CVE-2026-6783
published 2026-04-21CVE-2026-6783: Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.23%
13.9th percentile
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150 | Firefox 150 |
| mozilla | firefox | < 150.0 | 150.0 |
| mozilla | thunderbird | < Thunderbird 150 | Thunderbird 150 |
| mozilla | thunderbird | < 150.0 | 150.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 149 Playback integer overflow (Nessus ID 310623 / WID-SEC-2026-1228)
vuldb·2026-05-21·CVSS 5.3
CVE-2026-6783 [MEDIUM] Mozilla Firefox up to 149 Playback integer overflow (Nessus ID 310623 / WID-SEC-2026-1228)
A vulnerability categorized as critical has been discovered in Mozilla Firefox up to 149. Affected is an unknown function of the component Playback. Such manipulation leads to integer overflow.
This vulnerability is listed as CVE-2026-6783. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
GHSA-cp9h-w8px-6q24: Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component
ghsa_unreviewed·2026-04-21
CVE-2026-6783 [MEDIUM] CWE-190 GHSA-cp9h-w8px-6q24: Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150.
Red Hat
firefox: Firefox: Arbitrary code execution or denial of service in Audio/Video Playback component
vendor_redhat·2026-04-21·CVSS 5.3
CVE-2026-6783 [MEDIUM] CWE-190 firefox: Firefox: Arbitrary code execution or denial of service in Audio/Video Playback component
firefox: Firefox: Arbitrary code execution or denial of service in Audio/Video Playback component
A flaw was found in Firefox. This memory corruption vulnerability, located in the Audio/Video Playback component, is caused by incorrect boundary conditions and an integer overflow. A remote attacker could potentially exploit this flaw by enticing a user to process specially crafted media content. Successful exploitation may lead to arbitrary code execution or a denial of service.
Mozilla
Mozilla Foundation Security Advisory 2026-30: CVE-2026-6783
vendor_mozilla·CVSS 5.3
CVE-2026-6783 [MEDIUM] Mozilla Foundation Security Advisory 2026-30: CVE-2026-6783
Mozilla Foundation Security Advisory 2026-30
CVE: CVE-2026-6783
Product: Firefox
Impact: high
Fixed in: Firefox 150
Mozilla
Mozilla Foundation Security Advisory 2026-33: CVE-2026-6783
vendor_mozilla·CVSS 5.3
CVE-2026-6783 [MEDIUM] Mozilla Foundation Security Advisory 2026-33: CVE-2026-6783
Mozilla Foundation Security Advisory 2026-33
CVE: CVE-2026-6783
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150
No detection rules found.
No public exploits indexed.
2026-04-21
Published