apk package
wolfi/firefox
pkg:apk/wolfi/firefox
Vulnerabilities (650)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-16392 | Cri | 9.1 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16391 | Hig | 7.5 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16390 | Cri | 9.1 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16389 | Cri | 9.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16388 | Cri | 9.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16387 | Cri | 9.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16386 | Hig | 7.5 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16385 | Hig | 7.5 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16384 | Hig | 7.5 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16383 | Cri | 9.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16382 | Cri | 9.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16381 | Cri | 9.1 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16380 | Cri | 9.1 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16379 | Hig | 8.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16378 | Hig | 7.5 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16377 | Cri | 9.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16376 | Hig | 7.5 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |
| CVE-2026-16375 | Cri | 9.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16374 | Hig | 7.5 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | |
| CVE-2026-16372 | Hig | 8.8 | < 153.0-r0 | 153.0-r0 | Jul 21, 2026 | Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
- affected < 153.0-r0fixed 153.0-r0
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- affected < 153.0-r0fixed 153.0-r0
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- affected < 153.0-r0fixed 153.0-r0
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Page 2 of 33