PT-2026-33971 · Mozilla+1 · Firefox+2
Andrew Mccreight
+2
·
Published
2026-04-21
·
Updated
2026-05-25
·
CVE-2026-6785
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox ESR version 115.34
Firefox ESR version 140.9
Thunderbird ESR version 140.9
Firefox version 149
Thunderbird version 149
Description
Memory safety bugs involving memory corruption could allow an attacker to run arbitrary code.
Recommendations
Update Firefox ESR 115.34 to version 115.35.
Update Firefox ESR 140.9 to version 140.10.
Update Thunderbird ESR 140.9 to version 140.10.
Update Firefox 149 to version 150.
Update Thunderbird 149 to version 150.
Fix
DoS
Memory Corruption
Out of bounds Read
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox
Rocky Linux
Thunderbird