CVE-2026-0878
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Fir
CVSS
8.0
High
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Jan 13, 2026 · Last modified: Jul 15, 2026 · CWE-20 · CWE-119
0.4%EPSS · 30 days0.4%
2026-06-302026-07-19
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2003989
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-01/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-03/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-04/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-05/
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:0667
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:0694
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:0924
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:1320
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:1413
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:1414
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:1415
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:1461
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:1462
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:1471
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:1487
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:2041
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:2043
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:2044
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:2047
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-341978.8 HIG99.9%
KEV—80Apache ActiveMQ Improper Input Validation Vulnerability5dCVE-2025-312778.8 HIG71.0%
KEV—71Apple Multiple Products Buffer Overflow Vulnerability5dCVE-2026-125699.8 CRI66.0%
KEV—70PTC Windchill and FlexPLM Improper Input Validation Vulnerability20dCVE-2025-607877.2 HIG97.0%
——29MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.15dCVE-2005-445910.0 NO 96.2%
——29Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.13dCVE-2017-149197.5 HIG94.3%
——28Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.6d