CVE-2026-6785
Essential information
- Published
- 26/04/2026 19:53
- Modified
- 27/04/2026 18:57
- Author
- —
- Creator
- —
- CVSS
- 8.1 HIGH (v3.1)
- CISA KEV
- No
- CWE
- —
- CVSS vector
-
—
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H—
CVSS metrics
- Access vector
- —
- Access complexity
- —
- Authentication
- —
- Confidentiality impact
- —
- Integrity impact
- —
- Availability impact
- —
- Exploitability
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- NETWORK
- Attack complexity
- HIGH
- Privileges required
- NONE
- User interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality impact
- HIGH
- Integrity impact
- HIGH
- Availability impact
- HIGH
- Exploit code maturity
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- —
- Attack complexity
- —
- Attack requirements
- —
- Privileges required
- —
- User interaction
- —
- Confidentiality (V)
- —
- Confidentiality (S)
- —
- Integrity (V)
- —
- Integrity (S)
- —
- Availability (V)
- —
- Availability (S)
- —
- Exploit maturity
- —
Description
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
NVD status
- Status
- Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| mozilla / firefox | cpe:2.3:a:mozilla:firefox:115.34:*:*:*:*:*:*:* |
| mozilla / firefox | cpe:2.3:a:mozilla:firefox:140.9:*:*:*:*:*:*:* |
| mozilla / thunderbird | cpe:2.3:a:mozilla:thunderbird:140.9:*:*:*:*:*:*:* |
| mozilla / firefox | cpe:2.3:a:mozilla:firefox:149:*:*:*:*:*:*:* |
| mozilla / thunderbird | cpe:2.3:a:mozilla:thunderbird:149:*:*:*:*:*:*:* |
| mozilla / firefox | cpe:2.3:a:mozilla:firefox:150:*:*:*:*:*:*:* |
| mozilla / firefox esr | cpe:2.3:a:mozilla:firefox_esr:115.34:*:*:*:*:*:*:* |
| mozilla / firefox esr | cpe:2.3:a:mozilla:firefox_esr:140.9:*:*:*:*:*:*:* |
| mozilla / thunderbird | cpe:2.3:a:mozilla:thunderbird:150:*:*:*:*:*:*:* |
| mozilla / firefox esr | cpe:2.3:a:mozilla:firefox_esr:115.35:*:*:*:*:*:*:* |
| mozilla / firefox esr | cpe:2.3:a:mozilla:firefox_esr:140.10:*:*:*:*:*:*:* |
| mozilla / thunderbird | cpe:2.3:a:mozilla:thunderbird:140.10:*:*:*:*:*:*:* |