| CVE-2026-40261 |
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnera... |
Important |
composer |
是 |
完成修复 |
2026-04-16 |
2026-06-24 |
| CVE-2026-40176 |
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnera... |
Important |
composer |
是 |
完成修复 |
2026-04-16 |
2026-06-24 |
| CVE-2026-6067 |
A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directi... |
Important |
nasm |
是 |
完成修复 |
2026-04-15 |
2026-06-24 |
| CVE-2026-4786 |
A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing "%action" is processed, an attacker... |
Important |
python3, python36:3.6, python3.11, python, python3.12 |
是 |
完成修复 |
2026-04-15 |
2026-06-24 |
| CVE-2026-6100 |
A flaw was found in Python's decompression modules, including lzma.LZMADecompressor, bz2.BZ2Decompressor, and `gzip.GzipFil... |
Important |
python3, python36:3.6, python3.11, python, python3.12 |
是 |
完成修复 |
2026-04-14 |
2026-06-24 |
| CVE-2026-40226 |
A flaw was found in nspawn, a container runtime environment within systemd. A local attacker or a process within an nspawn cont... |
Important |
rpm-ostree, systemd, NetworkManager |
是 |
完成修复 |
2026-04-14 |
2026-06-24 |
| CVE-2026-40225 |
A flaw was found in udev in systemd. A local user with access to malicious hardware devices can exploit this vulnerability. By ... |
Important |
systemd, NetworkManager |
是 |
完成修复 |
2026-04-14 |
2026-06-24 |
| CVE-2026-33908 |
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 ... |
Important |
ImageMagick |
是 |
完成修复 |
2026-04-14 |
2026-06-24 |
| CVE-2026-33810 |
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard... |
Important |
golang, container-tools:an8, osbuild-composer, trustee, skopeo, weldr-client, grafana-pcp, git-lfs, go-toolset:an8, grafana |
否 |
完成修复 |
2026-04-14 |
2026-07-08 |
| CVE-2026-31427 |
A flaw was found in the Linux kernel's netfilter subsystem, specifically within the nf_conntrack_sip module. This vulnerability... |
Important |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
是 |
完成修复 |
2026-04-14 |
2026-08-03 |
| CVE-2026-31424 |
A flaw was found in the Linux kernel's netfilter subsystem, specifically within the x_tables and arptables components. This vul... |
Important |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
是 |
完成修复 |
2026-04-14 |
2026-08-03 |
| CVE-2026-31421 |
A flaw was found in the Linux kernel's cls_fw network scheduler component. This vulnerability, a null pointer dereference, oc... |
Important |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
是 |
完成修复 |
2026-04-14 |
2026-08-03 |
| CVE-2026-31419 |
In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast(... |
Important |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
是 |
完成修复 |
2026-04-14 |
2026-08-03 |
| CVE-2026-4631 |
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without va... |
Critical |
cockpit |
是 |
完成修复 |
2026-04-13 |
2026-07-08 |
| CVE-2026-34486 |
A flaw was found in Apache Tomcat. This vulnerability, categorized as Missing Encryption of Sensitive Data, arises from a bypas... |
Important |
pki-deps:10.6, tomcat |
是 |
完成修复 |
2026-04-13 |
2026-06-24 |
| CVE-2026-27140 |
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build t... |
Important |
go-toolset:an8 |
是 |
完成修复 |
2026-04-13 |
2026-06-26 |
| CVE-2025-14861 |
Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with eno... |
Important |
firefox |
是 |
完成修复 |
2026-04-13 |
2026-06-26 |
| CVE-2025-14860 |
Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1. |
Important |
firefox |
是 |
完成修复 |
2026-04-13 |
2026-06-26 |
| CVE-2026-4878 |
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the... |
Important |
libcap |
是 |
完成修复 |
2026-04-10 |
2026-06-24 |
| CVE-2026-29146 |
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tom... |
Important |
pki-deps:10.6, tomcat |
是 |
完成修复 |
2026-04-10 |
2026-06-24 |
| CVE-2026-5735 |
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption ... |
Important |
firefox, thunderbird |
是 |
完成修复 |
2026-04-09 |
2026-06-26 |
| CVE-2026-5734 |
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of th... |
Important |
firefox, thunderbird |
是 |
完成修复 |
2026-04-09 |
2026-06-26 |
| CVE-2026-5731 |
Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbi... |
Important |
firefox, thunderbird |
是 |
完成修复 |
2026-04-09 |
2026-06-26 |
| CVE-2026-39881 |
A flaw was found in Vim. A command injection vulnerability in Vim's NetBeans interface allows a malicious NetBeans server to ex... |
Important |
vim |
是 |
完成修复 |
2026-04-09 |
2026-06-24 |
| CVE-2026-28808 |
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by d... |
Important |
erlang |
是 |
完成修复 |
2026-04-09 |
2026-06-26 |
| CVE-2026-5733 |
