firefox-esr
by Debian
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-16375 | 0.00 | — | — | Jul 22, 2026 | Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | |||
| CVE-2026-16405 | 0.00 | — | — | Jul 22, 2026 | Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | |||
| CVE-2026-16390 | 0.00 | — | — | Jul 22, 2026 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | |||
| CVE-2026-16357 | 0.00 | — | — | Jul 22, 2026 | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | |||
| CVE-2026-16368 | 0.00 | — | — | Jul 22, 2026 | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | |||
| CVE-2026-16356 | 0.00 | — | — | Jul 22, 2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | |||
| CVE-2026-16396 | 0.00 | — | — | Jul 22, 2026 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | |||
| CVE-2026-16354 | 0.00 | — | — | Jul 22, 2026 | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. |
- CVE-2026-16375Jul 22, 2026risk 0.00cvss —epss —
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
- CVE-2026-16405Jul 22, 2026risk 0.00cvss —epss —
Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
- CVE-2026-16390Jul 22, 2026risk 0.00cvss —epss —
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
- CVE-2026-16357Jul 22, 2026risk 0.00cvss —epss —
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
- CVE-2026-16368Jul 22, 2026risk 0.00cvss —epss —
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
- CVE-2026-16356Jul 22, 2026risk 0.00cvss —epss —
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
- CVE-2026-16396Jul 22, 2026risk 0.00cvss —epss —
Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
- CVE-2026-16354Jul 22, 2026risk 0.00cvss —epss —
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.