CVE-2026-92008
- EPSS 0.27%
- Veröffentlicht 15.09.2026 12:33:27
- Zuletzt bearbeitet 06.10.2026 14:48:27
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunder...
CVE-2026-92007
- EPSS 0.27%
- Veröffentlicht 15.09.2026 12:33:26
- Zuletzt bearbeitet 06.10.2026 14:48:48
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunder...
CVE-2026-92006
- EPSS 0.34%
- Veröffentlicht 15.09.2026 12:33:25
- Zuletzt bearbeitet 06.10.2026 14:49:12
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunder...
CVE-2026-92005
- EPSS 0.16%
- Veröffentlicht 15.09.2026 12:33:24
- Zuletzt bearbeitet 06.10.2026 14:42:00
Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-84641
- EPSS 0.29%
- Veröffentlicht 01.09.2026 21:33:07
- Zuletzt bearbeitet 03.09.2026 19:01:11
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbir...
CVE-2026-84642
- EPSS 0.27%
- Veröffentlicht 01.09.2026 21:33:07
- Zuletzt bearbeitet 03.09.2026 19:00:52
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachment...
CVE-2026-84639
- EPSS 0.34%
- Veröffentlicht 01.09.2026 21:33:06
- Zuletzt bearbeitet 03.09.2026 19:01:50
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CVE-2026-84640
- EPSS 0.28%
- Veröffentlicht 01.09.2026 21:33:06
- Zuletzt bearbeitet 03.09.2026 19:01:32
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CVE-2026-84637
- EPSS 0.34%
- Veröffentlicht 01.09.2026 21:25:08
- Zuletzt bearbeitet 03.09.2026 19:02:08
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could al...
CVE-2026-84144
- EPSS 0.15%
- Veröffentlicht 01.09.2026 12:19:11
- Zuletzt bearbeitet 03.09.2026 16:33:15
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. Th...