Popis
Multiple vulnerabilities were found in Mozilla Thunderbird ESR. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.
Below is a complete list of vulnerabilities:
- Security vulnerability can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the JavaScript: GC component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the JavaScript: GC component can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Graphics: Text component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the Graphics: CanvasWebGL component can be exploited to bypass security restrictions.
- Security vulnerability in the Remote Settings Client component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Graphics: ImageLib component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Core & HTML component can be exploited remotely to execute arbitrary code.
- Information disclosure vulnerability in the Graphics: Text component can be exploited to obtain sensitive information.
- Denial of service vulnerability in the Graphics: CanvasWebGL component can be exploited remotely to cause denial of service.
- Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
- Information disclosure vulnerability in the Graphics component can be exploited to obtain sensitive information.
- A remote code execution vulnerability in the Graphics: Canvas2D component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the Downloads API component can be exploited to bypass security restrictions.
- Security vulnerability in the Networking: Cookies component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Storage: Cache API component can be exploited to obtain sensitive information.
- Security vulnerability in the Request Handling component can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Service Workers component can be exploited to bypass security restrictions.
- Security vulnerability in the Safe Browsing component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the WebRTC component can be exploited to obtain sensitive information.
- Security vulnerability in the Storage: Cache API component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Web Audio component can be exploited to obtain sensitive information.
- A remote code execution vulnerability in the Graphics component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the Shell Integration component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Form Autofill component can be exploited to obtain sensitive information.
- Security vulnerability in the Audio/Video: Playback component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Layout: Text and Fonts component can be exploited remotely to execute arbitrary code.
- Information disclosure vulnerability in the DOM: UI Events & Focus Handling component can be exploited to obtain sensitive information.
- Information disclosure vulnerability in the DOM: Push Subscriptions component can be exploited to obtain sensitive information.
- Security vulnerability in the Graphics: Severok component can be exploited to bypass security restrictions.
- Security vulnerability in the Add-ons Manager component can be exploited to bypass security restrictions.
- Denial of service vulnerability in the Widget component can be exploited remotely to cause denial of service.
- Security vulnerability in the Data Loss Prevention component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the JavaScript Engine component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the Enterprise Policies component can be exploited to bypass security restrictions.
Oficiální doporučení
Vykořisťování
Public exploits exist for this vulnerability.
Související produkty
seznam CVE
- CVE-2026-74934 unknown
- CVE-2026-74935 critical
- CVE-2026-74936 unknown
- CVE-2026-74937 critical
- CVE-2026-74938 critical
- CVE-2026-74939 critical
- CVE-2026-74940 unknown
- CVE-2026-74941 critical
- CVE-2026-74942 critical
- CVE-2026-74943 unknown
- CVE-2026-74944 unknown
- CVE-2026-74945 unknown
- CVE-2026-74946 critical
- CVE-2026-74947 critical
- CVE-2026-74948 unknown
- CVE-2026-74949 critical
- CVE-2026-74950 critical
- CVE-2026-74953 critical
- CVE-2026-74954 critical
- CVE-2026-74955 critical
- CVE-2026-74956 critical
- CVE-2026-74957 unknown
- CVE-2026-74958 critical
- CVE-2026-74959 unknown
- CVE-2026-74960 unknown
- CVE-2026-74961 unknown
- CVE-2026-74962 unknown
- CVE-2026-74963 high
- CVE-2026-74964 unknown
- CVE-2026-74965 critical
- CVE-2026-74966 unknown
- CVE-2026-74967 high
- CVE-2026-74968 high
- CVE-2026-74969 unknown
- CVE-2026-74970 high
- CVE-2026-74971 warning
- CVE-2026-74972 warning
- CVE-2026-74973 warning
- CVE-2026-74974 high
- CVE-2026-74976 unknown
- CVE-2026-74977 critical
- CVE-2026-74978 critical
- CVE-2026-74979 critical
- CVE-2026-74981 unknown
- CVE-2026-74982 unknown
- CVE-2026-74983 unknown
- CVE-2026-74984 unknown
- CVE-2026-74985 unknown
- CVE-2026-74986 unknown
- CVE-2026-74987 unknown
- CVE-2026-74988 unknown
- CVE-2026-74990 critical
Zobrazit více
Zjistěte statistiky zranitelností šířících se ve vaší oblasti statistics.securelist.com
Našli jste v popisu této chyby zabezpečení nepřesnost? Dej nám vědět!