High
CVE-2026-4371
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside th…
High
CVE-2026-4722
Privilege escalation in the IPC component. This vulnerability affects Firefox < 149 and Thunderbird < 149.
Critical
CVE-2026-4723
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149 and Thunderbird < 149.
Critical
CVE-2026-4724
Undefined behavior in the Audio/Video component. This vulnerability affects Firefox < 149 and Thunderbird < 149.
Critical
CVE-2026-4725
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149 and T…
High
CVE-2026-4726
Denial-of-service in the XML component. This vulnerability affects Firefox < 149 and Thunderbird < 149.