59
public CVEs overlapping this major version
- Critical0
- High20
- Medium27
- Low12
Version security report
These public CVE records overlap Firefox major version 154. Matching is based on disclosed version ranges, not an exploit test.
59
public CVEs overlapping this major version
High
Sandbox escape in the Remote Settings Client component
Fixed in 154
High
Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Fixed in 154
High
Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154
Fixed in 154
High
Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Fixed in 154
High
Privilege escalation due to use-after-free in the Graphics: Canvas2D component
Fixed in 154
High
Information disclosure in the Graphics component
Fixed in 154
High
Privilege escalation due to invalid pointer in the Graphics component
Fixed in 154
High
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Fixed in 154
High
Information disclosure in the Graphics: Text component
Fixed in 154
High
Use-after-free in the DOM: Core & HTML component
Fixed in 154
High
Use-after-free in the Graphics: ImageLib component
Fixed in 154
High
Privilege escalation in the Remote Settings Client component
Fixed in 154
High
Privilege escalation in the Graphics: CanvasWebGL component
Fixed in 154
High
Use-after-free in the Graphics: Text component
Fixed in 154
High
Privilege escalation in the DOM: Navigation component
Fixed in 154
High
Mitigation bypass in the JavaScript: GC component
Fixed in 154
High
Use-after-free in the JavaScript: GC component
Fixed in 154
High
Use-after-free in the JavaScript: WebAssembly component
Fixed in 154
High
Privilege escalation in the DOM: Networking component
Fixed in 154
High
Site isolation issue in the Graphics: CanvasWebGL component
Fixed in 154
Medium CVSS 6.1
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code.
Medium
Internally found bugs fixed in Firefox 154
Fixed in 154
Medium
Same-origin policy bypass in the Graphics: ImageLib component
Fixed in 154
Medium
Race condition, use-after-free in the Graphics component
Fixed in 154
Medium
Information disclosure in the DOM: Push Subscriptions component
Fixed in 154
Medium
Information disclosure in the DOM: UI Events & Focus Handling component
Fixed in 154
Medium
Site isolation issue in the Graphics component
Fixed in 154
Medium
Use-after-free in the Layout: Text and Fonts component
Fixed in 154
Medium
Site isolation issue in the Graphics: WebRender component
Fixed in 154
Medium
Same-origin policy bypass in the Audio/Video: Playback component
Fixed in 154
Medium
Information disclosure in the Form Autofill component
Fixed in 154
Medium
Privilege escalation in the Shell Integration component
Fixed in 154
Medium
Integer overflow in the Graphics component
Fixed in 154
Medium
Same-origin policy bypass in the Networking: Cookies component
Fixed in 154
Medium
Site isolation issue in the Networking: Cookies component
Fixed in 154
Medium
Side-channel in the Web Audio component
Fixed in 154
Medium
Site isolation issue in the WebExtensions component
Fixed in 154
Medium
Mitigation bypass in the Storage: Cache API component
Fixed in 154
Medium
Information disclosure in the WebRTC component
Fixed in 154
Medium
Mitigation bypass in the Safe Browsing component
Fixed in 154
Medium
Same-origin policy bypass in the DOM: Service Workers component
Fixed in 154
Medium
Privilege escalation in the Request Handling component
Fixed in 154
Medium
Information disclosure due to side-channel in the Storage: Cache API component
Fixed in 154
Medium
Privilege escalation in the Networking: Cookies component
Fixed in 154
Medium
Privilege escalation in the Application Update component
Fixed in 154
Medium
Clickjacking issue in Firefox for Android
Fixed in 154
Medium
Privilege escalation in the Downloads API component
Fixed in 154
Low
Site isolation issue in the CSS Parsing and Computation component
Fixed in 154
Low
Privilege escalation in the Enterprise Policies component
Fixed in 154
Low
Race condition in the JavaScript Engine component
Fixed in 154
Low
Mitigation bypass in the Data Loss Prevention component
Fixed in 154
Low
Denial-of-service in the Widget component
Fixed in 154
Low
Site isolation issue in the Audio/Video: Web Codecs component
Fixed in 154
Low
Clickjacking issue in the Downloads component in Firefox for Android
Fixed in 154
Low
Mitigation bypass in the Add-ons Manager component
Fixed in 154
Low
Clickjacking issue in the Widget component
Fixed in 154
Low
Integer overflow in the Graphics component
Fixed in 154
Low
JIT miscompilation in the JavaScript Engine: JIT component
Fixed in 154
Low
Spoofing issue in the Downloads component in Firefox for Android
Fixed in 154