CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

History

16 Jun 2026, 20:57

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2044738 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2044738 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-58/ - () https://www.mozilla.org/security/advisories/mfsa2026-58/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-61/ - () https://www.mozilla.org/security/advisories/mfsa2026-61/ - Vendor Advisory
First Time Mozilla
Mozilla thunderbird
Mozilla firefox
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

16 Jun 2026, 17:16

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2026-61/ -
Summary (en) Memory safety bug fixed in Firefox ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12. (en) Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
CWE CWE-119
CWE-416
CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

16 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-16 13:16

Updated : 2026-06-16 20:57


NVD link : CVE-2026-12329

Mitre link : CVE-2026-12329

CVE.ORG link : CVE-2026-12329


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-416

Use After Free

CWE-476

NULL Pointer Dereference