Description
Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Immediate Patch
AI Analysis

Impact

An incorrect boundary check in the DOM animation component can corrupt memory when an attacker supplies crafted content. This off‑by‑one error leads to behavior such as memory corruption.

Affected Systems

Mozilla’s Firefox and Thunderbird are affected. All releases before version 156 contain the flaw; users must upgrade to Firefox 156 or later and Thunderbird 156 or later.

Risk and Exploitability

The EPSS score is less than 1 % and the flaw is not listed in the CISA KEV catalog, suggesting a low exploitation probability. The CVE description indicates that an incorrect boundary check in the DOM animation component can lead to memory corruption when crafted content is processed. Based on this, it is inferred that a local attacker might exploit the flaw by opening a malicious web page or email message, though the official description does not explicitly state the attack vector. The resulting memory corruption could lead to denial of service or application crash, and the high CVSS score of 9.8 places the vulnerability at high overall risk.

Generated by OpenCVE AI on September 21, 2026 at 22:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Firefox update to version 156 or later
  • Apply Thunderbird update to version 156 or later
  • Enable automatic updates for the browser and email client to keep security patches up to date

Generated by OpenCVE AI on September 21, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-193

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-193

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156. Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
References

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156.
Title Incorrect boundary conditions in the DOM: Animation component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T17:21:20.983Z

Reserved: 2026-09-15T12:33:57.568Z

Link: CVE-2026-92037

cve-icon Vulnrichment

Updated: 2026-09-21T17:20:15.468Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:55.067

Modified: 2026-10-05T17:57:34.003

Link: CVE-2026-92037

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T12:33:58Z

Links: CVE-2026-92037 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T22:15:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write