5.4
CVE-2026-74963
- EPSS 0.12%
- Veröffentlicht 18.08.2026 12:23:32
- Zuletzt bearbeitet 19.08.2026 01:00:22
- CVE-Watchlists
- Unerledigt
Same-origin policy bypass in the Networking: Cookies component
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird SwEditionesr Version < 140.14.0
Mozilla ≫ Thunderbird SwEdition- Version < 154.0
Mozilla ≫ Thunderbird SwEditionesr Version >= 153.0 < 153.1.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.025 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
https://www.mozilla.org/security/advisories/mfsa2026-74/
https://www.mozilla.org/security/advisories/mfsa2026-76/
https://www.mozilla.org/security/advisories/mfsa2026-77/
https://bugzilla.mozilla.org/show_bug.cgi?id=2050482
https://www.mozilla.org/security/advisories/mfsa2026-78/
https://www.mozilla.org/security/advisories/mfsa2026-79/
https://www.mozilla.org/security/advisories/mfsa2026-80/