VDB

DEBIAN-CVE-2026-2447

DEBIAN-CVE-2026-2447 PUBLISHED CVSS 8.800000190734863 HIGH

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11thunderbird78.13.0-1, 78.13.0-1, 78.14.0-1
Debian:13libvpx0, 1.15.0-2.1, 0
Debian:14firefox-esr140.8.0, 140.7.0, 140.7.0
Debian:12libvpx1.12.0-1, 1.12.0-1+deb12u3, 1.12.0-1
Debian:13thunderbird*, *, 1:140.6.0esr-1~deb13u1
Debian:14libvpx0, 1.15.0-2.1, 1.15.2-1
Debian:14thunderbird1:140.3.0esr-1~deb11u1, 1:140.3.0esr-1~deb13u1, 1:140.3.1esr-1
Debian:11libvpx1.9.0-1, 1.9.0-1, 1.9.0-1
Debian:12thunderbird120.0, 1:102.11.0-1, 1:102.12.0-1
Debian:13firefox-esr*, *, *
Debian:12firefox-esr0, 102.12.0esr-1, 102.12.0esr-1~deb11u1
Debian:11firefox-esr140.4.0, 140.4.0, 140.4.0

Exploit Intelligence

Timeline

  • Feb 16, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›