Search CVE reports


Toggle filters

1 – 10 of 3498 results


CVE-2026-102633

Medium priority
Needs evaluation

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
expat Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
apache2 Not affected Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected Not affected
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vnc4 Not in release Not in release Not in release — Needs evaluation
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Not affected Not affected Not affected Not affected Needs evaluation
ayttm Not in release Not in release Not in release — —
cableswig Not in release Not in release Not in release — —
coin3 Not affected Not affected Not affected Not affected Needs evaluation
matanza Ignored Ignored Ignored Ignored Needs evaluation
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vtk Not in release Not in release Not in release — —
smart Not in release Not in release Not in release — Needs evaluation
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Not affected — —
libxmltok Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 23 packages Show less packages

CVE-2026-96869

Medium priority
Vulnerable

Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages

CVE-2026-100831

Medium priority
Vulnerable

Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages

CVE-2026-100830

Medium priority
Vulnerable

Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages

CVE-2026-100829

Medium priority
Vulnerable

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages

CVE-2026-100828

Medium priority
Vulnerable

Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages

CVE-2026-100826

Medium priority
Vulnerable

Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages

CVE-2026-100825

Medium priority
Vulnerable

Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages

CVE-2026-100824

Medium priority
Vulnerable

Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages

CVE-2026-100823

Medium priority
Vulnerable

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
thunderbird Not affected Not affected Vulnerable — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
Show all 9 packages Show less packages