CVE-2026-8949
published 2026-05-19CVE-2026-8949: Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 151 | Firefox 151 |
| mozilla | firefox | < 140.11.0 | 140.11.0 |
| mozilla | firefox | < 151.0.0 | 151.0.0 |
| mozilla | firefox_esr | < Firefox ESR 140.11 | Firefox ESR 140.11 |
| mozilla | thunderbird | < Thunderbird 151 | Thunderbird 151 |
| mozilla | thunderbird | < Thunderbird 140.11 | Thunderbird 140.11 |
| mozilla | thunderbird | < 140.11 | 140.11 |
| mozilla | thunderbird | < 151.0.0 | 151.0.0 |