説明
Multiple vulnerabilities were found in Mozilla Thunderbird ESR. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.
Below is a complete list of vulnerabilities:
- Security vulnerability can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Graphics: Text component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the Graphics: CanvasWebGL component can be exploited to bypass security restrictions.
- Security vulnerability in the Remote Settings Client component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Graphics: ImageLib component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Core & HTML component can be exploited remotely to execute arbitrary code.
- Information disclosure vulnerability in the Graphics: Text component can be exploited to obtain sensitive information.
- Denial of service vulnerability in the Graphics: CanvasWebGL component can be exploited remotely to cause denial of service.
- Information disclosure vulnerability in the Graphics component can be exploited to obtain sensitive information.
- A remote code execution vulnerability in the Graphics: Canvas2D component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the Networking: Cookies component can be exploited to bypass security restrictions.
- Security vulnerability in the Safe Browsing component can be exploited to bypass security restrictions.
- Security vulnerability in the Storage: Cache API component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Graphics component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the Shell Integration component can be exploited to bypass security restrictions.
- Security vulnerability in the Audio/Video: Playback component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Layout: Text and Fonts component can be exploited remotely to execute arbitrary code.
- Information disclosure vulnerability in the DOM: UI Events & Focus Handling component can be exploited to obtain sensitive information.
- Information disclosure vulnerability in the DOM: Push Subscriptions component can be exploited to obtain sensitive information.
- Security vulnerability in the Graphics: ImageLib component can be exploited to bypass security restrictions.
- Security vulnerability in the Data Loss Prevention component can be exploited to bypass security restrictions.
オリジナルアドバイザリー
エクスプロイテーション
Public exploits exist for this vulnerability.
関連製品
CVEリスト
- CVE-2026-74934 unknown
- CVE-2026-74935 critical
- CVE-2026-74936 unknown
- CVE-2026-74939 critical
- CVE-2026-74940 unknown
- CVE-2026-74941 critical
- CVE-2026-74942 critical
- CVE-2026-74943 unknown
- CVE-2026-74944 unknown
- CVE-2026-74945 unknown
- CVE-2026-74946 critical
- CVE-2026-74948 unknown
- CVE-2026-74949 critical
- CVE-2026-74953 critical
- CVE-2026-74957 unknown
- CVE-2026-74959 unknown
- CVE-2026-74960 unknown
- CVE-2026-74962 unknown
- CVE-2026-74963 high
- CVE-2026-74964 unknown
- CVE-2026-74965 critical
- CVE-2026-74967 high
- CVE-2026-74969 unknown
- CVE-2026-74971 warning
- CVE-2026-74972 warning
- CVE-2026-74973 warning
- CVE-2026-74974 high
- CVE-2026-74976 unknown
- CVE-2026-74983 unknown
- CVE-2026-74987 unknown
- CVE-2026-74990 critical
も参照してください
お住まいの地域に広がる脆弱性の統計をご覧ください statistics.securelist.com
この脆弱性についての記述に不正確な点がありますか? お知らせください!