Mozilla Firefox and Thunderbird type confusion vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2022-05-23, with remediation due by 2022-06-13. Because CISA treats it as known exploited, organizations should prioritize vendor updates for any affected Firefox or Thunderbird deployments and verify that patched versions are actually in place.

Known exploited Mozilla CVE published 2022-03-28

CVE-2013-1690

CVE-2013-1690 is recorded by CISA as a known exploited denial-of-service vulnerability affecting Mozilla Firefox and Thunderbird. The supplied corpus does not include root cause, affected version ranges, or exploit details, so remediation guidance should rely on the vendor’s updates and CISA’s KEV priority status.

Known exploited Mozilla CVE published 2022-03-07

CVE-2022-26486

CVE-2022-26486 is a Mozilla Firefox use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-07. Because it is listed as known to be exploited, defenders should treat this as a high-priority patching item and follow Mozilla’s update guidance without delay.

Known exploited Mozilla CVE published 2022-03-07

CVE-2022-26485

CVE-2022-26485 is a Mozilla Firefox use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-07. Because it is marked as known exploited, organizations should treat it as a high-priority browser remediation item and apply vendor updates as soon as possible.