Description
Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
Published: 2026-05-07
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Memory safety bugs were present in older releases of Mozilla Firefox: Firefox ESR 115.35.1, Firefox ESR 140.10.1, and Firefox 150.0.1. The bugs exhibit out‑of‑bounds reads, writes, and use‑after‑free conditions that can corrupt memory. The vendor presumes that with sufficient effort, these defects could be exploited to run arbitrary code within the affected application’s process.

Affected Systems

End users running Mozilla Thunderbird ESR 140.10.1, Thunderbird 150.0.1, Firefox 150.0.1, Firefox ESR 140.10.1 or Firefox ESR 115.35.1 remain vulnerable. The issues were addressed in Thunderbird 140.10.2 and 150.0.2, and in Firefox 150.0.2, Firefox ESR 140.10.2 and Firefox ESR 115.35.2. Any installation that has not yet migrated to these releases continues to be at risk.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity, while the EPSS score of <1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog and no public exploits are known. The flaw does not provide direct network access or privilege escalation; it requires crafted email or web content that is processed by the affected browser or mail client to trigger the memory corruption and potentially hijack control flow.

Generated by OpenCVE AI on May 18, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Thunderbird to the patched releases 140.10.2 or 150.0.2.
  • Upgrade Mozilla Firefox to the corresponding patched releases 150.0.2, Firefox ESR 140.10.2, or Firefox ESR 115.35.2.
  • Ensure all extensions or add‑ons that interact with Thunderbird or Firefox are updated to their latest versions to avoid any exposed memory paths.
  • If an immediate update is not possible, disable the rendering of external images or remote content to reduce the chance that malicious data activates the defect.

Generated by OpenCVE AI on May 18, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4575-1 firefox-esr security update
Debian DLA Debian DLA DLA-4582-1 thunderbird security update
Debian DSA Debian DSA DSA-6254-1 firefox-esr security update
Debian DSA Debian DSA DSA-6267-1 thunderbird security update
History

Mon, 18 May 2026 08:00:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2. Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
Title Memory safety bugs fixed in Thunderbird ESR 140.10.2 and Thunderbird 150.0.2 Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2

Mon, 11 May 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
Vendors & Products Mozilla thunderbird

Sat, 09 May 2026 00:15:00 +0000


Fri, 08 May 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 08 May 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-416
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 08 May 2026 13:00:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, and Firefox ESR 115.35.2. Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
Title Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 Memory safety bugs fixed in Thunderbird ESR 140.10.2 and Thunderbird 150.0.2
References

Thu, 07 May 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Thu, 07 May 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Thu, 07 May 2026 13:00:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, and Firefox ESR 115.35.2.
Title Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-19T16:48:31.003Z

Reserved: 2026-05-07T12:45:06.414Z

Link: CVE-2026-8092

cve-icon Vulnrichment

Updated: 2026-05-08T14:09:20.593Z

cve-icon NVD

Status : Modified

Published: 2026-05-07T13:16:14.203

Modified: 2026-05-18T08:16:14.850

Link: CVE-2026-8092

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-07T12:45:06Z

Links: CVE-2026-8092 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-18T09:30:22Z

Weaknesses