Vulnerability index

Browse CVEs

2,857 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2026-4371 A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or… Thunderbird 140.9.0 / 149.0+ Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-3889 Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9. Thunderbird 140.9.0 / 149.0+ Fix from $1,6002026-03-24 CRITICAL 10.0 CVE-2026-4725 Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4723 Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4729 Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Firefox 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4724 Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $2,3002026-03-24 HIGH 8.8 CVE-2026-4722 Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4726 Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4727 Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-4728 Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $1,6002026-03-24 CRITICAL 9.8 CVE-2026-4711 Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4717 Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4720 Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4721 Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showe… Firefox 115.34.0 / 140.9.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4715 Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunde… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4716 Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 HIGH 8.1 CVE-2026-4718 Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4712 Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4713 Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunder… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4714 Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4719 Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and T… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 CRITICAL 9.8 CVE-2026-4700 Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4701 Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 1… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4702 JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4705 Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4710 Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun… Firefox 140.9.0 / 149.0+ Fix from $2,3002026-03-24 HIGH 7.5 CVE-2026-4704 Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbir… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4706 Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9… Firefox 115.34.0 / 140.9.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4707 Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9… Firefox 115.34.0 / 140.9.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4708 Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunder… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24