CVE-2026-74947
EUVD-2026-6067718.08.2026, 13:17
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mozilla | firefox | 𝑥 < 154.0.0 | CNA |
| mozilla | firefox_esr | 141.0.0 ≤ 𝑥 < 153.1.0 | CNA |
| mozilla | thunderbird | 𝑥 < 154.0 | CNA |
| mozilla | thunderbird_esr | 141.0.0 ≤ 𝑥 < 153.1.0 | CNA |
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||
| thunderbird |
| ||||||||||
| mozjs38 |
| ||||||||||
| mozjs52 |
| ||||||||||
| mozjs68 |
| ||||||||||
| mozjs78 |
| ||||||||||
| mozjs91 |
| ||||||||||
| mozjs102 |
| ||||||||||
| mozjs115 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| MozillaFirefox |
| ||||||||||||||||||||||||
| MozillaFirefox-branding-SLE-153 |
| ||||||||||||||||||||||||
| MozillaFirefox-devel |
| ||||||||||||||||||||||||
| MozillaFirefox-translations-common |
| ||||||||||||||||||||||||
| MozillaFirefox-translations-other |
|
Common Weakness Enumeration
Vulnerability Media Exposure