345
public CVEs overlapping this major version
- Critical73
- High137
- Medium102
- Low33
Version security report
These public CVE records overlap Firefox major version 152. Matching is based on disclosed version ranges, not an exploit test.
345
public CVEs overlapping this major version
Critical CVSS 10.0
Sandbox escape in the Remote Settings Client component.
Fixed in 154
Critical CVSS 10.0
Sandbox escape due to invalid pointer in the Disability Access APIs component.
Fixed in 153
Critical CVSS 9.8
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.
Fixed in 155
Critical CVSS 9.8
Internally found bugs present in Thunderbird 154.
Fixed in 155
Critical CVSS 9.8
Integer overflow in the Graphics: ImageLib component.
Fixed in 155
Critical CVSS 9.8
Site isolation issue in the DOM: Navigation component.
Fixed in 155
Critical CVSS 9.8
Other issue in the Profile Backup component.
Fixed in 155
Critical CVSS 9.8
Site isolation issue in the DOM: Push Subscriptions component.
Fixed in 155
Critical CVSS 9.8
Site isolation issue in the DOM: Navigation component.
Fixed in 155
Critical CVSS 9.8
Internally found bugs present in Thunderbird ESR 140.
Fixed in 154
Critical CVSS 9.8
Internally found bugs present in Thunderbird 153.
Fixed in 154
Critical CVSS 9.8
Internally found bugs present in Thunderbird ESR 153.
Fixed in 154
Critical CVSS 9.8
Internally found bugs present in Thunderbird ESR 140.
Fixed in 154
Critical CVSS 9.8
Privilege escalation in the Enterprise Policies component.
Fixed in 154
Critical CVSS 9.8
Mitigation bypass in the Add-ons Manager component.
Fixed in 154
Critical CVSS 9.8
Integer overflow in the Graphics component.
Fixed in 154
Critical CVSS 9.8
Use-after-free in the DOM: Core & HTML component.
Fixed in 154
Critical CVSS 9.8
Use-after-free in the Graphics: ImageLib component.
Fixed in 154
Critical CVSS 9.8
Use-after-free in the Graphics: Text component.
Fixed in 154
Critical CVSS 9.8
Use-after-free in the JavaScript: WebAssembly component.
Fixed in 154
Critical CVSS 9.8
Memory safety bugs present in Firefox ESR 140.
Fixed in 153
Critical CVSS 9.8
Memory safety bugs present in Firefox 152.
Fixed in 153
Critical CVSS 9.8
JIT miscompilation in the JavaScript Engine: JIT component.
Fixed in 153
Critical CVSS 9.8
Integer overflow in the Audio/Video: Playback component.
Fixed in 153
Critical CVSS 9.8
Mitigation bypass in the DOM: Service Workers component.
Fixed in 153
Critical CVSS 9.8
Integer overflow in the Graphics: ImageLib component.
Fixed in 153
Critical CVSS 9.8
Integer overflow in the Audio/Video component.
Fixed in 153
Critical CVSS 9.8
Incorrect boundary conditions, integer overflow in the Libraries component in NSS.
Fixed in 153
Critical CVSS 9.8
Sandbox escape in the DOM: Networking component.
Fixed in 153
Critical CVSS 9.8
Site isolation issue in the Networking component.
Fixed in 153
Critical CVSS 9.8
Mitigation bypass in the DOM: Networking component.
Fixed in 153
Critical CVSS 9.8
Mitigation bypass in the DOM: Service Workers component.
Fixed in 153
Critical CVSS 9.8
Mitigation bypass in the PDF Viewer component.
Fixed in 153
Critical CVSS 9.8
Site isolation issue in the Networking: HTTP component.
Fixed in 153
Critical CVSS 9.8
Integer overflow in the JavaScript: WebAssembly component.
Fixed in 153
Critical CVSS 9.8
Incorrect boundary conditions in the JavaScript: WebAssembly component.
Fixed in 153
Critical CVSS 9.8
JIT miscompilation in the JavaScript: WebAssembly component.
Fixed in 153
Critical CVSS 9.8
Memory safety bugs present in Firefox ESR 115.
Fixed in 153
Critical CVSS 9.8
Site isolation issue in the Graphics: WebRender component.
Fixed in 153
Critical CVSS 9.8
Incorrect boundary conditions in the Graphics component.
Fixed in 153
Critical CVSS 9.8
Sandbox escape due to use-after-free in the Disability Access APIs component.
Fixed in 153
Critical CVSS 9.8
JIT miscompilation in the JavaScript Engine: JIT component.
Fixed in 153
Critical CVSS 9.8
Invalid pointer in the DOM: Bindings (WebIDL) component.
Fixed in 153
Critical CVSS 9.8
Sandbox escape due to use-after-free in the Disability Access APIs component.
Fixed in 153
Critical CVSS 9.8
Sandbox escape due to use-after-free in the DOM: Navigation component.
Fixed in 153
Critical CVSS 9.8
Incorrect boundary conditions in the Audio/Video: cubeb component.
Fixed in 153
Critical CVSS 9.8
Same-origin policy bypass in the DOM: Navigation component.
Fixed in 153
Critical CVSS 9.8
Memory safety bugs present in Firefox 152.
Fixed in 152.0.4
Critical CVSS 9.8
Use-after-free in the Graphics: WebGPU component.
Fixed in 152
Critical CVSS 9.6
Sandbox escape due to use-after-free in the DOM: Security component.
Fixed in 155
Critical CVSS 9.6
Sandbox escape due to use-after-free in the DOM: Navigation component.
Fixed in 155
Critical CVSS 9.6
Sandbox escape due to incorrect boundary conditions in the Networking component.
Fixed in 152
Critical CVSS 9.6
Sandbox escape in the Security: Process Sandboxing component.
Fixed in 152
Critical CVSS 9.6
Sandbox escape in the DOM: Navigation component.
Fixed in 152
Critical CVSS 9.6
Sandbox escape in the DOM: Workers component.
Fixed in 152
Critical CVSS 9.1
Site isolation issue in the CSS Parsing and Computation component.
Fixed in 154
Critical CVSS 9.1
Side-channel in the Web Audio component.
Fixed in 154
Critical CVSS 9.1
Mitigation bypass in the Storage: Cache API component.
Fixed in 154
Critical CVSS 9.1
Same-origin policy bypass in the DOM: Service Workers component.
Fixed in 154
Critical CVSS 9.1
Mitigation bypass in the JavaScript: GC component.
Fixed in 154
Showing the highest-severity 60 of 345 records.