VYPR

apk package

wolfi/firefox

pkg:apk/wolfi/firefox

Vulnerabilities (650)

  • CVE-2026-16392CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16391HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16390CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16389CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16388CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16387CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16386HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16385HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16384HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16383CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16382CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16381CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16380CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16379HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16378HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16377CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16376HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16375CriJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16374HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16372HigJul 21, 2026
    affected < 153.0-r0fixed 153.0-r0

    Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Page 2 of 33