CVE-2026-74990
CRITICAL
9,8
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
119
Improper Restriction of Operations within the Bounds of a Memory Buffer
StableCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Modify Memory
Read Memory
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Applicable Platforms
Languages:
Memory-Unsafe, C, C++, Assembly
Application
Thunderbird by Mozilla
Version Range Affected
From
141.0
(inclusive)
To
153.1.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Thunderbird by Mozilla
Version Range Affected
To
140.14.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Firefox by Mozilla
Version Range Affected
From
116.0
(inclusive)
To
140.14.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Firefox by Mozilla
Version Range Affected
From
141.0
(inclusive)
To
153.1.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Firefox by Mozilla
Version Range Affected
To
115.39.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045762%2C2052401%2C2058208
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045774%2C2048490%2C2050864%2C2…
https://www.mozilla.org/security/advisories/mfsa2026-74/
https://www.mozilla.org/security/advisories/mfsa2026-75/
https://www.mozilla.org/security/advisories/mfsa2026-76/
https://www.mozilla.org/security/advisories/mfsa2026-77/
https://www.mozilla.org/security/advisories/mfsa2026-78/
https://www.mozilla.org/security/advisories/mfsa2026-79/
https://www.mozilla.org/security/advisories/mfsa2026-80/