These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in Firefox for iOS could allow saved PDF content to overwrite PDF files or bundled content within the application sandbox if a user opens a maliciously titled page. This issue is particularly concerning for users who handle PDFs from various sources. The vulnerability was fixed in Firefox for iOS 152.4. Users should update to the latest version to mitigate this vulnerability. The CVE recor [truncated]
A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3. The issue allows for user interface deception and rendering of attacker-controlled content, posing a medium priority r [truncated]
A vulnerability was discovered in Firefox for iOS, which preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument. This allowed a malicious site to inject arbitrary cookies into requests to an unrelated target domain. The vulnerability was fixed in Firefox for iOS 152.0.
CVE-2026-53899 is a vulnerability in Firefox for iOS that allows a malicious site on a suffix domain to receive cookies belonging to the target site due to partial domain matching when attaching cookies to PDF requests. This issue was fixed in Firefox for iOS 152.0. The vulnerability was published on [cvePublishedAt] and has not been associated with a CVSS score or severity level.
CVE-2026-12330 is a vulnerability in the Internationalization component due to incorrect boundary conditions. This issue was addressed in Firefox ESR 140.12 and Firefox ESR 115.37.
A memory safety bug was fixed in Firefox ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12. The bug was reported via [ref-4](resourceLinkAnnotations.ref-4) and [ref-5](resourceLinkAnnotations.ref-5).
Memory safety bugs were present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151, and Thunderbird 151. Some of these bugs showed evidence of memory corruption, and it is presumed that with enough effort, some of these could have been exploited to run arbitrary code. The vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
A memory safety issue was discovered in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151, and Thunderbird 151. The issue, tracked as CVE-2026-12327, was found to have evidence of memory corruption. It is presumed that with sufficient effort, some of these bugs could have been exploited to run arbitrary code. The vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
A series of memory safety bugs were discovered in Firefox 151 and Thunderbird 151. Some of these bugs demonstrated evidence of memory corruption. While the exact impact of these vulnerabilities is unclear, it is presumed that, with sufficient effort, an attacker could potentially exploit them to execute arbitrary code.
CVE-2026-12325 is a denial-of-service vulnerability in the Graphics: ImageLib component. This issue was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-12325) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-12325).
CVE-2026-12324 is a vulnerability in the Graphics: CanvasWebGL component. The issue involves incorrect boundary conditions. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12. For more information, refer to the [CVE-2026-12324 CVE record](resourceLinkAnnotations.cve-org) and [CVE-2026-12324 NVD detail](resourceLinkAnnotations.nvd).
CVE-2026-12323 is a spoofing issue in the DOM: Core & HTML component. The vulnerability was fixed in Firefox 152. The CVE was published and modified on June 16, 2026, at 13:16:33 UTC. The vendor is currently listed as Unknown Vendor, but evidence suggests the vulnerability may be related to Mozilla. For more information, see [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-12323) and [nvd](https://nvd. [truncated]
A clickjacking issue was found in the Widget: Gtk component. This vulnerability was fixed in Firefox 152. The issue was reported to Mozilla via Bugzilla and addressed in the Mozilla Firefox Security Advisory (MFSA) 2026-57.
A JIT (Just-In-Time) miscompilation vulnerability was discovered in the JavaScript: WebAssembly component. This vulnerability was addressed and fixed in Firefox 152. Users are advised to update to the latest version to mitigate potential risks.
CVE-2026-12320 is an information disclosure vulnerability in the Password Manager component of Firefox. The vulnerability was published and modified on June 16, 2026, at 13:16:32.710Z. The vendor is currently listed as Unknown Vendor, but evidence suggests the vulnerability may be related to Mozilla. The vulnerability was fixed in Firefox 152. For more information, see [cve-org](https://www.cve.org/CVERec [truncated]
CVE-2026-12319 is a denial-of-service vulnerability in the Audio/Video: Playback component. The vulnerability was fixed in Firefox 152. The CVE was published and modified on 2026-06-16T13:16:32.563Z. The vendor is currently listed as Unknown Vendor, but evidence suggests the vulnerability may be related to Mozilla. For more information, see [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-12319) and [n [truncated]
CVE-2026-12318 is a vulnerability in the Libraries component in NSS. The issue is related to incorrect boundary conditions. This vulnerability was fixed in Firefox 152.
A memory safety bug was fixed in Firefox 152. This vulnerability was fixed in Firefox 152. The bug was reported to Mozilla via Bugzilla [ref-4]. For more information, refer to Mozilla's security advisory [ref-5].
A mitigation bypass vulnerability was discovered in the DOM: Security component. This issue was resolved in Firefox 152. Users are advised to update to the latest version to ensure their browser is secure.
CVE-2026-12315 is a mitigation bypass vulnerability in the DOM: Security component. The vulnerability was published on [cvePublishedAt] and has not been modified since. The vendor for this vulnerability is likely Mozilla, based on evidence from the source item. The vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.
A memory safety bug was fixed in Firefox 152 and Firefox ESR 140.12. This vulnerability was published on June 16, 2026.
CVE-2026-12313 is an information disclosure and sandbox escape vulnerability in the Security: Process Sandboxing component. This issue was addressed in Firefox 152 and Firefox ESR 140.12.
A memory safety bug was fixed in Firefox 152 and Firefox ESR 140.12, which is identified as CVE-2026-12312. The bug was published on June 16, 2026.
CVE-2026-12311 is an information disclosure and sandbox escape vulnerability in the Security: Process Sandboxing component. This issue was addressed in Firefox 152 and Firefox ESR 140.12.
A memory safety bug was fixed in Firefox 152 and Firefox ESR 140.12. This vulnerability was published on [CVE.org](resourceLinkAnnotations:cve-org).
A memory safety bug was fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12. The bug was reported to Mozilla via Bugzilla and addressed in security advisories.
A memory safety bug was fixed in Firefox 152 and Firefox ESR 140.12. This vulnerability was published on [cvePublishedAt].
CVE-2026-12307 is a memory safety bug that was fixed in Firefox 152 and Firefox ESR 140.12. The bug was reported and fixed, with no evidence of exploitation or ransomware campaign use.
A memory safety bug was fixed in Firefox 152 and Firefox ESR 140.12. This vulnerability was published on [CVE.org](resourceLinkAnnotations:cve-org) and additional details can be found on [NVD](resourceLinkAnnotations:nvd).
A memory safety bug was fixed in Firefox 152 and Firefox ESR 140.12. This vulnerability was addressed in the latest releases of Firefox and Firefox ESR.