An update for firefox is now available for Red Hat Enterprise Linux 10.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.
Security Fix(es):
* firefox: thunderbird: Site isolation issue in the DOM: Navigation component
(CVE-2026-15719)
* firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly
component (CVE-2026-15718)
* firefox: thunderbird: Mitigation bypass in the Enterprise Policies component
(CVE-2026-16390)
* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb
component (CVE-2026-16350)
* firefox: thunderbird: Information disclosure in the Storage: IndexedDB
component (CVE-2026-16391)
* firefox: thunderbird: Site isolation issue in the Networking: HTTP component
(CVE-2026-16375)
* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability
Access APIs component (CVE-2026-16356)
* firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly
component (CVE-2026-16363)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and
Firefox 153 (CVE-2026-16412)
* firefox: thunderbird: Same-origin policy bypass in the Networking: DNS
component (CVE-2026-16381)
* firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT
component (CVE-2026-16355)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and
Firefox ESR 140.13 (CVE-2026-16361)
* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability
Access APIs component (CVE-2026-16352)
* firefox: thunderbird: Incorrect boundary conditions in the JavaScript:
WebAssembly component (CVE-2026-16368)
* firefox: thunderbird: Mitigation bypass in the PDF Viewer component
(CVE-2026-16377)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox
ESR 140.13 and Firefox 153 (CVE-2026-16360)
* firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component
(CVE-2026-16362)
* firefox: thunderbird: Site isolation issue in the Graphics: WebRender
component (CVE-2026-16358)
* firefox: thunderbird: Site isolation issue in the Networking component
(CVE-2026-16387)
* firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation
component (CVE-2026-16349)
* firefox: thunderbird: Incorrect boundary conditions in the Graphics component
(CVE-2026-16357)
* firefox: thunderbird: Sandbox escape due to use-after-free in the DOM:
Navigation component (CVE-2026-16351)
* firefox: thunderbird: Privilege escalation in the DOM: Navigation component
(CVE-2026-16371)
* firefox: thunderbird: Privilege escalation in the DOM: Content Processes
component (CVE-2026-16379)
* firefox: thunderbird: Information disclosure in the Graphics: ImageLib
component (CVE-2026-16354)
* firefox: thunderbird: Information disclosure in the Framework component in
DevTools (CVE-2026-16374)
* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP
component (CVE-2026-16359)
* firefox: thunderbird: Mitigation bypass in the DOM: Networking component
(CVE-2026-16383)
* firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly
component (CVE-2026-16369)
* firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component
(CVE-2026-16353)
* firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396)
* firefox: thunderbird: Information disclosure in the Networking: WebSockets
component (CVE-2026-16405)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2026-15718
CVE-2026-15719: Trust Boundary Violation (CWE-501)
CVE-2026-16349: Origin Validation Error (CWE-346)
CVE-2026-16350
CVE-2026-16351: Expired Pointer Dereference (CWE-825)
CVE-2026-16352: Missing Release of Resource after Effective Lifetime (CWE-772)
CVE-2026-16353: NULL Pointer Dereference (CWE-476)
CVE-2026-16354: Insertion of Sensitive Information Into Sent Data (CWE-201)
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357: Out-of-bounds Write (CWE-787)
CVE-2026-16358: Context Switching Race Condition (CWE-368)
CVE-2026-16359: Buffer Copy without Checking Size of Input ('Classic Buffer
Overflow') (CWE-120)
CVE-2026-16360: Buffer Copy without Checking Size of Input ('Classic Buffer
Overflow') (CWE-120)
CVE-2026-16361
CVE-2026-16362: Expired Pointer Dereference (CWE-825)
CVE-2026-16363: Compiler Optimization Removal or Modification of
Security-critical Code (CWE-733)
CVE-2026-16368: Out-of-bounds Write (CWE-787)
CVE-2026-16369: Integer Overflow or Wraparound (CWE-190)
CVE-2026-16371: Incorrect Privilege Assignment (CWE-266)
CVE-2026-16374: Insertion of Sensitive Information Into Debugging Code
(CWE-215)
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379: Improper Isolation or Compartmentalization (CWE-653)
CVE-2026-16381: Origin Validation Error (CWE-346)
CVE-2026-16383: Reliance on Untrusted Inputs in a Security Decision (CWE-807)
CVE-2026-16387: Trust Boundary Violation (CWE-501)
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396: Incorrect Privilege Assignment (CWE-266)
CVE-2026-16405: Insertion of Sensitive Information Into Sent Data (CWE-201)
CVE-2026-16412: Out-of-bounds Write (CWE-787)
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Mehrere Probleme in firefox (Red Hat) | 0 | 10 | 29-07-2026 |
| 2 | Mehrere Probleme in Linux (Red Hat) | 0 | 5 | 08-07-2026 |
| 3 | Mehrere Probleme in chromium (Fedora) | 0 | 10 | 29-07-2026 |
| 4 | Mehrere Probleme in chromium (Fedora) | 0 | 10 | 29-07-2026 |
| 5 | Mehrere Probleme in nodejs (Red Hat) | 0 | 10 | 29-07-2026 |
| 6 | Mehrere Probleme in chromium (Fedora) | 0 | 5 | 18-07-2026 |
| 7 | Mehrere Probleme in chromium (Fedora) | 0 | 5 | 18-07-2026 |
| 8 | Mehrere Probleme in restic (Fedora) | 0 | 10 | 29-07-2026 |
| 9 | Mehrere Probleme in restic (Fedora) | 0 | 10 | 29-07-2026 |
| 10 | Mehrere Probleme in syslinux (Fedora) | 0 | 10 | 29-07-2026 |