<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Mozilla</title><description>Vulnerabilities across Mozilla Firefox, Thunderbird, and the shared Gecko/SpiderMonkey stack — the Mozilla Foundation Security Advisories (MFSA) cadence, browser-sandbox escapes, and the JavaScript-engine bugs that Pwn2Own and in-the-wild attackers keep finding. Combined article + CVE feed for the Mozilla beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2010-3765 — Mozilla Multiple Products Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2010-3765/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-3765/</guid><description>Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>critical</category><category>cve</category></item><item><title>CVE-2013-1675 — Mozilla Firefox Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2013-1675/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-1675/</guid><description>Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>medium</category><category>cve</category></item><item><title>CVE-2013-1690 — Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2013-1690/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-1690/</guid><description>Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>high</category><category>cve</category></item><item><title>CVE-2015-4495 — Mozilla Firefox Security Feature Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2015-4495/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-4495/</guid><description>Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>high</category><category>cve</category></item><item><title>CVE-2016-9079 — Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2016-9079/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-9079/</guid><description>Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>high</category><category>cve</category></item><item><title>CVE-2019-11707 — Mozilla Firefox and Thunderbird Type Confusion Vulnerability</title><link>https://0daynews.com/cve/cve-2019-11707/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-11707/</guid><description>Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>high</category><category>cve</category></item><item><title>CVE-2019-11708 — Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability</title><link>https://0daynews.com/cve/cve-2019-11708/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-11708/</guid><description>Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-17026 — Mozilla Firefox And Thunderbird Type Confusion Vulnerability</title><link>https://0daynews.com/cve/cve-2019-17026/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-17026/</guid><description>Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>high</category><category>cve</category></item><item><title>CVE-2020-6819 — Mozilla Firefox And Thunderbird Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2020-6819/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-6819/</guid><description>Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>high</category><category>cve</category></item><item><title>CVE-2020-6820 — Mozilla Firefox And Thunderbird Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2020-6820/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-6820/</guid><description>Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>high</category><category>cve</category></item><item><title>CVE-2022-26485 — Mozilla Firefox Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2022-26485/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-26485/</guid><description>Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>high</category><category>cve</category></item><item><title>CVE-2022-26486 — Mozilla Firefox Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2022-26486/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-26486/</guid><description>Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-9680 — Mozilla Firefox Use-After-Free Vulnerability</title><link>https://0daynews.com/cve/cve-2024-9680/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-9680/</guid><description>Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-10702 — JIT miscompilation in Firefox JavaScript engine allows renderer code execution</title><link>https://0daynews.com/cve/cve-2026-10702/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-10702/</guid><description>A JIT miscompilation in Firefox&apos;s JavaScript engine allows attackers to execute code in the browser renderer via a malicious webpage. Fixed in Firefox 151.0.3; also affected Tor Browser.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-15718 — Firefox JavaScript/WebAssembly invalid pointer with public exploit code</title><link>https://0daynews.com/cve/cve-2026-15718/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-15718/</guid><description>An invalid-pointer flaw in Firefox&apos;s JavaScript / WebAssembly component. Mozilla notes exploit code is public but no in-the-wild attacks are confirmed. Fixed in Firefox 152.0.6.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-15719 — Firefox DOM Navigation site-isolation flaw with public exploit code</title><link>https://0daynews.com/cve/cve-2026-15719/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-15719/</guid><description>A site-isolation flaw in Firefox&apos;s DOM Navigation component. Mozilla notes exploit code is public but no in-the-wild attacks are confirmed. Fixed in Firefox 152.0.6.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Mozilla</category><category>medium</category><category>cve</category></item><item><title>Firefox JIT Flaw Enables Tor Browser Code Execution</title><link>https://0daynews.com/articles/2026-07-29-firefox-jit-cve-2026-10702-tor-browser/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-firefox-jit-cve-2026-10702-tor-browser/</guid><description>CVE-2026-10702: a Firefox JIT miscompilation allowing renderer code execution via a single webpage visit. Fixed in Firefox 151.0.3; Tor Browser also affected.</description><pubDate>Wed, 29 Jul 2026 09:00:00 GMT</pubDate><category>Mozilla</category><category>article</category></item><item><title>Firefox exploit code public; Chrome, Adobe patch same day</title><link>https://0daynews.com/articles/2026-07-15-mozilla-firefox-exploit-public-chrome-adobe-coldfusion-patch-day/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-mozilla-firefox-exploit-public-chrome-adobe-coldfusion-patch-day/</guid><description>Mozilla says exploit code is public for two Firefox flaws fixed in 152.0.6. Chrome shipped Ozone use-after-free fixes; Adobe pushed 8 ColdFusion criticals.</description><pubDate>Wed, 15 Jul 2026 15:15:00 GMT</pubDate><category>Mozilla</category><category>article</category></item></channel></rss>