|
2081
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0880
|
2026-04-14 00:17 |
2026-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2082
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Escape de sandbox debido a desbordamiento de entero en el componente de Gráficos. Esta vulnerabilidad afecta a Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147,…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0880
|
2026-04-14 00:17 |
2026-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2083
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-0879
|
2026-04-14 00:17 |
2026-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2084
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Escape de sandbox debido a condiciones de contorno incorrectas en el componente de Gráficos. Esta vulnerabilidad afecta a Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbir…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-0879
|
2026-04-14 00:17 |
2026-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2085
|
8.0 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
|
CWE-20 CWE-119
Improper Input Validation Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-0878
|
2026-04-14 00:17 |
2026-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2086
|
8.0 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Escape de sandbox debido a condiciones de contorno incorrectas en el componente Graphics: CanvasWebGL. Esta vulnerabilidad afecta a Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, y T…
|
CWE-20 CWE-119
Improper Input Validation Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-0878
|
2026-04-14 00:17 |
2026-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2087
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0877
|
2026-04-14 00:17 |
2026-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2088
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Elusión de mitigación en el DOM: Componente de seguridad. Esta vulnerabilidad afecta a Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147 y Thunderbird < 140.7.
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0877
|
2026-04-14 00:17 |
2026-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2089
|
4.3 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted c…
|
CWE-116 CWE-200 CWE-352
Improper Encoding or Escaping of Output Information Exposure Origin Validation Error
|
CVE-2026-0818
|
2026-04-14 00:17 |
2026-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2090
|
4.3 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
Cuando un usuario solicitó explícitamente a Thunderbird que descifrara un mensaje OpenPGP en línea que estaba incrustado en una sección de texto de un correo electrónico que estaba formateado y estil…
|
CWE-116 CWE-200 CWE-352
Improper Encoding or Escaping of Output Information Exposure Origin Validation Error
|
CVE-2026-0818
|
2026-04-14 00:17 |
2026-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|