Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nss | Jul 30, 2026 | Jul 30, 2026 |
| Mfsa2026 68 | — | Upgrade to Mozilla Firefox version 153.0Upgrade to the latest version of Mozilla Firefox | Jul 21, 2026 | Jul 21, 2026 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 153.0Upgrade to the latest version of Mozilla Thunderbird | Jul 21, 2026 | Jul 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2026 | Jul 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub