|
2311
|
6.1 |
MEDIUM
Network
|
nuxt
|
og_image
|
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability …
|
CWE-79
Cross-site Scripting
|
CVE-2026-34405
|
2026-04-14 00:17 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2312
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
NVD-CWE-noinfo CWE-125
Out-of-bounds Read
|
CVE-2026-2771
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2313
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Comportamiento indefinido en el DOM: componente Core y HTML. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, y Thunderbird < 1…
|
NVD-CWE-noinfo CWE-125
Out-of-bounds Read
|
CVE-2026-2771
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2314
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
CWE-416
Use After Free
|
CVE-2026-2770
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2315
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Uso después de liberación en el DOM: componente de Enlaces (WebIDL). Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, y Thunderbir…
|
CWE-416
Use After Free
|
CVE-2026-2770
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2316
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
CWE-416
Use After Free
|
CVE-2026-2769
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2317
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Uso después de liberación en el componente Storage: IndexedDB. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, y Thunderbird <…
|
CWE-416
Use After Free
|
CVE-2026-2769
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2318
|
10.0 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
NVD-CWE-noinfo CWE-284 CWE-693
Improper Access Control Protection Mechanism Failure
|
CVE-2026-2768
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2319
|
10.0 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Escape de sandbox en el componente Storage: IndexedDB. Esta vulnerabilidad afecta a Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, y Thunderbird < 140.8.
|
NVD-CWE-noinfo CWE-284 CWE-693
Improper Access Control Protection Mechanism Failure
|
CVE-2026-2768
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2320
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
|
CWE-416
Use After Free
|
CVE-2026-2767
|
2026-04-14 00:17 |
2026-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|