AI description
Automated description summarized from trusted sources.
CVE-2026-84124 is a use-after-free vulnerability found within the DOM: Core & HTML component. This flaw was addressed by Mozilla in several product updates. Specifically, the vulnerability was patched in Firefox version 155, Firefox ESR versions 140.15 and 153.2, and corresponding Thunderbird versions 140.15, 153.2, and 155.
- Description
- Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Source
- security@mozilla.org
- NVD status
- Analyzed
- Products
- firefox, thunderbird
CVSS 3.1
- Type
- Secondary
- Base score
- 5.4
- Impact score
- 2.5
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- Severity
- MEDIUM
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-416
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
8
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BE9E1C22-F823-464B-8880-B10B988BEE3B",
"versionEndExcluding": "140.15.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BAC56AB7-FB63-4A76-BFBD-4C0122F2A93C",
"versionEndExcluding": "153.2.0",
"versionStartIncluding": "141.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "56769A1A-4A97-4814-8963-24B7AFD7E44F",
"versionEndExcluding": "155.0.0",
"versionStartIncluding": "154.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EC44CB46-89FD-40DC-92D1-F865A0521D06",
"versionEndExcluding": "140.15.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B217A29A-45B5-407C-9B4B-96CF6EB0838E",
"versionEndExcluding": "153.2.0",
"versionStartIncluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C6AB910B-074A-42F7-A3C7-B7E822011D92",
"versionEndExcluding": "155.0",
"versionStartIncluding": "154.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]