BrowserShield

Version security report

Firefox 151 security vulnerabilities

These public CVE records overlap Firefox major version 151. Matching is based on disclosed version ranges, not an exploit test.

382

public CVEs overlapping this major version

CVE list

CVE-2026-75874

Critical CVSS 10.0

Sandbox escape in the Remote Settings Client component.

Fixed in 154

CVE-2026-16367

Critical CVSS 10.0

Sandbox escape due to invalid pointer in the Disability Access APIs component.

Fixed in 153

CVE-2026-8956

Critical CVSS 9.8

Integer overflow in the Networking: JAR component.

Fixed in 151

CVE-2026-84143

Critical CVSS 9.8

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.

Fixed in 155

CVE-2026-84142

Critical CVSS 9.8

Internally found bugs present in Thunderbird 154.

Fixed in 155

CVE-2026-84141

Critical CVSS 9.8

Integer overflow in the Graphics: ImageLib component.

Fixed in 155

CVE-2026-84140

Critical CVSS 9.8

Site isolation issue in the DOM: Navigation component.

Fixed in 155

CVE-2026-84134

Critical CVSS 9.8

Other issue in the Profile Backup component.

Fixed in 155

CVE-2026-84133

Critical CVSS 9.8

Site isolation issue in the DOM: Push Subscriptions component.

Fixed in 155

CVE-2026-84129

Critical CVSS 9.8

Site isolation issue in the DOM: Navigation component.

Fixed in 155

CVE-2026-74990

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 140.

Fixed in 154

CVE-2026-74989

Critical CVSS 9.8

Internally found bugs present in Thunderbird 153.

Fixed in 154

CVE-2026-74988

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 153.

Fixed in 154

CVE-2026-74987

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 140.

Fixed in 154

CVE-2026-74985

Critical CVSS 9.8

Privilege escalation in the Enterprise Policies component.

Fixed in 154

CVE-2026-74979

Critical CVSS 9.8

Mitigation bypass in the Add-ons Manager component.

Fixed in 154

CVE-2026-74964

Critical CVSS 9.8

Integer overflow in the Graphics component.

Fixed in 154

CVE-2026-74944

Critical CVSS 9.8

Use-after-free in the DOM: Core & HTML component.

Fixed in 154

CVE-2026-74943

Critical CVSS 9.8

Use-after-free in the Graphics: ImageLib component.

Fixed in 154

CVE-2026-74940

Critical CVSS 9.8

Use-after-free in the Graphics: Text component.

Fixed in 154

CVE-2026-74936

Critical CVSS 9.8

Use-after-free in the JavaScript: WebAssembly component.

Fixed in 154

CVE-2026-16412

Critical CVSS 9.8

Memory safety bugs present in Firefox ESR 140.

Fixed in 153

CVE-2026-16411

Critical CVSS 9.8

Memory safety bugs present in Firefox 152.

Fixed in 153

CVE-2026-16410

Critical CVSS 9.8

JIT miscompilation in the JavaScript Engine: JIT component.

Fixed in 153

CVE-2026-16408

Critical CVSS 9.8

Integer overflow in the Audio/Video: Playback component.

Fixed in 153

CVE-2026-16407

Critical CVSS 9.8

Mitigation bypass in the DOM: Service Workers component.

Fixed in 153

CVE-2026-16402

Critical CVSS 9.8

Integer overflow in the Graphics: ImageLib component.

Fixed in 153

CVE-2026-16395

Critical CVSS 9.8

Integer overflow in the Audio/Video component.

Fixed in 153

CVE-2026-16389

Critical CVSS 9.8

Incorrect boundary conditions, integer overflow in the Libraries component in NSS.

Fixed in 153

CVE-2026-16388

Critical CVSS 9.8

Sandbox escape in the DOM: Networking component.

Fixed in 153

CVE-2026-16387

Critical CVSS 9.8

Site isolation issue in the Networking component.

