PatchSiren

Mozilla CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Mozilla CVE published 2026-09-01

CVE-2026-84142

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T13:20:08.337Z and has not been modified since then. The vulnerability affects Mozilla Thunderbird version 154 and earlier, with evidence of memory corruption or other security-relevant defects. These bugs were fixed in Firefox 155 and Thunderbird 155. The vulnerability has a CVSS score of 9.8 and [truncated]

MEDIUM Mozilla CVE published 2026-09-01

CVE-2026-84139

The CVE-2026-84139 vulnerability is a clickjacking issue in the DOM: Events component of Mozilla products, including Firefox, Firefox ESR, Thunderbird, and Thunderbird. This issue allows attackers to trick users into performing unintended actions on a web page. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. Affected product deployments should be reviewed for potential expo [truncated]

MEDIUM Mozilla CVE published 2026-09-01

CVE-2026-84138

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T13:20:07.920Z and has not been modified since then. This denial-of-service vulnerability in the PDF Viewer component of Firefox and Thunderbird was fixed in Firefox 155 and Thunderbird 155. Organizations and individuals using these applications should review and apply the necessary patches to pre [truncated]

MEDIUM Mozilla CVE published 2026-09-01

CVE-2026-84136

The CVE-2026-84136 vulnerability, classified as an 'Other issue in the DOM: Navigation component,' affects Mozilla Firefox and Thunderbird. This medium-severity issue, with a CVSS score of 6.1, was addressed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. The vulnerability's impact is primarily related to potential cross-site scripting (XSS) attacks, which could allow attackers [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84132

The CVE-2026-84132 vulnerability is an information disclosure issue in the Networking: HTTP component of Mozilla products, including Firefox, Firefox ESR, Thunderbird, and Thunderbird. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. The CVSS score of 7.5 indicates high severity. The vulnerability can be exploited remotely with low attack complexity a [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84131

The CVE-2026-84131 vulnerability is a privilege escalation issue caused by an invalid pointer in the Graphics component of Mozilla products. This vulnerability was addressed in various product versions, including Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Organizations should review the official advisory and CVE recor [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84130

Information disclosure vulnerability in the Graphics: WebGPU component of Firefox, Firefox ESR, Thunderbird, and Thunderbird. The vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. This issue allows for potential information disclosure. Users and security teams should review official advisories for specific guidance and apply patches to prevent potential inf [truncated]

CRITICAL Mozilla CVE published 2026-09-01

CVE-2026-84129

The CVE-2026-84129 vulnerability is a critical site isolation issue in the DOM: Navigation component of Firefox and Thunderbird products. It was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a critical vulnerability with high impact. Organizations and individuals using these products, especially [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84128

The WebDriver BiDi component in Firefox and Thunderbird is vulnerable to privilege escalation. This issue was patched in Firefox 155 and Thunderbird 155. Users of affected versions should update to the latest version to mitigate the vulnerability. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Affected users, particularly those using WebDriver BiDi, should prioritize patching t [truncated]

MEDIUM Mozilla CVE published 2026-09-01

CVE-2026-84127

Information disclosure vulnerability in Firefox for Android's WebExtensions component, fixed in Firefox 155. The vulnerability allows sensitive information to be disclosed, potentially impacting users who rely on WebExtensions for enhanced functionality. This issue was addressed with the release of Firefox 155, which includes security patches to mitigate the vulnerability. Users of Firefox for Android, pa [truncated]

MEDIUM Mozilla CVE published 2026-09-01

CVE-2026-84126

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T13:20:06.537Z and has not been modified since then. The CVE-2026-84126 vulnerability involves incorrect boundary conditions in the Layout: Grid component of Firefox and Thunderbird. This issue was fixed in Firefox 155 and Thunderbird 155. The vulnerability has a CVSS score of 4.3 and a severity o [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84117

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T13:20:05.487Z and has not been modified since then. CVE-2026-84117 is a high-severity privilege escalation vulnerability in Firefox for Android, fixed in Firefox 155. The vulnerability may allow attackers to gain elevated privileges on affected systems, potentially leading to unauthorized access [truncated]

MEDIUM Mozilla CVE published 2026-08-31

CVE-2026-81267

A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0. The issue allows a malicious webpage to stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while c [truncated]

CRITICAL Mozilla CVE published 2026-08-18

CVE-2026-75874

The CVE-2026-75874 vulnerability is a critical sandbox escape issue in the Remote Settings Client component of various Mozilla products, including Firefox and Thunderbird. This vulnerability allows for a sandbox escape and was addressed through updates to versions 154, 115.40, 140.15, 153.2, and others. The CVSS score for this vulnerability is 10, indicating a critical severity level. Organizations and in [truncated]

CRITICAL Mozilla CVE published 2026-08-18

CVE-2026-74990

The CVE-2026-74990 vulnerability is a critical issue affecting multiple versions of Firefox ESR and Firefox. It was internally found and shows evidence of memory corruption or other security-relevant defects. Organizations and individuals using the affected versions should apply patches immediately to prevent potential exploitation. The bugs found could lead to memory corruption or other security-relevant [truncated]

