Skip to content
COOEY

EXPOSURES › CVE-2026-84141

CVE-2026-84141

CRITICAL
DETAIL
SourceNVD · cve Published2026-09-01 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-84141 ↗
SHAME 45/100 unpatched

Mozilla Firefox had an integer overflow vulnerability in its ImageLib component that was patched in Firefox 155 and Firefox ESR 153.2.

An integer overflow in Firefox's ImageLib component could theoretically allow remote code execution if exploited, but the source material does not confirm exploitation or RCE. The vulnerability was patched in Firefox 155 and Firefox ESR 153.2. DIB organizations must ensure their browsers are updated to the latest versions to avoid potential exploitation of unpatched vulnerabilities.

Shame score — The vulnerability was patched in a timely manner and was not exploited in the wild, resulting in moderate embarrassment.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.