Kaspersky ID:
KLA91164
Date de la détection:
07/21/2026
Mis à jour:
07/22/2026

Description

Multiple vulnerabilities were found in Mozilla Firefox. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
  2. Denial of service vulnerability in the Audio/Video: cubeb component can be exploited remotely to cause denial of service.
  3. A remote code execution vulnerability in the WebRTC: Audio/Video component can be exploited remotely to execute arbitrary code.
  4. A remote code execution vulnerability in the DOM: Navigation component can be exploited remotely to execute arbitrary code.
  5. A remote code execution vulnerability in the Disability Access APIs component can be exploited remotely to execute arbitrary code.
  6. Security vulnerability can be exploited to bypass security restrictions.
  7. Denial of service vulnerability in the Audio/Video: Playback component can be exploited remotely to cause denial of service.
  8. Security vulnerability in the DOM: Workers component can be exploited to bypass security restrictions.
  9. Denial of service vulnerability in the DOM: Bindings (WebIDL) component can be exploited remotely to cause denial of service.
  10. Information disclosure vulnerability in the Graphics: ImageLib component can be exploited to obtain sensitive information.
  11. Denial of service vulnerability in the Disability Access APIs component can be exploited remotely to cause denial of service.
  12. Denial of service vulnerability in the JavaScript: WebAssembly component can be exploited remotely to cause denial of service.
  13. A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
  14. Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
  15. Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
  16. Security vulnerability in the DOM: Content Processes component can be exploited to bypass security restrictions.
  17. Information disclosure vulnerability in the Privacy component in Firefox for Android can be exploited to obtain sensitive information.
  18. Information disclosure vulnerability in the Framework component in DevTools can be exploited to obtain sensitive information.
  19. Denial of service vulnerability in the Graphics: WebGPU component can be exploited remotely to cause denial of service.
  20. Security vulnerability in the PDF Viewer component can be exploited to bypass security restrictions.
  21. Denial of service vulnerability in the DOM: Copy & Paste and Drag & Drop component can be exploited remotely to cause denial of service.
  22. Security vulnerability in the Networking component can be exploited to bypass security restrictions.
  23. Security vulnerability in the Networking: DNS component can be exploited to bypass security restrictions.
  24. Security vulnerability in the DOM: Service Workers component can be exploited to bypass security restrictions.
  25. Information disclosure vulnerability in the Graphics: WebGPU component can be exploited to obtain sensitive information.
  26. A remote code execution vulnerability in the Libraries component in NSS can be exploited remotely to execute arbitrary code.
  27. Security vulnerability in the Enterprise Policies component can be exploited to bypass security restrictions.
  28. Information disclosure vulnerability in the Storage: IndexedDB component can be exploited to obtain sensitive information.
  29. Denial of service vulnerability in the Audio/Video: GMP component can be exploited remotely to cause denial of service.
  30. Security vulnerability in the DOM: Security component can be exploited to bypass security restrictions.
  31. A remote code execution vulnerability in the Audio/Video component can be exploited remotely to execute arbitrary code.
  32. Security vulnerability in WebExtensions can be exploited to bypass security restrictions.
  33. Information disclosure vulnerability in the DOM: Security component can be exploited to obtain sensitive information.
  34. Security vulnerability in the Data Loss Prevention component can be exploited to bypass security restrictions.
  35. A remote code execution vulnerability in the Graphics: ImageLib component can be exploited remotely to execute arbitrary code.
  36. Security UI vulnerability in the Address Bar component can be exploited to spoof user interface.
  37. Security UI vulnerability in Firefox for Android can be exploited to spoof user interface.
  38. Information disclosure vulnerability in the Networking: WebSockets component can be exploited to obtain sensitive information.
  39. A remote code execution vulnerability in the Audio/Video: Playback component can be exploited remotely to execute arbitrary code.
  40. Denial of service vulnerability in the Security: PSM component can be exploited remotely to cause denial of service.
  41. A remote code execution vulnerability in Firefox 153 can be exploited remotely to execute arbitrary code.
  42. A remote code execution vulnerability in Firefox ESR 140 can be exploited remotely to execute arbitrary code.
  43. A remote code execution vulnerability in Firefox ESR 115 can be exploited remotely to execute arbitrary code.

Fiches de renseignement originales

Liste CVE

  • CVE-2026-16349
    unknown
  • CVE-2026-16350
    unknown
  • CVE-2026-16351
    unknown
  • CVE-2026-16352
    unknown
  • CVE-2026-16353
    unknown
  • CVE-2026-16354
    unknown
  • CVE-2026-16355
    unknown
  • CVE-2026-16356
    unknown
  • CVE-2026-16357
    unknown
  • CVE-2026-16358
    unknown
  • CVE-2026-16359
    critical
  • CVE-2026-16360
    unknown
  • CVE-2026-16362
    unknown
  • CVE-2026-16363
    unknown
  • CVE-2026-16364
    unknown
  • CVE-2026-16365
    unknown
  • CVE-2026-16366
    unknown
  • CVE-2026-16367
    unknown
  • CVE-2026-16368
    unknown
  • CVE-2026-16369
    unknown
  • CVE-2026-16370
    unknown
  • CVE-2026-16371
    unknown
  • CVE-2026-16372
    unknown
  • CVE-2026-16373
    unknown
  • CVE-2026-16374
    unknown
  • CVE-2026-16375
    unknown
  • CVE-2026-16376
    unknown
  • CVE-2026-16377
    unknown
  • CVE-2026-16378
    unknown
  • CVE-2026-16379
    unknown
  • CVE-2026-16380
    unknown
  • CVE-2026-16381
    unknown
  • CVE-2026-16382
    unknown
  • CVE-2026-16383
    unknown
  • CVE-2026-16384
    unknown
  • CVE-2026-16385
    unknown
  • CVE-2026-16386
    unknown
  • CVE-2026-16387
    unknown
  • CVE-2026-16388
    unknown
  • CVE-2026-16389
    unknown
  • CVE-2026-16390
    unknown
  • CVE-2026-16391
    unknown
  • CVE-2026-16392
    unknown
  • CVE-2026-16393
    unknown
  • CVE-2026-16394
    critical
  • CVE-2026-16395
    critical
  • CVE-2026-16396
    unknown
  • CVE-2026-16397
    high
  • CVE-2026-16398
    unknown
  • CVE-2026-16399
    unknown
  • CVE-2026-16400
    unknown
  • CVE-2026-16401
    unknown
  • CVE-2026-16402
    unknown
  • CVE-2026-16403
    unknown
  • CVE-2026-16404
    unknown
  • CVE-2026-16405
    critical
  • CVE-2026-16406
    critical
  • CVE-2026-16407
    unknown
  • CVE-2026-16408
    critical
  • CVE-2026-16409
    unknown
  • CVE-2026-16410
    unknown
  • CVE-2026-16411
    critical
  • CVE-2026-16412
    critical

En savoir plus

Découvrez les statistiques de la propagation des vulnérabilités dans votre région statistics.securelist.com

Vous avez trouvé une inexactitude dans la description de cette vulnérabilité ? Faites-le nous savoir !
Kaspersky IT Security Calculator:
Calculez le profil de sécurité de votre entreprise
Apprendre encore plus
Kaspersky!
Votre vie en ligne mérite une protection complète!
Apprendre encore plus
Do you want to save your changes?
Your message has been sent successfully.