Kaspersky ID:
KLA91229
Detekováno:
08/18/2026
Aktualizováno:
08/19/2026

Popis

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Security vulnerability in the Remote Settings Client component can be exploited to bypass security restrictions.
  2. Security vulnerability can be exploited to bypass security restrictions.
  3. Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
  4. A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
  5. A remote code execution vulnerability in the JavaScript: GC component can be exploited remotely to execute arbitrary code.
  6. Security vulnerability in the JavaScript: GC component can be exploited to bypass security restrictions.
  7. Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
  8. A remote code execution vulnerability in the Graphics: Text component can be exploited remotely to execute arbitrary code.
  9. Security vulnerability in the Graphics: CanvasWebGL component can be exploited to bypass security restrictions.
  10. A remote code execution vulnerability in the Graphics: ImageLib component can be exploited remotely to execute arbitrary code.
  11. A remote code execution vulnerability in the DOM: Core & HTML component can be exploited remotely to execute arbitrary code.
  12. Information disclosure vulnerability in the Graphics: Text component can be exploited to obtain sensitive information.
  13. Denial of service vulnerability in the Graphics: CanvasWebGL component can be exploited remotely to cause denial of service.
  14. Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
  15. Information disclosure vulnerability in the Graphics component can be exploited to obtain sensitive information.
  16. A remote code execution vulnerability in the Graphics: Canvas2D component can be exploited remotely to execute arbitrary code.
  17. Security vulnerability in the Downloads API component can be exploited to bypass security restrictions.
  18. Security vulnerability in the Application Update component can be exploited to bypass security restrictions.
  19. Security vulnerability in the Networking: Cookies component can be exploited to bypass security restrictions.
  20. Information disclosure vulnerability in the Storage: Cache API component can be exploited to obtain sensitive information.
  21. Security vulnerability in the Request Handling component can be exploited to bypass security restrictions.
  22. Security vulnerability in the DOM: Service Workers component can be exploited to bypass security restrictions.
  23. Security vulnerability in the Safe Browsing component can be exploited to bypass security restrictions.
  24. Information disclosure vulnerability in the WebRTC component can be exploited to obtain sensitive information.
  25. Security vulnerability in the Storage: Cache API component can be exploited to bypass security restrictions.
  26. Information disclosure vulnerability in the Web Audio component can be exploited to obtain sensitive information.
  27. A remote code execution vulnerability in the Graphics component can be exploited remotely to execute arbitrary code.
  28. Security vulnerability in the Shell Integration component can be exploited to bypass security restrictions.
  29. Information disclosure vulnerability in the Form Autofill component can be exploited to obtain sensitive information.
  30. Security vulnerability in the Audio/Video: Playback component can be exploited to bypass security restrictions.
  31. A remote code execution vulnerability in the Layout: Text and Fonts component can be exploited remotely to execute arbitrary code.
  32. Information disclosure vulnerability in the DOM: UI Events & Focus Handling component can be exploited to obtain sensitive information.
  33. Information disclosure vulnerability in the DOM: Push Subscriptions component can be exploited to obtain sensitive information.
  34. Security vulnerability in the Graphics: ImageLib component can be exploited to bypass security restrictions.
  35. Security vulnerability in the Add-ons Manager component can be exploited to bypass security restrictions.
  36. Denial of service vulnerability in the Widget component can be exploited remotely to cause denial of service.
  37. Security vulnerability in the Data Loss Prevention component can be exploited to bypass security restrictions.
  38. A remote code execution vulnerability in the JavaScript Engine component can be exploited remotely to execute arbitrary code.
  39. Security vulnerability in the Enterprise Policies component can be exploited to bypass security restrictions.

Oficiální doporučení

Vykořisťování

Public exploits exist for this vulnerability.

Související produkty

seznam CVE

  • CVE-2026-74934
    unknown
  • CVE-2026-74935
    critical
  • CVE-2026-74936
    unknown
  • CVE-2026-74937
    critical
  • CVE-2026-74938
    critical
  • CVE-2026-74939
    critical
  • CVE-2026-74940
    unknown
  • CVE-2026-74941
    critical
  • CVE-2026-74942
    critical
  • CVE-2026-74943
    unknown
  • CVE-2026-74944
    unknown
  • CVE-2026-74945
    unknown
  • CVE-2026-74946
    critical
  • CVE-2026-74947
    critical
  • CVE-2026-74948
    unknown
  • CVE-2026-74949
    critical
  • CVE-2026-74950
    critical
  • CVE-2026-74952
    critical
  • CVE-2026-74953
    critical
  • CVE-2026-74954
    critical
  • CVE-2026-74955
    critical
  • CVE-2026-74956
    critical
  • CVE-2026-74957
    unknown
  • CVE-2026-74958
    critical
  • CVE-2026-74959
    unknown
  • CVE-2026-74960
    unknown
  • CVE-2026-74961
    unknown
  • CVE-2026-74962
    unknown
  • CVE-2026-74963
    high
  • CVE-2026-74964
    unknown
  • CVE-2026-74965
    critical
  • CVE-2026-74966
    unknown
  • CVE-2026-74967
    high
  • CVE-2026-74968
    high
  • CVE-2026-74969
    unknown
  • CVE-2026-74970
    high
  • CVE-2026-74971
    warning
  • CVE-2026-74972
    warning
  • CVE-2026-74973
    warning
  • CVE-2026-74974
    high
  • CVE-2026-74976
    unknown
  • CVE-2026-74977
    critical
  • CVE-2026-74978
    critical
  • CVE-2026-74979
    critical
  • CVE-2026-74981
    unknown
  • CVE-2026-74982
    unknown
  • CVE-2026-74983
    unknown
  • CVE-2026-74984
    unknown
  • CVE-2026-74985
    unknown
  • CVE-2026-74986
    unknown
  • CVE-2026-74987
    unknown
  • CVE-2026-74988
    unknown
  • CVE-2026-74989
    unknown
  • CVE-2026-74990
    critical
  • CVE-2026-75874
    critical

Zobrazit více

Zjistěte statistiky zranitelností šířících se ve vaší oblasti statistics.securelist.com

Našli jste v popisu této chyby zabezpečení nepřesnost? Dej nám vědět!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Zjistěte více
Kaspersky Premium
Zjistěte více
Do you want to save your changes?
Your message has been sent successfully.