CVE-2026-6786

EUVD-2026-24127
Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
firefox
sid
150.0-1
fixed
firefox-esr
bookworm
vulnerable
bookworm (security)
140.10.0esr-1~deb12u1
fixed
bullseye
vulnerable
bullseye (security)
140.10.0esr-1~deb11u1
fixed
forky
vulnerable
sid
140.10.0esr-1
fixed
trixie
vulnerable
trixie (security)
140.10.0esr-1~deb13u1
fixed
thunderbird
bookworm
vulnerable
bookworm (security)
1:140.10.0esr-1~deb12u1
fixed
bullseye
vulnerable
bullseye (security)
vulnerable
forky
vulnerable
sid
1:140.10.0esr-1
fixed
trixie
vulnerable
trixie (security)
1:140.10.0esr-1~deb13u1
fixed