Memory Safety Issues in Firefox ESR and Firefox Products by Mozilla
CVE-2026-8974
8.8HIGH
What is CVE-2026-8974?
Mozilla Firefox ESR versions 140.10 and Firefox 150 contain critical memory safety bugs that may lead to memory corruption, potentially allowing attackers to execute arbitrary code with sufficient effort. These vulnerabilities have been addressed in the latest updates with Firefox version 151 and Firefox ESR 140.11, emphasizing the importance of keeping software up to date to mitigate security risks.
Affected Version(s)
Firefox 140.11
Firefox 151
Thunderbird 140.11
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nika Layzell, Randell Jesup, Timothy Nikkel, Tom Schuster and the Mozilla Fuzzing Team