Fixed in 153

CVE-2026-16383

Critical CVSS 9.8

Mitigation bypass in the DOM: Networking component.

Fixed in 153

CVE-2026-16382

Critical CVSS 9.8

Mitigation bypass in the DOM: Service Workers component.

Fixed in 153

CVE-2026-16377

Critical CVSS 9.8

Mitigation bypass in the PDF Viewer component.

Fixed in 153

CVE-2026-16375

Critical CVSS 9.8

Site isolation issue in the Networking: HTTP component.

Fixed in 153

CVE-2026-16369

Critical CVSS 9.8

Integer overflow in the JavaScript: WebAssembly component.

Fixed in 153

CVE-2026-16368

Critical CVSS 9.8

Incorrect boundary conditions in the JavaScript: WebAssembly component.

Fixed in 153

CVE-2026-16363

Critical CVSS 9.8

JIT miscompilation in the JavaScript: WebAssembly component.

Fixed in 153

CVE-2026-16360

Critical CVSS 9.8

Memory safety bugs present in Firefox ESR 115.

Fixed in 153

CVE-2026-16358

Critical CVSS 9.8

Site isolation issue in the Graphics: WebRender component.

Fixed in 153

CVE-2026-16357

Critical CVSS 9.8

Incorrect boundary conditions in the Graphics component.

Fixed in 153

CVE-2026-16356

Critical CVSS 9.8

Sandbox escape due to use-after-free in the Disability Access APIs component.

Fixed in 153

CVE-2026-16355

Critical CVSS 9.8

JIT miscompilation in the JavaScript Engine: JIT component.

Fixed in 153

CVE-2026-16353

Critical CVSS 9.8

Invalid pointer in the DOM: Bindings (WebIDL) component.

Fixed in 153

CVE-2026-16352

Critical CVSS 9.8

Sandbox escape due to use-after-free in the Disability Access APIs component.

Fixed in 153

CVE-2026-16351

Critical CVSS 9.8

Sandbox escape due to use-after-free in the DOM: Navigation component.

Fixed in 153

CVE-2026-16350

Critical CVSS 9.8

Incorrect boundary conditions in the Audio/Video: cubeb component.

Fixed in 153

CVE-2026-16349

Critical CVSS 9.8

Same-origin policy bypass in the DOM: Navigation component.

Fixed in 153

CVE-2026-12293

Critical CVSS 9.8

Use-after-free in the Graphics: WebGPU component.

Fixed in 152

CVE-2026-8959

Critical CVSS 9.6

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.

Fixed in 151

CVE-2026-8953

Critical CVSS 9.6

Sandbox escape due to use-after-free in the Disability Access APIs component.

Fixed in 151

CVE-2026-84121

Critical CVSS 9.6

Sandbox escape due to use-after-free in the DOM: Security component.

Fixed in 155

CVE-2026-84119

Critical CVSS 9.6

Sandbox escape due to use-after-free in the DOM: Navigation component.

Fixed in 155

CVE-2026-12297

Critical CVSS 9.6

Sandbox escape due to incorrect boundary conditions in the Networking component.

Fixed in 152

CVE-2026-12296

Critical CVSS 9.6

Sandbox escape in the Security: Process Sandboxing component.

Fixed in 152

CVE-2026-12295

Critical CVSS 9.6

Sandbox escape in the DOM: Navigation component.

Fixed in 152

CVE-2026-12294

Critical CVSS 9.6

Sandbox escape in the DOM: Workers component.

Fixed in 152

CVE-2026-8950

Critical CVSS 9.3

Same-origin policy bypass in the Networking: HTTP component.

Fixed in 151

CVE-2026-8948

Critical CVSS 9.1

Same-origin policy bypass in the DOM: Networking component.

Fixed in 151

CVE-2026-74986

Critical CVSS 9.1

Site isolation issue in the CSS Parsing and Computation component.

Fixed in 154

Showing the highest-severity 60 of 382 records.

Check my browser