|
2281
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
CWE-416
Use After Free
|
CVE-2026-2786
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2282
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Uso después de liberación en el componente del motor JavaScript. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, y Thunderbird < 140.8.
|
CWE-416
Use After Free
|
CVE-2026-2786
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2283
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2026-2785
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2284
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Puntero no válido en el componente del motor JavaScript. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148 y Thunderbird < 140.8.
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2026-2785
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2285
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
NVD-CWE-noinfo CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-2784
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2286
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Elusión de mitigación en el DOM: Componente de seguridad. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, y Thunderbird < 140.8.
|
NVD-CWE-noinfo CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-2784
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2287
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
CWE-843 CWE-200
Type Confusion Information Exposure
|
CVE-2026-2783
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2288
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Revelación de información debido a compilación errónea JIT en el motor JavaScript: componente JIT. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, y Thund…
|
CWE-843 CWE-200
Type Confusion Information Exposure
|
CVE-2026-2783
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2289
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
NVD-CWE-noinfo CWE-269
Improper Privilege Management
|
CVE-2026-2782
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2290
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Escalada de privilegios en el componente Netmonitor. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, y Thunderbird < 140.8.
|
NVD-CWE-noinfo CWE-269
Improper Privilege Management
|
CVE-2026-2782
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|