Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-60316] X Plugin unspecified vulnerability (CPU Jul 2026)
X Plugin unspecified vulnerability (CPU Jul 2026). Red Hat rates this important (CVSS 7.2). Weakness: CWE-648.
Medium [CVE-2026-12548] heap out-of-bounds read in libsoup due to integer truncation
A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application using libsoup or potentially disclose heap memory contents. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
Medium [CVE-2026-16401] Privilege escalation in the Data Loss Prevention component
Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-16402] Integer overflow in the Graphics: ImageLib component
Integer overflow in the Graphics: ImageLib component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190.
Medium [CVE-2026-16400] Information disclosure in the DOM: Security component
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-16399] Site isolation issue in the DOM: Navigation component
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-16398] Site isolation issue in the Graphics component
Site isolation issue in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-653.
Medium [CVE-2026-16397] Clickjacking issue in the WebExtensions component in Firefox for Android
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-16395] Integer overflow in the Audio/Video component
Integer overflow in the Audio/Video component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190.
Medium [CVE-2026-16394] Mitigation bypass in the DOM: Security component
Mitigation bypass in the DOM: Security component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-358.
Medium [CVE-2026-16393] Incorrect boundary conditions in the Graphics: WebGPU component
Incorrect boundary conditions in the Graphics: WebGPU component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.
Medium [CVE-2026-16392] JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-733.
Medium [CVE-2026-16389] Incorrect boundary conditions, integer overflow in the Libraries component in NSS
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787.
Medium [CVE-2026-16388] Sandbox escape in the DOM: Networking component
Sandbox escape in the DOM: Networking component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-653.
Medium [CVE-2026-16386] Information disclosure due to uninitialized memory in the Graphics: WebGPU component
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-824.
Medium [CVE-2026-16382] Mitigation bypass in the DOM: Service Workers component
Mitigation bypass in the DOM: Service Workers component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-807.
Medium [CVE-2026-16380] Mitigation bypass in the Networking component
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-16378] Other issue in the DOM: Copy & Paste and Drag & Drop component
Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-16376] Denial-of-service in the Graphics: WebGPU component
Denial-of-service in the Graphics: WebGPU component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-770.
Medium [CVE-2026-16373] Information disclosure in the Privacy component in Firefox for Android
Information disclosure in the Privacy component in Firefox for Android. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-201.