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 149.0.2 and Thunderbird <... |
Important |
firefox, thunderbird |
是 |
完成修复 |
2026-04-08 |
2026-06-26 |
| CVE-2026-5732 |
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability affects Firefox < 149.0.2, ... |
Important |
firefox, thunderbird |
是 |
完成修复 |
2026-04-08 |
2026-06-26 |
| CVE-2026-5663 |
A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStud... |
Important |
dcmtk |
是 |
完成修复 |
2026-04-08 |
2026-06-26 |
| CVE-2026-31789 |
Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 3... |
Important |
openssl |
是 |
完成修复 |
2026-04-08 |
2026-06-26 |
| CVE-2026-24660 |
A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially c... |
Important |
LibRaw, libraw1394 |
是 |
完成修复 |
2026-04-08 |
2026-06-24 |
| CVE-2026-21413 |
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Comm... |
Important |
LibRaw, libraw1394 |
是 |
完成修复 |
2026-04-08 |
2026-06-24 |
| CVE-2026-20911 |
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d... |
Important |
LibRaw, libraw1394 |
是 |
完成修复 |
2026-04-08 |
2026-06-24 |
| CVE-2026-20889 |
A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially c... |
Important |
LibRaw, libraw1394 |
是 |
完成修复 |
2026-04-08 |
2026-06-24 |
| CVE-2026-35385 |
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectat... |
Important |
openssh |
是 |
完成修复 |
2026-04-07 |
2026-06-24 |
| CVE-2026-34982 |
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary O... |
Important |
vim |
是 |
完成修复 |
2026-04-07 |
2026-06-24 |
| CVE-2026-34589 |
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion ... |
Important |
OpenEXR |
是 |
完成修复 |
2026-04-07 |
2026-06-24 |
| CVE-2026-34588 |
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion ... |
Important |
OpenEXR |
是 |
完成修复 |
2026-04-07 |
2026-06-24 |
| CVE-2026-34379 |
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion ... |
Important |
OpenEXR |
是 |
完成修复 |
2026-04-07 |
2026-06-24 |
| CVE-2026-31402 |
A flaw was found in the Linux kernel's NFSv4.0 server (nfsd). A remote, unauthenticated attacker can exploit this heap overflow... |
Important |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
是 |
完成修复 |
2026-04-07 |
2026-08-03 |
| CVE-2026-31394 |
A flaw was found in the Linux kernel's mac80211 component. This vulnerability occurs when processing stations on AP_VLAN interf... |
Moderate |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
否 |
完成修复 |
2026-04-07 |
2026-06-24 |
| CVE-2026-23461 |
A flaw was found in the Linux kernel's Bluetooth L2CAP component. A race condition exists due to inconsistent locking mechanism... |
Moderate |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
否 |
完成修复 |
2026-04-07 |
2026-06-24 |
| CVE-2026-23455 |
A flaw was found in the Linux kernel's netfilter subsystem, specifically within the nf_conntrack_h323 module. This vulnerabil... |
Important |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
是 |
完成修复 |
2026-04-07 |
2026-08-03 |
| CVE-2026-23450 |
A flaw was found in the Linux kernel's net/smc component. A remote attacker could exploit a race condition during the concurren... |
Important |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
是 |
完成修复 |
2026-04-07 |
2026-08-03 |
| CVE-2026-23428 |
A flaw was found in ksmbd, a component of the Linux kernel. This use-after-free vulnerability occurs during the processing of S... |
Important |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
是 |
完成修复 |
2026-04-07 |
2026-08-03 |
| CVE-2026-23427 |
A flaw was found in ksmbd, a component within the Linux kernel that provides server message block (SMB) functionality. This vul... |
Important |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
否 |
完成修复 |
2026-04-07 |
2026-06-24 |
| CVE-2026-35535 |
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before runni... |
Important |
sudo |
是 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-34743 |
XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_deco... |
Important |
xz |
是 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-34545 |
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion ... |
Important |
OpenEXR |
是 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-34543 |
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion ... |
Important |
OpenEXR |
是 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-23417 |
A flaw was found in the Linux kernel's Berkeley Packet Filter (BPF) component. This vulnerability occurs because the BPF_ST | B... |
Low |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
否 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-23416 |
A flaw was found in the Linux kernel. An issue in the memory management (mm/mseal) component, specifically during the merging o... |
