apk package
wolfi/firefox-docker-selenium-compat
pkg:apk/wolfi/firefox-docker-selenium-compat
Vulnerabilities (105)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-84123 | Hig | 8.8 | < 155.0.1-r0 | 155.0.1-r0 | Sep 1, 2026 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |
| CVE-2026-84122 | Med | 5.4 | < 155.0.1-r0 | 155.0.1-r0 | Sep 1, 2026 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84121 | Cri | 9.6 | < 155.0.1-r0 | 155.0.1-r0 | Sep 1, 2026 | Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84120 | Med | 5.4 | < 155.0.1-r0 | 155.0.1-r0 | Sep 1, 2026 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84119 | Cri | 9.6 | < 155.0.1-r0 | 155.0.1-r0 | Sep 1, 2026 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84118 | Med | 5.4 | < 155.0.1-r0 | 155.0.1-r0 | Sep 1, 2026 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |
| CVE-2026-75874 | Cri | 10.0 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. | |
| CVE-2026-74989 | Cri | 9.8 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbir | |
| CVE-2026-74979 | Cri | 9.8 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74968 | Med | 5.4 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74965 | Hig | 8.8 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74963 | Med | 5.4 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74958 | Hig | 7.5 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74956 | Cri | 9.1 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74955 | Hig | 8.8 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74954 | Hig | 7.5 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74952 | Hig | 8.8 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2. | |
| CVE-2026-74950 | Hig | 8.8 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74947 | Hig | 8.8 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74940 | Cri | 9.8 | < 154.0-r0 | 154.0-r0 | Aug 18, 2026 | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
- affected < 155.0.1-r0fixed 155.0.1-r0
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- affected < 155.0.1-r0fixed 155.0.1-r0
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 155.0.1-r0fixed 155.0.1-r0
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 155.0.1-r0fixed 155.0.1-r0
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 155.0.1-r0fixed 155.0.1-r0
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 155.0.1-r0fixed 155.0.1-r0
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- affected < 154.0-r0fixed 154.0-r0
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
- affected < 154.0-r0fixed 154.0-r0
Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbir
- affected < 154.0-r0fixed 154.0-r0
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2.
- affected < 154.0-r0fixed 154.0-r0
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-r0fixed 154.0-r0
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Page 2 of 6