Kaspersky ID:
KLA91302
Erkennungsdatum:
09/29/2026
Aktualisiert:
09/30/2026

Beschreibung

Multiple vulnerabilities were found in Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. Denial of service vulnerability in the Audio/Video: Playback component can be exploited remotely to cause denial of service.
  2. A remote code execution vulnerability in the Widget component can be exploited remotely to execute arbitrary code.
  3. Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
  4. Denial of service vulnerability in the Storage: Quota Manager component can be exploited remotely to cause denial of service.
  5. Security vulnerability in the Security: Process Sandboxing component can be exploited to bypass security restrictions.
  6. A remote code execution vulnerability in the DOM: Content Processes component can be exploited remotely to execute arbitrary code.
  7. A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
  8. Information disclosure vulnerability in the Networking: JAR component can be exploited to obtain sensitive information.
  9. A remote code execution vulnerability in the Networking: Cache component can be exploited remotely to execute arbitrary code.
  10. Security vulnerability can be exploited to bypass security restrictions.
  11. A remote code execution vulnerability in the DOM: Core & HTML component can be exploited remotely to execute arbitrary code.
  12. A remote code execution vulnerability in the Storage: IndexedDB component can be exploited remotely to execute arbitrary code.
  13. Security vulnerability in the Graphics component can be exploited to bypass security restrictions.
  14. A remote code execution vulnerability in the Graphics: Canvas2D component can be exploited remotely to execute arbitrary code.
  15. A remote code execution vulnerability in the XSLT component can be exploited remotely to execute arbitrary code.
  16. Denial of service vulnerability in the Graphics: WebRender component can be exploited remotely to cause denial of service.
  17. Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
  18. Denial of service vulnerability in the Audio/Video component can be exploited remotely to cause denial of service.
  19. A remote code execution vulnerability in the Layout: Text and Fonts component can be exploited remotely to execute arbitrary code.
  20. A remote code execution vulnerability in the Graphics component can be exploited remotely to execute arbitrary code.
  21. Security vulnerability in the XUL component can be exploited to bypass security restrictions.
  22. Denial of service vulnerability in the JavaScript: WebAssembly component can be exploited remotely to cause denial of service.
  23. Denial of service vulnerability in the Internationalization component can be exploited remotely to cause denial of service.
  24. Information disclosure vulnerability in the Networking component can be exploited to obtain sensitive information.
  25. A remote code execution vulnerability in the Graphics: WebRender component can be exploited remotely to execute arbitrary code.
  26. A remote code execution vulnerability in the Disability Access APIs component can be exploited remotely to execute arbitrary code.
  27. Security vulnerability in the DLL Services component can be exploited to bypass security restrictions.
  28. Security vulnerability in the WebExtensions component can be exploited to bypass security restrictions.
  29. Denial of service vulnerability in the Graphics: WebGPU component can be exploited remotely to cause denial of service.
  30. Security vulnerability in the DOM: Service Workers component can be exploited to bypass security restrictions.
  31. Security vulnerability in the DevTools component can be exploited to bypass security restrictions.
  32. Denial of service vulnerability in the JavaScript Engine: JIT component can be exploited remotely to cause denial of service.
  33. A remote code execution vulnerability in the CSS Parsing and Computation component can be exploited remotely to execute arbitrary code.
  34. A remote code execution vulnerability in the Widget: Gtk component can be exploited remotely to execute arbitrary code.
  35. Denial of service vulnerability in the XPCOM component can be exploited remotely to cause denial of service.
  36. Security vulnerability in the Address Bar component can be exploited to bypass security restrictions.
  37. Security UI vulnerability in the Networking: HTTP component can be exploited to spoof user interface.
  38. Security vulnerability in the Places component can be exploited to bypass security restrictions.
  39. A remote code execution vulnerability in the JavaScript Engine: JIT component can be exploited remotely to execute arbitrary code.
  40. Denial of service vulnerability in the Storage: StorageManager component can be exploited remotely to cause denial of service.
  41. Security vulnerability in the Bookmarks & History component can be exploited to bypass security restrictions.
  42. Security vulnerability in the DOM: Security component can be exploited to bypass security restrictions.
  43. A remote code execution vulnerability in the DOM: UI Events & Focus Handling component can be exploited remotely to execute arbitrary code.

Ursprüngliche Informationshinweise

Betroffene Produkte

CVE Liste

  • CVE-2026-100756
    unknown
  • CVE-2026-100757
    critical
  • CVE-2026-100758
    unknown
  • CVE-2026-100759
    unknown
  • CVE-2026-100760
    unknown
  • CVE-2026-100762
    critical
  • CVE-2026-100765
    critical
  • CVE-2026-100766
    warning
  • CVE-2026-100767
    critical
  • CVE-2026-100769
    critical
  • CVE-2026-100770
    critical
  • CVE-2026-100771
    unknown
  • CVE-2026-100772
    critical
  • CVE-2026-100773
    critical
  • CVE-2026-100774
    critical
  • CVE-2026-100775
    unknown
  • CVE-2026-100776
    critical
  • CVE-2026-100777
    critical
  • CVE-2026-100778
    critical
  • CVE-2026-100779
    critical
  • CVE-2026-100780
    critical
  • CVE-2026-100781
    unknown
  • CVE-2026-100782
    critical
  • CVE-2026-100783
    warning
  • CVE-2026-100784
    critical
  • CVE-2026-100785
    critical
  • CVE-2026-100786
    critical
  • CVE-2026-100787
    unknown
  • CVE-2026-100788
    unknown
  • CVE-2026-100789
    critical
  • CVE-2026-100790
    critical
  • CVE-2026-100791
    critical
  • CVE-2026-100792
    unknown
  • CVE-2026-100794
    unknown
  • CVE-2026-100797
    critical
  • CVE-2026-100798
    unknown
  • CVE-2026-100800
    critical
  • CVE-2026-100801
    critical
  • CVE-2026-100803
    unknown
  • CVE-2026-100806
    warning
  • CVE-2026-100807
    critical
  • CVE-2026-100808
    unknown
  • CVE-2026-100809
    unknown
  • CVE-2026-100811
    critical
  • CVE-2026-100812
    high
  • CVE-2026-100814
    critical
  • CVE-2026-100815
    critical
  • CVE-2026-100816
    unknown
  • CVE-2026-100818
    critical
  • CVE-2026-100819
    critical
  • CVE-2026-100820
    critical
  • CVE-2026-100821
    unknown
  • CVE-2026-100822
    unknown
  • CVE-2026-100824
    critical
  • CVE-2026-100825
    critical
  • CVE-2026-100826
    high
  • CVE-2026-100828
    unknown
  • CVE-2026-100829
    unknown
  • CVE-2026-100830
    unknown
  • CVE-2026-100831
    critical
  • CVE-2026-100832
    critical
  • CVE-2026-96869
    warning

Mehr erfahren

Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com

Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!
Kaspersky Next
Let´s go Next: Cybersicherheit neu gedacht
Erfahren Sie mehr
Neu: Kaspersky!
Dein digitales Leben verdient umfassenden Schutz!
Erfahren Sie mehr
Do you want to save your changes?
Your message has been sent successfully.