|
2221
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-4685
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2222
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
Condiciones de límite incorrectas en el componente Graphics: Canvas2D. Esta vulnerabilidad afecta a Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, y Thunderb…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-4685
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2223
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-4684
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2224
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
Condición de carrera, uso después de liberación en el componente Gráficos: WebRender. Esta vulnerabilidad afecta a Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < …
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-4684
|
2026-04-14 00:17 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2225
|
7.4 |
HIGH
Network
|
mozilla
|
thunderbird
|
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an …
|
CWE-126
Buffer Over-read
|
CVE-2026-4371
|
2026-04-14 00:17 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2226
|
7.4 |
HIGH
Network
|
mozilla
|
thunderbird
|
Un servidor de correo malicioso podría enviar cadenas malformadas con longitudes negativas, haciendo que el analizador lea memoria fuera del búfer. Si un servidor de correo o una conexión a un servid…
|
CWE-126
Buffer Over-read
|
CVE-2026-4371
|
2026-04-14 00:17 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2227
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass.
_pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed…
|
CWE-130
Improper Handling of Length Parameter Inconsistency
|
CVE-2026-40199
|
2026-04-14 00:17 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2228
|
7.5 |
HIGH
Network
|
-
|
-
|
Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass.
_pack_ipv6() does not check that uncompressed IPv6 addresses (without ::) have exactl…
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-40198
|
2026-04-14 00:17 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2229
|
6.5 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-3889
|
2026-04-14 00:17 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2230
|
6.5 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
Problema de suplantación en Thunderbird. Esta vulnerabilidad afecta a Thunderbird < 149 y Thunderbird < 140.9.
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-3889
|
2026-04-14 00:17 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|