PT-2026-33935 · Mozilla+1 · Firefox+2

Inseo An

·

Published

2026-04-21

·

Updated

2026-05-19

·

CVE-2026-6749

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 150 Firefox ESR versions prior to 115.35 Firefox ESR versions prior to 140.10 Thunderbird versions prior to 150 Thunderbird versions prior to 140.10
Description Information disclosure occurs due to uninitialized memory in the Graphics: Canvas2D component.
Recommendations Update Firefox to version 150. Update Firefox ESR to version 115.35. Update Firefox ESR to version 140.10. Update Thunderbird to version 150. Update Thunderbird to version 140.10.

Fix

DoS

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:10757
ALSA-2026:10766
ALSA-2026:10767
ALSA-2026:12285
ALSA-2026:13537
ALSA-2026:15892
ALSA-2026:19348
CVE-2026-6749
OESA-2026-2105
OESA-2026-2106
OESA-2026-2107
OESA-2026-2108
OESA-2026-2109
OPENSUSE-SU-2026:10610-1
OPENSUSE-SU-2026:10626-1
RHSA-2026:10757
RHSA-2026:10766
RHSA-2026:10767
RHSA-2026:19348

Affected Products

Firefox
Rocky Linux
Thunderbird