|
2141
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-4726
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2142
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Denegación de servicio en el componente XML. Esta vulnerabilidad afecta a Firefox < 149 y Thunderbird < 149.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-4726
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2143
|
9.3 |
CRITICAL
Network
|
mozilla
|
firefox
|
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
|
CWE-416
Use After Free
|
CVE-2026-4725
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2144
|
9.3 |
CRITICAL
Network
|
mozilla
|
firefox
|
Escape de sandbox debido a uso después de liberación en el componente Graphics: Canvas2D. Esta vulnerabilidad afecta a Firefox < 149 y Thunderbird < 149.
|
CWE-416
Use After Free
|
CVE-2026-4725
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2145
|
9.1 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
|
CWE-758
Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
|
CVE-2026-4724
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2146
|
9.1 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Comportamiento indefinido en el componente de Audio/Video. Esta vulnerabilidad afecta a Firefox < 149 y Thunderbird < 149.
|
CWE-758
Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
|
CVE-2026-4724
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2147
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
|
CWE-416
Use After Free
|
CVE-2026-4723
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2148
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Uso después de liberación en el componente del motor JavaScript. Esta vulnerabilidad afecta a Firefox < 149 y Thunderbird < 149.
|
CWE-416
Use After Free
|
CVE-2026-4723
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2149
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
|
NVD-CWE-noinfo
|
CVE-2026-4722
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2150
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Escalada de privilegios en el componente IPC. Esta vulnerabilidad afecta a Firefox < 149 y Thunderbird < 149.
|
NVD-CWE-noinfo
|
CVE-2026-4722
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|