Kaspersky ID:
KLA91169
Дата обнаружения:
21/07/2026
Обновлено:
23/07/2026

Описание

Multiple vulnerabilities were found in Mozilla Thunderbird ESR. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Denial of service vulnerability in MIME header parser for forwarding can be exploited remotely to cause denial of service.
  2. Denial of service vulnerability in the JavaScript: WebAssembly component can be exploited remotely to cause denial of service.
  3. Security vulnerability can be exploited to bypass security restrictions.
  4. Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
  5. Denial of service vulnerability in the Audio/Video: cubeb component can be exploited remotely to cause denial of service.
  6. A remote code execution vulnerability in the WebRTC: Audio/Video component can be exploited remotely to execute arbitrary code.
  7. A remote code execution vulnerability in the DOM: Navigation component can be exploited remotely to execute arbitrary code.
  8. A remote code execution vulnerability in the Disability Access APIs component can be exploited remotely to execute arbitrary code.
  9. Denial of service vulnerability in the DOM: Bindings (WebIDL) component can be exploited remotely to cause denial of service.
  10. Information disclosure vulnerability in the Graphics: ImageLib component can be exploited to obtain sensitive information.
  11. A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
  12. Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
  13. Information disclosure vulnerability in the Framework component in DevTools can be exploited to obtain sensitive information.
  14. Security vulnerability in the PDF Viewer component can be exploited to bypass security restrictions.
  15. Security vulnerability in the DOM: Content Processes component can be exploited to bypass security restrictions.
  16. Security vulnerability in the Networking: DNS component can be exploited to bypass security restrictions.
  17. Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
  18. Security vulnerability in the Enterprise Policies component can be exploited to bypass security restrictions.
  19. Information disclosure vulnerability in the Storage: IndexedDB component can be exploited to obtain sensitive information.
  20. Denial of service vulnerability in the Audio/Video: GMP component can be exploited remotely to cause denial of service.
  21. Security vulnerability in WebExtensions can be exploited to bypass security restrictions.
  22. Information disclosure vulnerability in the Networking: WebSockets component can be exploited to obtain sensitive information.
  23. A remote code execution vulnerability in Firefox ESR 140 can be exploited remotely to execute arbitrary code.
  24. A remote code execution vulnerability in Firefox ESR 115 can be exploited remotely to execute arbitrary code.

Первичный источник обнаружения

Список CVE

  • CVE-2026-15718
    warning
  • CVE-2026-15719
    high
  • CVE-2026-16349
    critical
  • CVE-2026-16350
    critical
  • CVE-2026-16351
    critical
  • CVE-2026-16352
    critical
  • CVE-2026-16353
    critical
  • CVE-2026-16354
    critical
  • CVE-2026-16355
    critical
  • CVE-2026-16356
    critical
  • CVE-2026-16357
    critical
  • CVE-2026-16358
    critical
  • CVE-2026-16359
    critical
  • CVE-2026-16360
    critical
  • CVE-2026-16361
    critical
  • CVE-2026-16362
    critical
  • CVE-2026-16363
    critical
  • CVE-2026-16368
    critical
  • CVE-2026-16369
    critical
  • CVE-2026-16371
    critical
  • CVE-2026-16374
    critical
  • CVE-2026-16375
    critical
  • CVE-2026-16377
    critical
  • CVE-2026-16379
    critical
  • CVE-2026-16381
    critical
  • CVE-2026-16383
    critical
  • CVE-2026-16387
    critical
  • CVE-2026-16390
    critical
  • CVE-2026-16391
    critical
  • CVE-2026-16396
    critical
  • CVE-2026-16405
    critical
  • CVE-2026-16412
    critical
  • CVE-2026-14899
    unknown

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Do you want to save your changes?
Your message has been sent successfully.