Описание
Multiple vulnerabilities were found in Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.
Below is a complete list of vulnerabilities:
- Denial of service vulnerability in the JavaScript: WebAssembly component can be exploited remotely to cause denial of service.
- Security vulnerability can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
- Denial of service vulnerability in the Audio/Video: cubeb component can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in the WebRTC: Audio/Video component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Navigation component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the Disability Access APIs component can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in the DOM: Bindings (WebIDL) component can be exploited remotely to cause denial of service.
- Information disclosure vulnerability in the Graphics: ImageLib component can be exploited to obtain sensitive information.
- A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
- Information disclosure vulnerability in the Framework component in DevTools can be exploited to obtain sensitive information.
- Security vulnerability in the PDF Viewer component can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Content Processes component can be exploited to bypass security restrictions.
- Security vulnerability in the Networking: DNS component can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
- Security vulnerability in the Enterprise Policies component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Storage: IndexedDB component can be exploited to obtain sensitive information.
- Denial of service vulnerability in the Audio/Video: GMP component can be exploited remotely to cause denial of service.
- Security vulnerability in WebExtensions can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Networking: WebSockets component can be exploited to obtain sensitive information.
- A remote code execution vulnerability in Firefox ESR 140 can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Firefox ESR 115 can be exploited remotely to execute arbitrary code.
Первичный источник обнаружения
Эксплуатация
Список CVE
- CVE-2026-15718 warning
- CVE-2026-15719 high
- CVE-2026-16349 unknown
- CVE-2026-16350 unknown
- CVE-2026-16351 unknown
- CVE-2026-16352 unknown
- CVE-2026-16353 unknown
- CVE-2026-16354 unknown
- CVE-2026-16355 unknown
- CVE-2026-16356 unknown
- CVE-2026-16357 unknown
- CVE-2026-16358 unknown
- CVE-2026-16359 critical
- CVE-2026-16360 unknown
- CVE-2026-16361 critical
- CVE-2026-16362 unknown
- CVE-2026-16363 unknown
- CVE-2026-16368 unknown
- CVE-2026-16369 unknown
- CVE-2026-16371 unknown
- CVE-2026-16374 unknown
- CVE-2026-16375 unknown
- CVE-2026-16377 unknown
- CVE-2026-16379 unknown
- CVE-2026-16381 unknown
- CVE-2026-16383 unknown
- CVE-2026-16387 unknown
- CVE-2026-16390 unknown
- CVE-2026-16391 unknown
- CVE-2026-16396 unknown
- CVE-2026-16405 critical
- CVE-2026-16412 critical
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!