CVE-2026-12317 Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. cve.org/CVERecord?id=CVE-202…
CVE-2026-12318 Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152. cve.org/CVERecord?id=CVE-202…
CVE-2026-12319 Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. cve.org/CVERecord?id=CVE-202…
CVE-2026-12320 Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. cve.org/CVERecord?id=CVE-202…
CVE-2026-12321 JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. cve.org/CVERecord?id=CVE-202…
CVE-2026-12322 Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. cve.org/CVERecord?id=CVE-202…
CVE-2026-12323 Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. cve.org/CVERecord?id=CVE-202…
CVE-2026-12324 Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbir… cve.org/CVERecord?id=CVE-202…
CVE-2026-12325 Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thund… cve.org/CVERecord?id=CVE-202…
CVE-2026-12326 Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of … cve.org/CVERecord?id=CVE-202…
CVE-2026-12327 Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and… cve.org/CVERecord?id=CVE-202…
CVE-2026-12328 Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of m… cve.org/CVERecord?id=CVE-202…
CVE-2026-12329 Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. cve.org/CVERecord?id=CVE-202…
CVE-2026-12330 Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12. cve.org/CVERecord?id=CVE-202…
CVE-2026-53899 Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging to the … cve.org/CVERecord?id=CVE-202…
CVE-2026-53900 Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrar… cve.org/CVERecord?id=CVE-202…
CVE-2026-11317 A denial of service security issue exists in the
affected product. The security issue stems from a fault occurring when a
crafted CIP message is sent. Devices with le… cve.org/CVERecord?id=CVE-202…
CVE-2026-10636 In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the packet via net_pkt_iface(pkt) after the packet ha… cve.org/CVERecord?id=CVE-202…
CVE-2026-10637 subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the network stack's ownership… cve.org/CVERecord?id=CVE-202…
CVE-2026-10638 subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_request() and net_ic… cve.org/CVERecord?id=CVE-202…