CVE-2026-7320
גבוהה 7.5
תיאור (מקור, אנגלית)
Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-30/7/2026
- CWE
- CWE-119, CWE-125
מוצרים מושפעים
mozilla: firefox; mozilla: thunderbird
קישורים
- https://www.mozilla.org/security/advisories/mfsa2026-35/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-36/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-37/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-38/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-39/ Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=2027433 Permissions Required
- https://access.redhat.com/errata/RHSA-2026:19153
- https://access.redhat.com/errata/RHSA-2026:19157
- https://access.redhat.com/errata/RHSA-2026:19348
- https://access.redhat.com/errata/RHSA-2026:19370