PatchSiren

Mozilla CVE debriefs · Page 9

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Mozilla CVE published 2026-04-21

CVE-2026-6749

CVE-2026-6749 is a high-severity information disclosure vulnerability in the Firefox browser, caused by uninitialized memory in the Graphics: Canvas2D component. The vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. The CVSS score for this vulnerability is 7.5, indicating a high severity. The vulnerability was publicly disclosed on Apr [truncated]

CRITICAL Mozilla CVE published 2026-04-21

CVE-2026-6748

CVE-2026-6748 is a critical vulnerability in the Audio/Video: Web Codecs component of Firefox. The issue arises from uninitialized memory, which could potentially be exploited for code execution. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. The CVE was published on April 21, 2026, and last modified on June 30, 2026. The CVSS score for this vulne [truncated]

HIGH Mozilla CVE published 2026-04-21

CVE-2026-6747

CVE-2026-6747 is a use-after-free vulnerability in the WebRTC component of Firefox, Thunderbird, and Firefox ESR. The vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. This vulnerability has a CVSS score of 7.5 and a severity of HIGH. The CVE was published on 2026-04-21 and last modified on 2026-06-30. The vulnerability allows for a potential crash and co [truncated]

HIGH Mozilla CVE published 2026-04-21

CVE-2026-6746

CVE-2026-6746 is a high-severity use-after-free vulnerability in the DOM: Core & HTML component of Firefox. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The CVE was published on April 21, 2026, and last modified on June 30, 2026.

CRITICAL Mozilla CVE published 2026-04-07

CVE-2026-5735

CVE-2026-5735 is a critical Mozilla vulnerability affecting Firefox 149.0.1 and Thunderbird 149.0.1. The CVE description says the issue involved memory safety bugs, some with evidence of memory corruption, and that Mozilla presumed some could have been exploited to run arbitrary code. Mozilla fixed the problem in Firefox 149.0.2 and Thunderbird 149.0.2. Because NVD rates the issue 9.8 and the CVSS vector [truncated]

CRITICAL Mozilla CVE published 2026-04-07

CVE-2026-5734

CVE-2026-5734 is a critical vulnerability affecting multiple Mozilla products, including Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1, and Thunderbird 149.0.1. The vulnerability is caused by memory safety bugs, some of which showed evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fixed in Firefox 149.0.2 [truncated]

HIGH Mozilla CVE published 2026-04-07

CVE-2026-5733

CVE-2026-5733 is a HIGH-severity vulnerability in Mozilla Firefox and Thunderbird, caused by incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. The CVE record was published on 2026-04-07T13:16:47.567Z and last modified on 2026-06-30T03:21:09.290Z.

HIGH Mozilla CVE published 2026-04-07

CVE-2026-5732

CVE-2026-5732 is a high-severity vulnerability affecting Mozilla Firefox and Thunderbird. The vulnerability is caused by incorrect boundary conditions and integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1. The CVSS score for this vulnerability is 8.8, indicating a high level of severity. User [truncated]

CRITICAL Mozilla CVE published 2026-04-07

CVE-2026-5731

CVE-2026-5731 is a critical vulnerability affecting multiple Mozilla products, including Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1, and Thunderbird 149.0.1. The vulnerability is caused by memory safety bugs, some of which showed evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fi [truncated]

CRITICAL Mozilla CVE published 2026-03-24

CVE-2026-4729

CVE-2026-4729 is a critical vulnerability affecting Firefox 148 and Thunderbird 148, involving multiple memory safety bugs that could potentially lead to arbitrary code execution. These bugs showed evidence of memory corruption. The vulnerability was fixed in Firefox 149 and Thunderbird 149. Users are advised to update to the latest versions to mitigate this vulnerability. The CVE was published on March 2 [truncated]

CRITICAL Mozilla CVE published 2026-03-24

CVE-2026-4721

CVE-2026-4721 is a critical vulnerability affecting Mozilla Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148, and Thunderbird 148. The vulnerability involves memory safety bugs that show evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, [truncated]

CRITICAL Mozilla CVE published 2026-03-24

CVE-2026-4720

CVE-2026-4720 is a critical vulnerability affecting Mozilla Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148, and Thunderbird 148. The vulnerability involves memory safety bugs that showed evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9 [truncated]

CRITICAL Mozilla CVE published 2026-03-24

CVE-2026-4698

CVE-2026-4698 is a critical Mozilla JavaScript engine JIT miscompilation issue. According to the published advisory data, the flaw was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. Because the CVSS score is 9.8 and the vector is network-reachable with no privileges or user interaction required, this should be treated as an urgent update item for any e [truncated]

HIGH Mozilla CVE published 2026-03-24

CVE-2026-4697

CVE-2026-4697 is a HIGH severity vulnerability in Mozilla Firefox, Thunderbird, and Firefox ESR. It relates to incorrect boundary conditions in the Audio/Video: Web Codecs component. This issue was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability was publicly disclosed on March 24, 2026, and last modified on June 30, 2026. The CVSS score for this vulnerability is 7.5.

