Description
Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Published: 2026-09-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A malicious PDF file can trigger a crash in the PDF Viewer component of Mozilla Firefox and Thunderbird, resulting in the application terminating unexpectedly. The crash causes a denial of service that is local to the user’s session, blocking access to web content and potentially disrupting automated scripts or kiosk operations. The vulnerability is caused by insufficient resource handling and memory safety problems, identified as CWE‑400. Based on the description, it is inferred that the attacker must supply a carefully crafted PDF to trigger the crash; the vulnerable code does not perform adequate checks on input data and can be exploited via a supply‑of‑malformed PDF. The CVSS score of 7.5 reflects the local impact and the requirement for the victim to open the malicious PDF.

Affected Systems

All installations of Mozilla Firefox or Thunderbird older than version 155 are affected.

Risk and Exploitability

The EPSS score indicates a very low exploitation probability of less than 1 %, and the vulnerability is not listed in the CISA KEV catalog. The high CVSS score of 7.5 highlights the local denial‑of‑service risk when a user opens a malicious PDF. The attacker only needs to supply the crafted file; once processed, the PDF Viewer crashes, resulting in service disruption on the victim’s machine.

Generated by OpenCVE AI on September 3, 2026 at 22:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest release of Mozilla Firefox or Thunderbird (v155 or newer), which contains the fix for this crash.
  • If upgrading is not immediately possible, temporarily disable the built‑in PDF viewer via browser settings or use a separate PDF reader that is not patched.
  • Enable automatic updates on the operating system or ensure that the browser auto‑updates are active to receive the fix without manual intervention.

Generated by OpenCVE AI on September 3, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-787

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
Weaknesses CWE-400
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Wed, 02 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-787

Wed, 02 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-400

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155. Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
References

Tue, 01 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-400

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155.
Title Denial-of-service in the PDF Viewer component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-03T17:24:04.292Z

Reserved: 2026-09-01T07:25:51.081Z

Link: CVE-2026-84138

cve-icon Vulnrichment

Updated: 2026-09-03T16:49:32.301Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T13:20:07.920

Modified: 2026-09-03T18:17:26.290

Link: CVE-2026-84138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T22:30:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption