77
public CVEs overlapping this major version
- Critical0
- High38
- Medium30
- Low9
Version security report
These public CVE records overlap Firefox major version 157. Matching is based on disclosed version ranges, not an exploit test.
77
public CVEs overlapping this major version
High
JIT miscompilation in the JavaScript Engine component
Fixed in 157
High
JIT miscompilation in the JavaScript: WebAssembly component
Fixed in 157
High
Use-after-free in the DOM: Core & HTML component
Fixed in 157
High
Use-after-free in the XSLT component
Fixed in 157
High
Use-after-free in the Graphics: Canvas2D component
Fixed in 157
High
Invalid pointer in the JavaScript: WebAssembly component
Fixed in 157
High
Sandbox escape in the XUL component
Fixed in 157
High
Sandbox escape due to use-after-free in the Graphics component
Fixed in 157
High
Use-after-free in the DOM: Core & HTML component
Fixed in 157
High
Use-after-free in the Layout: Text and Fonts component
Fixed in 157
High
Uninitialized memory in the Audio/Video component
Fixed in 157
High
Privilege escalation due to incorrect boundary conditions in the Graphics component
Fixed in 157
High
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
Fixed in 157
High
Use-after-free in the DOM: Core & HTML component
Fixed in 157
High
Use-after-free in the XSLT component
Fixed in 157
High
Sandbox escape due to use-after-free in the DOM: Core & HTML component
Fixed in 157
High
Use-after-free in the Graphics: Canvas2D component
Fixed in 157
High
Use-after-free in the JavaScript: WebAssembly component
Fixed in 157
High
Sandbox escape in the Graphics component
Fixed in 157
High
Use-after-free in the DOM: Core & HTML component
Fixed in 157
High
Use-after-free in the Storage: IndexedDB component
Fixed in 157
High
Use-after-free in the DOM: Core & HTML component
Fixed in 157
High
Undefined behavior in the DOM: Streams component
Fixed in 157
High
Sandbox escape due to use-after-free in the DOM: Content Processes component
Fixed in 157
High
Use-after-free in the JavaScript: WebAssembly component
Fixed in 157
High
Use-after-free in the Graphics: WebGPU component
Fixed in 157
High
Use-after-free in the Networking: Cache component
Fixed in 157
High
Information disclosure in the Networking: JAR component
Fixed in 157
High
Use-after-free in the JavaScript: WebAssembly component
Fixed in 157
High
Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component
Fixed in 157
High
Incorrect boundary conditions in the Graphics: WebGPU component
Fixed in 157
High
Sandbox escape due to use-after-free in the DOM: Content Processes component
Fixed in 157
High
Privilege escalation due to use-after-free in the Graphics: WebGPU component
Fixed in 157
High
Sandbox escape in the Security: Process Sandboxing component
Fixed in 157
High
Uninitialized memory in the Storage: Quota Manager component
Fixed in 157
High
Sandbox escape in the DOM: Navigation component
Fixed in 157
High
Use-after-free in the Widget component
Fixed in 157
High
Incorrect boundary conditions in the Audio/Video: Playback component
Fixed in 157
Medium CVSS 6.1
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code.
Medium
Information disclosure in the Networking component
Fixed in 157
Medium
Site isolation issue in the Panning and Zooming component
Fixed in 157
Medium
Privilege escalation in the Address Bar component
Fixed in 157
Medium
Sandbox escape due to incorrect boundary conditions in the XPCOM component
Fixed in 157
Medium
Sandbox escape due to use-after-free in the Widget: Gtk component
Fixed in 157
Medium
Other issue in the JavaScript: WebAssembly component
Fixed in 157
Medium
Site isolation issue in the DOM: Networking component
Fixed in 157
Medium
Use-after-free in the CSS Parsing and Computation component
Fixed in 157
Medium
Incorrect boundary conditions in the JavaScript Engine: JIT component
Fixed in 157
Medium
Invalid pointer in the JavaScript Engine: JIT component
Fixed in 157
Medium
Denial-of-service in the Graphics component
Fixed in 157
Medium
Sandbox escape due to use-after-free in the DOM: Core & HTML component
Fixed in 157
Medium
Other issue in the DevTools component
Fixed in 157
Medium
Same-origin policy bypass in the DevTools component
Fixed in 157
Medium
Mitigation bypass in the DOM: Service Workers component
Fixed in 157
Medium
Privilege escalation in the DOM: Service Workers component
Fixed in 157
Medium
Uninitialized memory in the Graphics: WebGPU component
Fixed in 157
Medium
Race condition, use-after-free in the Audio/Video component
Fixed in 157
Medium
Sandbox escape due to use-after-free in the Preferences: Backend component
Fixed in 157
Medium
Same-origin policy bypass in the WebExtensions component
Fixed in 157
Medium
Uninitialized memory in the Graphics: WebGPU component
Fixed in 157
Showing the highest-severity 60 of 77 records.