Vulnerability index

Browse CVEs

2,857 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thunderbird HIGH 7.4
CVE-2026-4371

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Thunderbird MEDIUM 6.5
CVE-2026-3889

Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

Fix: 140.9.0 / 149.0+
Fix from $1,600 2026-03-24
Firefox CRITICAL 10.0
CVE-2026-4725

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4723

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4729

Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.1
CVE-2026-4724

Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox HIGH 8.8
CVE-2026-4722

Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4726

Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4727

Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $1,950 2026-03-24
Firefox MEDIUM 6.5
CVE-2026-4728

Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $1,600 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4711

Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4717

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4720

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4721

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showe…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.1
CVE-2026-4715

Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunde…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.1
CVE-2026-4716

Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox HIGH 8.1
CVE-2026-4718

Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4712

Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4713

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunder…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4714

Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4719

Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and T…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4700

Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4701

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 1…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4702

JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4705

Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4710

Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox HIGH 7.5
CVE-2026-4704

Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbir…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4706

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9…

Fix: 115.34.0 / 140.9.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4707

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9…

Fix: 115.34.0 / 140.9.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4708

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunder…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24