Kaspersky ID:
KLA91231
Дата обнаружения:
18/08/2026
Обновлено:
19/08/2026

Описание

Multiple vulnerabilities were found in Mozilla Thunderbird ESR. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Security vulnerability can be exploited to bypass security restrictions.
  2. Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
  3. A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
  4. Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
  5. A remote code execution vulnerability in the Graphics: Text component can be exploited remotely to execute arbitrary code.
  6. Security vulnerability in the Graphics: CanvasWebGL component can be exploited to bypass security restrictions.
  7. Security vulnerability in the Remote Settings Client component can be exploited to bypass security restrictions.
  8. A remote code execution vulnerability in the Graphics: ImageLib component can be exploited remotely to execute arbitrary code.
  9. A remote code execution vulnerability in the DOM: Core & HTML component can be exploited remotely to execute arbitrary code.
  10. Information disclosure vulnerability in the Graphics: Text component can be exploited to obtain sensitive information.
  11. Denial of service vulnerability in the Graphics: CanvasWebGL component can be exploited remotely to cause denial of service.
  12. Information disclosure vulnerability in the Graphics component can be exploited to obtain sensitive information.
  13. A remote code execution vulnerability in the Graphics: Canvas2D component can be exploited remotely to execute arbitrary code.
  14. Security vulnerability in the Networking: Cookies component can be exploited to bypass security restrictions.
  15. Security vulnerability in the Safe Browsing component can be exploited to bypass security restrictions.
  16. Security vulnerability in the Storage: Cache API component can be exploited to bypass security restrictions.
  17. A remote code execution vulnerability in the Graphics component can be exploited remotely to execute arbitrary code.
  18. Security vulnerability in the Shell Integration component can be exploited to bypass security restrictions.
  19. Security vulnerability in the Audio/Video: Playback component can be exploited to bypass security restrictions.
  20. A remote code execution vulnerability in the Layout: Text and Fonts component can be exploited remotely to execute arbitrary code.
  21. Information disclosure vulnerability in the DOM: UI Events & Focus Handling component can be exploited to obtain sensitive information.
  22. Information disclosure vulnerability in the DOM: Push Subscriptions component can be exploited to obtain sensitive information.
  23. Security vulnerability in the Graphics: ImageLib component can be exploited to bypass security restrictions.
  24. Security vulnerability in the Data Loss Prevention component can be exploited to bypass security restrictions.

Первичный источник обнаружения

Эксплуатация

Public exploits exist for this vulnerability.

Связанные продукты

Список CVE

  • CVE-2026-74934
    unknown
  • CVE-2026-74935
    critical
  • CVE-2026-74936
    unknown
  • CVE-2026-74939
    critical
  • CVE-2026-74940
    unknown
  • CVE-2026-74941
    critical
  • CVE-2026-74942
    critical
  • CVE-2026-74943
    unknown
  • CVE-2026-74944
    unknown
  • CVE-2026-74945
    unknown
  • CVE-2026-74946
    critical
  • CVE-2026-74948
    unknown
  • CVE-2026-74949
    critical
  • CVE-2026-74953
    critical
  • CVE-2026-74957
    unknown
  • CVE-2026-74959
    unknown
  • CVE-2026-74960
    unknown
  • CVE-2026-74962
    unknown
  • CVE-2026-74963
    high
  • CVE-2026-74964
    unknown
  • CVE-2026-74965
    critical
  • CVE-2026-74967
    high
  • CVE-2026-74969
    unknown
  • CVE-2026-74971
    warning
  • CVE-2026-74972
    warning
  • CVE-2026-74973
    warning
  • CVE-2026-74974
    high
  • CVE-2026-74976
    unknown
  • CVE-2026-74983
    unknown
  • CVE-2026-74987
    unknown
  • CVE-2026-74990
    critical

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Do you want to save your changes?
Your message has been sent successfully.