CRITICAL Mozilla CVE published 2026-08-18

CVE-2026-74987

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-74987 was published on 2026-08-18T13:17:40.560Z. This critical vulnerability, with a CVSS score of 9.8, was found in Firefox ESR 140.13, Firefox ESR 153.0, and Firefox 153. The bugs showed evidence of memory corruption or another security-relevant defect, which could potentially be exploited with enough effort. [truncated]

CRITICAL Mozilla CVE published 2026-08-18

CVE-2026-74986

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. The issue arises from the component's handling of CSS parsing and computation, which could be exploited to bypass site isolation mechanisms. Users of Mozilla products should be aware of this vulnerability and take necessary precautions. [truncated]

CRITICAL Mozilla CVE published 2026-08-18

CVE-2026-74985

CVE-2026-74985 is a critical vulnerability in the Enterprise Policies component of Mozilla products, including Firefox, Firefox ESR, and Thunderbird. The vulnerability has a CVSS score of 9.8 and allows for privilege escalation. It was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. Limited evidence suggests that this is a privilege escalation issue; further analysis is re [truncated]

MEDIUM Mozilla CVE published 2026-08-18

CVE-2026-74984

A race condition vulnerability exists in the JavaScript Engine component of Mozilla products, including Firefox, Firefox ESR, Thunderbird, and Thunderbird. The vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. The CVSS score is 6.8, indicating a medium severity. This vulnerability could potentially allow attackers to execute arbitrary code or cause a denial [truncated]

HIGH Mozilla CVE published 2026-08-18

CVE-2026-74981

A site isolation issue was found in the Audio/Video: Web Codecs component. This issue was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. The vulnerability has a high CVSS score of 8.1, indicating a high severity level. Users and administrators of Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR should apply the patches to prevent potential exploitation. Defenders sh [truncated]

MEDIUM Mozilla CVE published 2026-08-18

CVE-2026-74980

A clickjacking issue was discovered in the Downloads component of Firefox Mobile for Android. This vulnerability, tracked as CVE-2026-74980, was fixed in Firefox version 154. The CVSS score for this vulnerability is 6.5, indicating a medium severity level. Organizations and individuals using Firefox Mobile for Android should be aware of this vulnerability and take steps to mitigate it. The CVE record was [truncated]

HIGH Mozilla CVE published 2026-08-18

CVE-2026-74978

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T13:17:36.390Z and has not been modified since then. CVE-2026-74978 is a clickjacking issue in the Widget component of Mozilla products, including Firefox and Thunderbird. This vulnerability allows an attacker to trick users into performing unintended actions. The issue was addressed in Firefox 15 [truncated]

HIGH Mozilla CVE published 2026-08-18

CVE-2026-74977

Integer overflow vulnerability in the Graphics component of Firefox, Firefox ESR, Thunderbird, and Thunderbird. This issue was addressed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. The vulnerability allows for potential code execution, posing a significant risk to users of these applications. Users and administrators should apply patches immediately to mitigate the vulnerabi [truncated]

MEDIUM Mozilla CVE published 2026-08-18

CVE-2026-74975

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T13:17:35.353Z and has not been modified since then. This medium-severity spoofing vulnerability in the Downloads component of Firefox Mobile for Android was fixed in Firefox 154. The vulnerability is characterized by a CVSS score of 5.4. Organizations and individuals using Firefox Mobile for Andr [truncated]

MEDIUM Mozilla CVE published 2026-08-18

CVE-2026-74970

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. The issue could potentially allow for user interaction-based attacks. Users of Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR should apply the relevant patches to prevent potential site isolation issues in the Graphics component. Affected operators [truncated]

HIGH Mozilla CVE published 2026-08-18

CVE-2026-74966

The CVE-2026-74966 record indicates an information disclosure vulnerability in the Form Autofill component of Mozilla products. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. The CVSS score is 7.5 with HIGH severity. Affected users should verify and apply vendor patches if vulnerable. Limited evidence suggests that the vulnerability was addressed in [truncated]

HIGH Mozilla CVE published 2026-08-18

CVE-2026-74960

A site isolation issue was found in the WebExtensions component of Firefox, which could potentially allow an attacker to access sensitive information. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. The issue arises from the WebExtensions component's handling of isolated web pages, which could be exploited to a [truncated]

HIGH Mozilla CVE published 2026-08-18

CVE-2026-74957

CVE-2026-74957 is a mitigation bypass vulnerability in the Safe Browsing component of Firefox, Firefox ESR, and Thunderbird. The vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. This vulnerability has a CVSS score of 8.1, indicating high severity. Organizations and individuals using these products should be aware of [truncated]

HIGH Mozilla CVE published 2026-08-18

CVE-2026-74952

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T13:17:32.100Z and has not been modified since then. The CVE-2026-74952 vulnerability is a high-severity issue (CVSS score of 8.8) affecting the Application Update component of Mozilla products, allowing for privilege escalation. It was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and [truncated]

MEDIUM Mozilla CVE published 2026-08-18

CVE-2026-74945

Information disclosure vulnerability in the Graphics: Text component of Firefox, Firefox ESR, and Thunderbird. The CVE record was published on 2026-08-18T13:17:31.133Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability could potentially allow attackers to access sensitive information. Affected organizations and individuals should apply patches from Moz [truncated]