CVE-2026-2781
Severity
Critical
CVSS score
9.8Package
nssAffected versions
>= 2:3.87.1-1+deb12u1, < 2:3.110-1+e2An integer overflow exists in the Libraries component of NSS. This vulnerability impacts Firefox versions earlier than 148, Firefox ESR versions earlier than 140.8, Thunderbird versions earlier than 148, and Thunderbird ESR versions earlier than 140.8.
NVD Record:
References:
- https://bugzilla.mozilla.org/show_bug.cgi?id=2009552
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://lists.debian.org/debian-lts-announce/2026/03/msg00012.html