﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
22851	firefox-140.8.0 spidermonkey	Douglas R. Reno	blfs-book	"New minor version

This contains **37** security fixes! This is in the JavaScript engine as well as Firefox itself, with numerous types of issues as well.

- CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component (High)
- CVE-2026-2758: Use-after-free in the JavaScript: GC component (High)
- CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component (High)
- CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component (High)
- CVE-2026-2761: Sandbox escape in the Graphics: WebRender component (High)
- CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component (High)
- CVE-2026-2763: Use-after-free in the JavaScript Engine component (High)
- CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component (High)
- CVE-2026-2765: Use-after-free in the JavaScript Engine component (High)
- CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component (High)
- CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component (High)
- CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component (High)
- CVE-2026-2769: Use-after-free in the Storage: IndexedDB component (High)
- CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component (High)
- CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component (High)
- CVE-2026-2772: Use-after-free in the Audio/Video: Playback component (High)
- CVE-2026-2773: Incorrect boundary conditions in the Web Audio component (High)
- CVE-2026-2774: Integer overflow in the Audio/Video component (High)
- CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component (High)
- CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software (High)
- CVE-2026-2777: Privilege escalation in the Messaging System component (High)
- CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component (High)
- CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component (Moderate)
- CVE-2026-2780: Privilege escalation in the Netmonitor component (Moderate)
- CVE-2026-2781: Integer overflow in the Libraries component in NSS (Moderate)
- CVE-2026-2782: Privilege escalation in the Netmonitor component (Moderate)
- CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component (Moderate)
- CVE-2026-2784: Mitigation bypass in the DOM: Security component (Moderate)
- CVE-2026-2785: Invalid pointer in the JavaScript Engine component (Moderate)
- CVE-2026-2786: Use-after-free in the JavaScript Engine component (Moderate)
- CVE-2026-2787: Use-after-free in the DOM: Window and Location component (Moderate)
- CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component (Moderate)
- CVE-2026-2789: Use-after-free in the Graphics: ImageLib component (Moderate)
- CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component (Low)
- CVE-2026-2791: Mitigation bypass in the Networking: Cache component (Low)
- CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 (High)
- CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 (High)"	enhancement	closed	high	13.0	BOOK	git	critical	duplicate		