Low |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
否 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-23415 |
A flaw was found in the Linux kernel. A timing issue, known as a race condition, exists within the futex subsystem. This vulner... |
Moderate |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
否 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-23414 |
A flaw was found in the Linux kernel's Transport Layer Security (TLS) subsystem. When processing TLS messages, a memory leak ca... |
Moderate |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
否 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-23413 |
A flaw was found in the Linux kernel's clsact qdisc. This use-after-free vulnerability occurs due to an asymmetry in the initia... |
Moderate |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
否 |
完成修复 |
2026-04-03 |
2026-06-24 |
| CVE-2026-4800 |
Impact:\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable optio... |
Important |
grafana, pcs, cockpit-appstream, ceph, cockpit, ipa, mozjs60, gjs, container-tools:an8, grafana-pcp, firefox, thunderbird, qt5-qtbase |
是 |
完成修复 |
2026-04-02 |
2026-06-26 |
| CVE-2026-35093 |
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user co... |
Important |
libinput |
是 |
完成修复 |
2026-04-02 |
2026-06-24 |
| CVE-2026-23411 |
A flaw was found in the Linux kernel's AppArmor security module. A race condition occurs when AppArmor incorrectly manages the ... |
Important |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
是 |
完成修复 |
2026-04-02 |
2026-08-03 |
| CVE-2026-23410 |
A flaw was found in the Linux kernel's AppArmor security module. This vulnerability, a race condition, allows a local attacker ... |
Important |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
是 |
完成修复 |
2026-04-02 |
2026-08-03 |
| CVE-2026-5201 |
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due t... |
Important |
gdk-pixbuf2, librsvg2 |
是 |
完成修复 |
2026-04-01 |
2026-06-24 |
| CVE-2026-34714 |
A flaw was found in Vim. This vulnerability allows an attacker to execute malicious code on a user's system. This occurs when a... |
Important |
vim |
是 |
完成修复 |
2026-03-31 |
2026-07-09 |
| CVE-2026-28859 |
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Taho... |
Important |
webkitgtk4, webkitgtk, webkitgtk3, webkit2gtk3 |
是 |
完成修复 |
2026-03-31 |
2026-07-09 |
| CVE-2026-28857 |
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Taho... |
Important |
webkitgtk4, webkitgtk, webkitgtk3, webkit2gtk3 |
是 |
完成修复 |
2026-03-31 |
2026-07-09 |
| CVE-2026-21710 |
A flaw in Node.js HTTP request handling causes an uncaught TypeError when a request is received with a header named `_proto... |
Important |
nodejs:20, nodejs |
是 |
完成修复 |
2026-03-31 |
2026-07-09 |
| CVE-2026-20664 |
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Taho... |
Important |
webkitgtk4, webkitgtk, webkitgtk3, webkit2gtk3 |
是 |
完成修复 |
2026-03-31 |
2026-07-09 |
| CVE-2026-4926 |
Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), su... |
Important |
mozjs60, gjs, pcs |
是 |
完成修复 |
2026-03-29 |
2026-07-09 |
| CVE-2026-33941 |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars ... |
Important |
mozjs60, thunderbird, firefox, 389-ds:1.4, grafana |
是 |
完成修复 |
2026-03-29 |
2026-07-09 |
| CVE-2026-33940 |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted objec... |
Important |
mozjs60, thunderbird, firefox, 389-ds:1.4, grafana |
是 |
完成修复 |
2026-03-29 |
2026-07-09 |
| CVE-2026-33939 |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handleba... |
Important |
mozjs60, thunderbird, firefox, grafana |
是 |
完成修复 |
2026-03-29 |
2026-07-09 |
| CVE-2026-33938 |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-b... |
Important |
mozjs60, thunderbird, firefox, 389-ds:1.4, grafana |
是 |
完成修复 |
2026-03-29 |
2026-07-09 |
| CVE-2026-33937 |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.com... |
Important |
mozjs60, thunderbird, firefox, 389-ds:1.4, grafana |
是 |
完成修复 |
2026-03-29 |
2026-07-09 |
| CVE-2026-23398 |
In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_validatio... |
Important |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
是 |
完成修复 |
2026-03-28 |
2026-08-03 |
| CVE-2026-34352 |
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause a... |
Important |
tigervnc |
是 |
完成修复 |
2026-03-27 |
2026-07-09 |
| CVE-2026-33150 |
libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulne... |
Important |
fuse-sshfs, fuse3, fuse |
是 |
完成修复 |
2026-03-27 |
2026-06-26 |
| CVE-2026-29063 |
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution... |
Important |
pcs, mozjs60, gjs, grafana |
是 |
完成修复 |
