|
21
|
7.5 |
HIGH
Network
|
-
|
-
|
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-8968
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
- |
|
-
|
-
|
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
-
|
CVE-2026-8967
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
- |
|
-
|
-
|
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
-
|
CVE-2026-8966
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
- |
|
-
|
-
|
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
-
|
CVE-2026-8965
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
7.5 |
HIGH
Network
|
-
|
-
|
Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8964
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
7.5 |
HIGH
Network
|
-
|
-
|
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8963
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
- |
|
-
|
-
|
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
-
|
CVE-2026-8962
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
- |
|
-
|
-
|
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
-
|
CVE-2026-8961
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
7.5 |
HIGH
Network
|
-
|
-
|
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8960
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-20 CWE-119 CWE-693
Improper Input Validation Incorrect Access of Indexable Resource ('Range Error') Protection Mechanism Failure
|
CVE-2026-8959
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|