|
2341
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Condiciones de contorno incorrectas en el componente WebRTC: Audio/Video. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, y Thund…
|
NVD-CWE-noinfo CWE-1384
|
CVE-2026-2757
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2342
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed …
|
NVD-CWE-noinfo CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-2634
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2343
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Scripts maliciosos podrían causar desincronización entre la barra de direcciones y el contenido web antes de que se reciba una respuesta en Firefox iOS, permitiendo que páginas controladas por el ata…
|
NVD-CWE-noinfo CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-2634
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2344
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-2447
|
2026-04-14 00:17 |
2026-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2345
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Desbordamiento de búfer en el heap en libvpx. Esta vulnerabilidad afecta a Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, y Thunderbird < 147.…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-2447
|
2026-04-14 00:17 |
2026-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2346
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. Thi…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-2032
|
2026-04-14 00:17 |
2026-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2347
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Scripts maliciosos que interrumpen la carga de la página de nueva pestaña podrían causar desincronización entre la barra de direcciones y el contenido de la página, permitiendo al atacante suplantar …
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-2032
|
2026-04-14 00:17 |
2026-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2348
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
|
CWE-416
Use After Free
|
CVE-2026-24869
|
2026-04-14 00:17 |
2026-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2349
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Uso después de liberación en el componente de Diseño: Desplazamiento y Desbordamiento. Esta vulnerabilidad afecta a Firefox < 147.0.2.
|
CWE-416
Use After Free
|
CVE-2026-24869
|
2026-04-14 00:17 |
2026-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2350
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-24868
|
2026-04-14 00:17 |
2026-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|