CVE-2026-100779
CVE-2026-100779
8.8
HighPublished:
Last updated:
Source:security@mozilla.org
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
References
security@mozilla.org
https://bugzilla.mozilla.org/show_bug.cgi?id=2068417security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-100/security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-101/security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-102/security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-103/security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-97/security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-98/security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-99/