Get real-time updates on Telegram
CVE-2026-100756, CVE-2026-100757, CVE-2026-100758 +59 more CVEs: firefox from 115.0 (inclusive), before 115.42.0 (exclusive), from 140.0.0 (inclusive), before…
CVE-2026-100756, CVE-2026-100757, CVE-2026-100758, CVE-2026-100759, CVE-2026-100760, CVE-2026-100762, CVE-2026-100765, CVE-2026-100766, CVE-2026-100767, CVE-2026-100769, CVE-2026-100770, CVE-2026-100771, CVE-2026-100772, CVE-2026-100773, CVE-2026-100774, CVE-2026-100775, CVE-2026-100776, CVE-2026-100777, CVE-2026-100778, CVE-2026-100779, CVE-2026-100780, CVE-2026-100781, CVE-2026-100782, CVE-2026-100783, CVE-2026-100784, CVE-2026-100785, CVE-2026-100786, CVE-2026-100787, CVE-2026-100788, CVE-2026-100789, CVE-2026-100790, CVE-2026-100791, CVE-2026-100792, CVE-2026-100794, CVE-2026-100797, CVE-2
CVE-2026-100756
Affected technology
firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100757
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100758
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100759
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100760
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100762
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100765
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100766
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100767
Affected technology
firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100769
Affected technology
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100770
Affected technology
firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100771
Affected technology
firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100772
Affected technology
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100773
Affected technology
firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100774
Affected technology
firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100775
Affected technology
firefox · from 115.0.1 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100776
Affected technology
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100777
Affected technology
firefox · from 115.0.1 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100778
Affected technology
firefox · from 115.0.1 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100779
Affected technology
firefox · before 157.0.0 (exclusive)
mozilla
firefox · from 115.1.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · before 157.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100780
Affected technology
firefox · before 157.0.0 (exclusive)
mozilla
firefox · from 115.1.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · before 157.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100781
Affected technology
firefox · before 157.0.0 (exclusive)
mozilla
firefox · from 115.1.0 (inclusive), before 115.42.0 (exclusive)
mozilla
firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · before 157.0 (exclusive)
mozilla
thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla
thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100782
Affected technology
firefox · before 115.42.0 (exclusive)
mozilla
firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100783
Affected technology
firefox · before 115.42.0 (exclusive)
mozilla
firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 4.3/10) rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100784
Affected technology
firefox · before 115.42.0 (exclusive)
mozilla
firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100785
Affected technology
firefox · before 115.42.0 (exclusive)
mozilla
firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100786
Affected technology
firefox · before 115.42.0 (exclusive)
mozilla
firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100787
Affected technology
firefox · before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100788
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100789
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100790
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100791
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100792
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality impact as high; integrity impact as low; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100794
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100797
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100798
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100800
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100801
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100803
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100806
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100807
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100808
Affected technology
firefox · before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100809
Affected technology
firefox · before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100811
Affected technology
firefox · before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100812
Affected technology
firefox · before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100814
Affected technology
firefox · before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100815
Affected technology
firefox · before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100816
Affected technology
firefox · before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100818
Affected technology
firefox · before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100819
Affected technology
firefox · before 115.42.0 (exclusive)
mozilla
firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100820
Affected technology
firefox · before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100821
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100822
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as low; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100824
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100825
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100826
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100828
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100829
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100830
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100831
Affected technology
Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-100832
Affected technology
firefox · before 115.42.0 (exclusive)
mozilla
firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
CVE-2026-96869
Affected technology
firefox · before 140.17.0 (exclusive)
mozilla
firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla
thunderbird · before 140.17.0 (exclusive)
mozilla
thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla
thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 4.3/10) rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
- CVE
- CVE-2026-100759, CVE-2026-100760, CVE-2026-100762, CVE-2026-100765, CVE-2026-100766, CVE-2026-100767, CVE-2026-100769, CVE-2026-100770, CVE-2026-100771, CVE-2026-100772, CVE-2026-100773, CVE-2026-100774, CVE-2026-100775, CVE-2026-100776, CVE-2026-100777, CVE-2026-100778, CVE-2026-100779, CVE-2026-100780, CVE-2026-100781, CVE-2026-100782, CVE-2026-100783, CVE-2026-100784, CVE-2026-100785, CVE-2026-100786, CVE-2026-100787, CVE-2026-100788, CVE-2026-100789, CVE-2026-100790, CVE-2026-100791, CVE-2026-100792, CVE-2026-100794, CVE-2026-100797, CVE-2026-100798, CVE-2026-100800, CVE-2026-100801, CVE-2026-100803, CVE-2026-100806, CVE-2026-100807, CVE-2026-100808, CVE-2026-100809, CVE-2026-100811, CVE-2026-100812, CVE-2026-100814, CVE-2026-100815, CVE-2026-100816, CVE-2026-100818, CVE-2026-100819, CVE-2026-100820, CVE-2026-100821, CVE-2026-100822, CVE-2026-100824, CVE-2026-100825, CVE-2026-100826, CVE-2026-100828, CVE-2026-100829, CVE-2026-100830, CVE-2026-100831, CVE-2026-100832, CVE-2026-96869
- CWE
- CWE-20, CWE-119, CWE-200, CWE-269, CWE-346, CWE-416, CWE-457, CWE-693, CWE-758, CWE-770
- Product
- MozillaFirefox
- CCR priority
- 32.5 /100 (P4)
- CVSS 3.1
- 8.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N · Source advisory
- EPSS
- 0.00329 · percentile 0.23728 · 2026-10-05
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-06 17:55:17.257073+00:00 UTC
- OSV.dev · Source record · observed 2026-10-06 17:58:42.508367+00:00 UTC
- OSV.dev · Source record · observed 2026-10-06 17:58:42.508367+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-100756.html