SB2026082006 - Debian update for firefox-esr
Published: August 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 31 vulnerabilities.
1) Protection mechanism failure (CVE-ID: CVE-2026-74959)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Storage: Cache API component when handling cached web content. A remote attacker can trigger specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
2) Buffer overflow (CVE-ID: CVE-2026-74990)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when rendering content or handling browser operations. A remote attacker can trigger crafted browser interactions to execute arbitrary code.
Multiple internally found bugs are covered by this entry, and the advisory notes that some showed evidence of memory corruption or another security-relevant defect.
3) Buffer overflow (CVE-ID: CVE-2026-74987)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
The advisory states that some of the internally found bugs showed evidence of memory corruption or another security-relevant defect.
4) Protection mechanism failure (CVE-ID: CVE-2026-74983)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Data Loss Prevention component when processing web content. A remote attacker can trigger specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
5) Incorrect calculation (CVE-ID: CVE-2026-74976)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing crafted script content. A remote attacker can cause the browser to execute specially crafted script content to cause a denial of service.
User interaction is required to visit a specially crafted website or URL.
6) Improper access control (CVE-ID: CVE-2026-74974)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Graphics: ImageLib component when rendering content. A remote attacker can cause the browser to process crafted content to bypass the same-origin policy.
7) Use-after-free (CVE-ID: CVE-2026-74973)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a race condition leading to use-after-free in the Graphics component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
8) Information disclosure (CVE-ID: CVE-2026-74972)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the DOM: Push Subscriptions component when handling push subscription data. A remote attacker can trigger specially crafted web content to disclose sensitive information.
User interaction is required to visit a specially crafted website or URL.
9) Information disclosure (CVE-ID: CVE-2026-74971)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the DOM: UI Events & Focus Handling component when processing web content. A remote attacker can trigger specially crafted web content to disclose sensitive information.
10) Use-after-free (CVE-ID: CVE-2026-74969)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Layout: Text and Fonts component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
11) Origin validation error (CVE-ID: CVE-2026-74967)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Audio/Video: Playback component when processing media content. A remote attacker can cause the browser to handle specially crafted media content to bypass the same-origin policy.
User interaction is required to visit a specially crafted website or URL.
12) Improper privilege management (CVE-ID: CVE-2026-74965)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Shell Integration component when processing crafted content. A remote attacker can trigger specially crafted content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
13) Integer overflow (CVE-ID: CVE-2026-74964)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics component when rendering crafted web content. A remote attacker can cause the browser to process specially crafted web content to cause a denial of service.
User interaction is required to visit a specially crafted website or URL.
14) Origin validation error (CVE-ID: CVE-2026-74963)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to bypass the same-origin policy.
User interaction is required to visit a specially crafted website or URL.
15) Origin validation error (CVE-ID: CVE-2026-74962)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper isolation enforcement in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to bypass site isolation.
User interaction is required to visit a specially crafted website or URL.
16) Origin validation error (CVE-ID: CVE-2026-74960)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper isolation enforcement in the WebExtensions component when handling extension-related web content. A remote attacker can cause the browser to process specially crafted web content to bypass site isolation.
User interaction is required to visit a specially crafted website or URL.
17) Improper access control (CVE-ID: CVE-2026-74934)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to bypass site isolation.
18) Protection mechanism failure (CVE-ID: CVE-2026-74957)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Safe Browsing component when processing web content. A remote attacker can cause the browser to handle specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
19) Improper privilege management (CVE-ID: CVE-2026-74953)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
20) Use-after-free (CVE-ID: CVE-2026-74949)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when rendering web content. A remote attacker can cause the browser to process specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
21) Information disclosure (CVE-ID: CVE-2026-74948)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics component when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.
22) Buffer overflow (CVE-ID: CVE-2026-74946)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to escalate privileges.
23) Information disclosure (CVE-ID: CVE-2026-74945)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics: Text component when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.
24) Use-after-free (CVE-ID: CVE-2026-74944)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
25) Use-after-free (CVE-ID: CVE-2026-74943)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: ImageLib component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
26) Improper access control (CVE-ID: CVE-2026-74942)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Remote Settings Client component when processing remote settings data. A remote attacker can trigger crafted browser interactions to escalate privileges.
27) Improper privilege management (CVE-ID: CVE-2026-74941)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
28) Use-after-free (CVE-ID: CVE-2026-74940)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Text component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
29) Improper access control (CVE-ID: CVE-2026-74939)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted browser interactions to escalate privileges.
30) Use-after-free (CVE-ID: CVE-2026-74936)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
31) Improper access control (CVE-ID: CVE-2026-74935)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Networking component when handling web content. A remote attacker can trigger crafted browser interactions to escalate privileges.
Remediation
Install update from vendor's website.