VYPR

apk package

chainguard/firefox

pkg:apk/chainguard/firefox

Vulnerabilities (685)

  • CVE-2026-16408CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16407CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16406CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16405HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16403MedJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16402CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16401HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16400HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16399HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16398HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16397MedJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.

  • CVE-2026-16396HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16395CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16394CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16393CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16392CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16391HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16390CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16389CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16388CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Page 3 of 35