2026-03-27 |
2026-07-09 |
| CVE-2026-33186 |
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from imprope... |
Important |
osbuild-composer, container-tools:an8, trustee, skopeo, grafana-pcp, grpc, grafana |
是 |
完成修复 |
2026-03-26 |
2026-07-09 |
| CVE-2026-3104 |
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.\nThis issue af... |
Important |
bind, bind9.16 |
是 |
完成修复 |
2026-03-26 |
2026-07-09 |
| CVE-2026-23394 |
A flaw was found in the Linux kernel's af_unix component. A race condition exists between the MSG_PEEK operation and the garbag... |
Moderate |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
否 |
完成修复 |
2026-03-26 |
2026-06-24 |
| CVE-2026-23393 |
A flaw was found in the Linux kernel's bridge Connectivity Fault Management (CFM) component. A race condition can occur during ... |
Important |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
是 |
完成修复 |
2026-03-26 |
2026-08-03 |
| CVE-2026-23362 |
A flaw was found in the Linux kernel's Controller Area Network (CAN) Broadcast Manager (BCM) module. When the RX_RTR_FRAME flag... |
Moderate |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
否 |
完成修复 |
2026-03-26 |
2026-06-24 |
| CVE-2026-23321 |
A flaw was found in the Linux kernel's Multipath TCP (MPTCP) implementation. A local user can exploit this vulnerability by per... |
Moderate |
kernel:5.10, kernel:4.19, kernel:4.18, kernel:6.6 |
否 |
完成修复 |
2026-03-26 |
2026-06-24 |
| CVE-2026-23281 |
A flaw was found in the Linux kernel's Marvell Libertas Wi-Fi driver. This vulnerability, a use-after-free, occurs because the ... |
Important |
kernel:6.6, kernel:4.18, kernel:5.10, kernel:4.19 |
是 |
完成修复 |
2026-03-26 |
2026-08-03 |
| CVE-2026-1519 |
A flaw was found in BIND. A remote attacker could exploit this vulnerability by sending a maliciously crafted DNSSEC-validated ... |
Important |
bind9.16, bind |
是 |
完成修复 |
2026-03-26 |
2026-07-09 |
| CVE-2026-4775 |
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcont... |
Important |
libtiff, compat-libtiff3, mingw-libtiff |
是 |
完成修复 |
2026-03-25 |
2026-06-24 |
| CVE-2026-4729 |
Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we p... |
Important |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4728 |
Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability affects Firefox < 149 and Thunderbird < 149. |
Low |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4727 |
Denial-of-service in the Libraries component in NSS. This vulnerability affects Firefox < 149 and Thunderbird < 149. |
Low |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4726 |
Denial-of-service in the XML component. This vulnerability affects Firefox < 149 and Thunderbird < 149. |
Low |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4725 |
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149 and Thunderb... |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4724 |
Undefined behavior in the Audio/Video component. This vulnerability affects Firefox < 149 and Thunderbird < 149. |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4723 |
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149 and Thunderbird < 149. |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4722 |
Privilege escalation in the IPC component. This vulnerability affects Firefox < 149 and Thunderbird < 149. |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4721 |
Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. So... |
Important |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4720 |
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs sho... |
Important |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4719 |
Incorrect boundary conditions in the Graphics: Text component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, T... |
Low |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4718 |
Undefined behavior in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbi... |
Low |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4717 |
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < ... |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4716 |
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 14... |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4715 |
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunde... |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4714 |
Incorrect boundary conditions in the Audio/Video component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thun... |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |
| CVE-2026-4713 |
Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunder... |
Moderate |
thunderbird, firefox |
是 |
完成修复 |
2026-03-25 |
2026-06-26 |