Security News

Cybersecurity news aggregator

🦊
CRITICAL Vulnerabilities Web Discovery

NVD - CVE-2026-0892

CVE-2026-0892 is a critical memory safety vulnerability in Mozilla Firefox
Read Full Article →

Vulnerabilities CVE-2026-0892 Detail Description Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. ADP: CISA-ADP Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS 2.0 Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected] . URL Source(s) Tag(s) https://bugzilla.mozilla.org/buglist.cgi?bug_id=1986912%2C1996718%2C1999633%2C2001081%2C2004443 Mozilla Corporation Broken Link https://www.mozilla.org/security/advisories/mfsa2026-01/ Mozilla Corporation Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2026-04/ Mozilla Corporation Vendor Advisory Weakness Enumeration CWE-ID CWE Name Source CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer CISA-ADP Known Affected Software Configurations Switch to CPE 2.2 CPEs loading, please wait. Change History 4 change records found show changes Initial Analysis by NIST 1/22/2026 2:14:32 PM Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* versions up to (excluding) 147.0 *cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* versions up to (excluding) 147.0 Added Reference Type Mozilla Corporation: https://bugzilla.mozilla.org/buglist.cgi?bug_id=1986912%2C1996718%2C1999633%2C2001081%2C2004443 Types: Broken Link Added Reference Type Mozilla Corporation: https://www.mozilla.org/security/advisories/mfsa2026-01/ Types: Vendor Advisory Added Reference Type Mozilla Corporation: https://www.mozilla.org/security/advisories/mfsa2026-04/ Types: Vendor Advisory CVE Modified by Mozilla Corporation 1/15/2026 5:16:08 AM Action Type Old Value New Value Changed Description Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147. Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147. Added Reference https://www.mozilla.org/security/advisories/mfsa2026-04/ CVE Modified by CISA-ADP 1/13/2026 10:16:00 AM Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-119 New CVE Received from Mozilla Corporation 1/13/2026 9:16:39 AM Action Type Old Value New Value Added Description Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147. Added Reference https://bugzilla.mozilla.org/buglist.cgi?bug_id=1986912%2C1996718%2C1999633%2C2001081%2C2004443 Added Reference https://www.mozilla.org/security/advisories/mfsa2026-01/ Quick Info CVE Dictionary Entry: CVE-2026-0892 NVD Published Date: 01/13/2026 NVD Last Modified: 01/22/2026 Source: Mozilla Corporation

Share this article