
CVE-2026-84118-who-labeled-the-crit-as-a-high
Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

Proof-of-concept exploit for CVE-2026-6770 targeting Firefox and Tor browsers, demonstrating the vulnerability and enabling security researchers to…

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

A vulnerability scanner for Firefox and Thunderbird that checks if your versions are out of date and susceptible to CVE-2024-9680.

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process…

Full Firefox chain: CVE-2026-2796 wasm type confusion -> content-process RCE, plus CVE-2026-2768 parent-process escape analysis (both fixed in…

CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

CVE-2026-74970, Fission site isolation bypass in Firefox WebRender

Proof-of-concept exploit chain for Firefox JIT CVE-2026-2764, chaining JIT miscompilation and use-after-free into arbitrary read/write and WASM…

Hands-on lab for CVE-2024-4367, demonstrating PDF.js font rendering vulnerability exploitation in Firefox. Includes PoC generator, vulnerable and…

Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.

CVE-2018-12386 - Firefox Sandboxed RCE Exploit for Linux (Firefox <v62.0.3)

Exploit code for CVE-2016-9066

Critical CVE-2025-4322 exploit for Firefox on Windows enabling sandbox escape and arbitrary code execution. Includes download link and technical…

Hands-on lab to learn CVE-2024-4367 (Firefox PDF.js RCE) with PoC generation, vulnerable browser launch, and patched version verification.