7.5

CVE-2026-12298

Memory safety bug fixed in Thunderbird 152

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox SwEdition - Version < 152.0
Mozilla ≫ Firefox SwEdition esr Version >= 140.0 < 140.12.0
Mozilla ≫ Thunderbird SwEdition - Version < 152.0.0
Mozilla ≫ Thunderbird SwEdition esr Version >= 140.0 < 140.12.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.222
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://www.mozilla.org/security/advisories/mfsa2026-57/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2026-58/
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=2041981
Permissions Required
https://www.mozilla.org/security/advisories/mfsa2026-60/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2026-61/
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2489248
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12298.json
https://access.redhat.com/errata/RHSA-2026:27717
https://access.redhat.com/errata/RHSA-2026:27733
https://access.redhat.com/errata/RHSA-2026:27734
https://access.redhat.com/errata/RHSA-2026:29940
https://access.redhat.com/errata/RHSA-2026:30846
https://access.redhat.com/errata/RHSA-2026:33445
https://access.redhat.com/errata/RHSA-2026:36100
https://access.redhat.com/errata/RHSA-2026:36101
https://access.redhat.com/errata/RHSA-2026:36102
https://access.redhat.com/errata/RHSA-2026:36103
https://access.redhat.com/security/cve/CVE-2026-12298
https://access.redhat.com/errata/RHSA-2026:37210
https://access.redhat.com/errata/RHSA-2026:37391
https://access.redhat.com/errata/RHSA-2026:38506
https://access.redhat.com/errata/RHSA-2026:38750
https://access.redhat.com/errata/RHSA-2026:38751
https://access.redhat.com/errata/RHSA-2026:38753
https://access.redhat.com/errata/RHSA-2026:39011
https://access.redhat.com/errata/RHSA-2026:39141
https://access.redhat.com/errata/RHSA-2026:39142
https://access.redhat.com/errata/RHSA-2026:39428
https://access.redhat.com/errata/RHSA-2026:39706