Description
Multiple vulnerabilities were found in Mozilla Firefox. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information, spoof user interface.
Below is a complete list of vulnerabilities:
- Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
- Denial of service vulnerability in the Audio/Video: cubeb component can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in the WebRTC: Audio/Video component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Navigation component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the Disability Access APIs component can be exploited remotely to execute arbitrary code.
- Security vulnerability can be exploited to bypass security restrictions.
- Denial of service vulnerability in the Audio/Video: Playback component can be exploited remotely to cause denial of service.
- Security vulnerability in the DOM: Workers component can be exploited to bypass security restrictions.
- Denial of service vulnerability in the DOM: Bindings (WebIDL) component can be exploited remotely to cause denial of service.
- Information disclosure vulnerability in the Graphics: ImageLib component can be exploited to obtain sensitive information.
- Denial of service vulnerability in the Disability Access APIs component can be exploited remotely to cause denial of service.
- Denial of service vulnerability in the JavaScript: WebAssembly component can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
- Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Content Processes component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Privacy component in Firefox for Android can be exploited to obtain sensitive information.
- Information disclosure vulnerability in the Framework component in DevTools can be exploited to obtain sensitive information.
- Denial of service vulnerability in the Graphics: WebGPU component can be exploited remotely to cause denial of service.
- Security vulnerability in the PDF Viewer component can be exploited to bypass security restrictions.
- Denial of service vulnerability in the DOM: Copy & Paste and Drag & Drop component can be exploited remotely to cause denial of service.
- Security vulnerability in the Networking component can be exploited to bypass security restrictions.
- Security vulnerability in the Networking: DNS component can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Service Workers component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Graphics: WebGPU component can be exploited to obtain sensitive information.
- A remote code execution vulnerability in the Libraries component in NSS can be exploited remotely to execute arbitrary code.
- Security vulnerability in the Enterprise Policies component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Storage: IndexedDB component can be exploited to obtain sensitive information.
- Denial of service vulnerability in the Audio/Video: GMP component can be exploited remotely to cause denial of service.
- Security vulnerability in the DOM: Security component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Audio/Video component can be exploited remotely to execute arbitrary code.
- Security vulnerability in WebExtensions can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the DOM: Security component can be exploited to obtain sensitive information.
- Security vulnerability in the Data Loss Prevention component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Graphics: ImageLib component can be exploited remotely to execute arbitrary code.
- Security UI vulnerability in the Address Bar component can be exploited to spoof user interface.
- Security UI vulnerability in Firefox for Android can be exploited to spoof user interface.
- Information disclosure vulnerability in the Networking: WebSockets component can be exploited to obtain sensitive information.
- A remote code execution vulnerability in the Audio/Video: Playback component can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in the Security: PSM component can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Firefox 153 can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Firefox ESR 140 can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Firefox ESR 115 can be exploited remotely to execute arbitrary code.
Fiches de renseignement originales
Liste CVE
- CVE-2026-16349 unknown
- CVE-2026-16350 unknown
- CVE-2026-16351 unknown
- CVE-2026-16352 unknown
- CVE-2026-16353 unknown
- CVE-2026-16354 unknown
- CVE-2026-16355 unknown
- CVE-2026-16356 unknown
- CVE-2026-16357 unknown
- CVE-2026-16358 unknown
- CVE-2026-16359 critical
- CVE-2026-16360 unknown
- CVE-2026-16362 unknown
- CVE-2026-16363 unknown
- CVE-2026-16364 unknown
- CVE-2026-16365 unknown
- CVE-2026-16366 unknown
- CVE-2026-16367 unknown
- CVE-2026-16368 unknown
- CVE-2026-16369 unknown
- CVE-2026-16370 unknown
- CVE-2026-16371 unknown
- CVE-2026-16372 unknown
- CVE-2026-16373 unknown
- CVE-2026-16374 unknown
- CVE-2026-16375 unknown
- CVE-2026-16376 unknown
- CVE-2026-16377 unknown
- CVE-2026-16378 unknown
- CVE-2026-16379 unknown
- CVE-2026-16380 unknown
- CVE-2026-16381 unknown
- CVE-2026-16382 unknown
- CVE-2026-16383 unknown
- CVE-2026-16384 unknown
- CVE-2026-16385 unknown
- CVE-2026-16386 unknown
- CVE-2026-16387 unknown
- CVE-2026-16388 unknown
- CVE-2026-16389 unknown
- CVE-2026-16390 unknown
- CVE-2026-16391 unknown
- CVE-2026-16392 unknown
- CVE-2026-16393 unknown
- CVE-2026-16394 critical
- CVE-2026-16395 critical
- CVE-2026-16396 unknown
- CVE-2026-16397 high
- CVE-2026-16398 unknown
- CVE-2026-16399 unknown
- CVE-2026-16400 unknown
- CVE-2026-16401 unknown
- CVE-2026-16402 unknown
- CVE-2026-16403 unknown
- CVE-2026-16404 unknown
- CVE-2026-16405 critical
- CVE-2026-16406 critical
- CVE-2026-16407 unknown
- CVE-2026-16408 critical
- CVE-2026-16409 unknown
- CVE-2026-16410 unknown
- CVE-2026-16411 critical
- CVE-2026-16412 critical
En savoir plus
Découvrez les statistiques de la propagation des vulnérabilités dans votre région statistics.securelist.com
Vous avez trouvé une inexactitude dans la description de cette vulnérabilité ? Faites-le nous savoir !