BlackTreeCVE IntelligenceOfficial source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org
Security Vulnerabilities fixed in Firefox ESR 140.17 — Mozilla
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 14:38 UTC
Linked CVEs43
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-100821Site isolation issue in the Panning and Zooming component
- CVE-2026-100775Sandbox escape in the Graphics component
- CVE-2026-100781Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
- CVE-2026-100803Same-origin policy bypass in the WebExtensions component
- CVE-2026-100794Sandbox escape due to incorrect boundary conditions in the Internationalization component
- CVE-2026-100792JIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-100788Invalid pointer in the JavaScript: WebAssembly component
- CVE-2026-100771Undefined behavior in the DOM: Streams component
- CVE-2026-100759Uninitialized memory in the Storage: Quota Manager component
- CVE-2026-100756Incorrect boundary conditions in the Audio/Video: Playback component
- CVE-2026-100758Sandbox escape in the DOM: Navigation component
- CVE-2026-100820Privilege escalation in the Address Bar component
- CVE-2026-100819Sandbox escape due to incorrect boundary conditions in the XPCOM component
- CVE-2026-100818Sandbox escape due to use-after-free in the Widget: Gtk component
- CVE-2026-100811Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100807Privilege escalation in the DOM: Service Workers component
- CVE-2026-100801Privilege escalation in the DLL Services component
- CVE-2026-100797Privilege escalation due to use-after-free in the Graphics: WebRender component
- CVE-2026-96869Information disclosure in the Networking component
- CVE-2026-100832Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100791Use-after-free in the DOM: Core & HTML component
- CVE-2026-100790Use-after-free in the XSLT component
- CVE-2026-100789Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100786Sandbox escape due to use-after-free in the Graphics component
- CVE-2026-100785Use-after-free in the DOM: Core & HTML component
- CVE-2026-100784Use-after-free in the Layout: Text and Fonts component
- CVE-2026-100783Uninitialized memory in the Audio/Video component
- CVE-2026-100782Privilege escalation due to incorrect boundary conditions in the Graphics component
- CVE-2026-100780Use-after-free in the DOM: Core & HTML component
- CVE-2026-100779Use-after-free in the XSLT component
- CVE-2026-100778Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100777Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100776Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100774Use-after-free in the DOM: Core & HTML component
- CVE-2026-100773Use-after-free in the Storage: IndexedDB component
- CVE-2026-100772Use-after-free in the DOM: Core & HTML component
- CVE-2026-100770Sandbox escape due to use-after-free in the DOM: Content Processes component
- CVE-2026-100769Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100767Use-after-free in the Networking: Cache component
- CVE-2026-100766Information disclosure in the Networking: JAR component
- CVE-2026-100762Sandbox escape due to use-after-free in the DOM: Content Processes component
- CVE-2026-100757Use-after-free in the Widget component
- CVE-2026-92035Sandbox escape due to incorrect boundary conditions in the Graphics component
Source and provenance
Original title: Security Vulnerabilities fixed in Firefox ESR 140.17 — Mozilla. Captured 29 Sept 2026, 14:38 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