HIGH Mozilla CVE published 2026-03-24

CVE-2026-4695

CVE-2026-4695 is a HIGH-severity vulnerability affecting the Audio/Video: Web Codecs component. The issue involves incorrect boundary conditions and was addressed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability was publicly disclosed on March 24, 2026, and the CVE record was last modified on June 30, 2026. The CVSS score for this vulnerability is 7.5. The CVE r [truncated]

HIGH Mozilla CVE published 2026-03-24

CVE-2026-4694

CVE-2026-4694 is a high-severity vulnerability in Mozilla Firefox, with a CVSS score of 7.5. The vulnerability is caused by incorrect boundary conditions and an integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability was published on March 24, 2026, and modified on June 30, 202 [truncated]

HIGH Mozilla CVE published 2026-03-24

CVE-2026-4693

CVE-2026-4693 is a HIGH severity vulnerability in the Audio/Video: Playback component. The issue involves incorrect boundary conditions. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The CVE was published on March 24, 2026, and modified on June 30, 2026. The vulnerability has a CVSS score of 7.5 and a CVSS severity of HIGH.

CRITICAL Mozilla CVE published 2026-03-24

CVE-2026-4692

CVE-2026-4692 is a critical vulnerability in the Responsive Design Mode component of Firefox, allowing for sandbox escape. The vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The CVSS score for this vulnerability is 10, indicating the highest severity. The vulnerability was publicly disclosed on March 24, 2026, and the CVE record was l [truncated]

CRITICAL Mozilla CVE published 2026-03-24

CVE-2026-4689

CVE-2026-4689 is a critical vulnerability in Mozilla Firefox, allowing for sandbox escape due to incorrect boundary conditions and integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability has a CVSS score of 10 and a severity of CRITICAL. The CVE was published on March 24, 2026, an [truncated]

CRITICAL Mozilla CVE published 2026-03-24

CVE-2026-4688

CVE-2026-4688 is a critical vulnerability in Mozilla Firefox, with a CVSS score of 10. The vulnerability allows for a sandbox escape due to a use-after-free issue in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability was publicly disclosed on March 24, 2026, and last modified on June 30, 2026. The [truncated]

HIGH Mozilla CVE published 2026-03-24

CVE-2026-4687

CVE-2026-4687 is a high-severity vulnerability in Mozilla Firefox, allowing for sandbox escape due to incorrect boundary conditions in the Telemetry component. The vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. This vulnerability has a CVSS score of 8.6 and is classified as HIGH. The CVE was published on March 24, 2026, and last modif [truncated]

HIGH Mozilla CVE published 2026-03-24

CVE-2026-4686

CVE-2026-4686 is a HIGH-severity vulnerability in the Graphics: Canvas2D component of Mozilla Firefox, with a CVSS score of 7.5. The vulnerability is caused by incorrect boundary conditions. This issue was addressed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. Users should update to the latest versions to mitigate the risk. The CVE was published on March 2 [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2807

CVE-2026-2807 is a critical vulnerability affecting Firefox 147 and Thunderbird 147, involving memory safety bugs that could lead to arbitrary code execution. The bugs showed evidence of memory corruption, and it is presumed that with enough effort, some of these could have been exploited. The vulnerability was fixed in Firefox 148 and Thunderbird 148. Users are advised to update to the latest versions to [truncated]

HIGH Mozilla CVE published 2026-02-24

CVE-2026-2798

CVE-2026-2798 is a high-severity use-after-free vulnerability in the DOM: Core & HTML component of Firefox and Thunderbird. The vulnerability was fixed in Firefox 148 and Thunderbird 148. It has a CVSS score of 8.8 and is classified as HIGH. The vulnerability was published on February 24, 2026, and last modified on June 30, 2026. The CVE record and NVD detail provide further information on this vulnerability.

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2797

CVE-2026-2797 is a critical use-after-free vulnerability in the JavaScript: GC component of Firefox and Thunderbird. The vulnerability was fixed in Firefox 148 and Thunderbird 148. This vulnerability has a CVSS score of 9.8 and a severity of CRITICAL. The CVE was published on 2026-02-24T14:16:28.200Z and last modified on 2026-06-30T03:18:21.253Z. The vulnerability affects Firefox and Thunderbird versions [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2796

CVE-2026-2796 is a critical vulnerability in the JavaScript: WebAssembly component of Mozilla Firefox and Thunderbird. The vulnerability, which has a CVSS score of 9.8, was fixed in Firefox 148 and Thunderbird 148. This vulnerability involves a Just-In-Time (JIT) miscompilation issue. The CVE was published on February 24, 2026, and last modified on June 30, 2026. The vulnerability affects Firefox versions [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2795

CVE-2026-2795 is a critical use-after-free vulnerability in the JavaScript: GC component of Firefox and Thunderbird. The vulnerability was fixed in Firefox 148 and Thunderbird 148. It has a CVSS score of 9.8 and a severity of CRITICAL. The vulnerability was publicly disclosed on February 24, 2026, and the CVE record was last modified on June 30, 2026. The vendor, Mozilla, has provided advisories for this [truncated]

HIGH Mozilla CVE published 2026-02-24

CVE-2026-2794

CVE-2026-2794 is a high-severity information disclosure vulnerability affecting Firefox and Firefox Focus for Android. The issue arises from uninitialized memory, which could potentially expose sensitive information. This vulnerability was addressed in Firefox version 148. Users are advised to update to the latest version to mitigate this risk. The CVE was published on February 24, 2026, and last modified [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2793

CVE-2026-2793 is a critical vulnerability affecting multiple Mozilla products, including Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147, and Thunderbird 147. The vulnerability is caused by memory safety bugs, some of which showed evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fixed in Firefox [truncated]

CRITICAL Mozilla CVE published 2026-02-24

CVE-2026-2792

CVE-2026-2792 is a critical vulnerability affecting Mozilla's Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147, and Thunderbird 147. The issue involves memory safety bugs that could lead to memory corruption and potentially allow attackers to execute arbitrary code. This vulnerability was addressed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The CVSS score for this vuln [truncated]