CVE-2026-2447

HIGH

libvpx - Buffer Overflow

Title source: llm
STIX 2.1

Description

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 5.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (8)
mozilla/firefox < 115.32.1
mozilla/firefox < 147.0.4
Mozilla/Firefox 115.32.1 - 115.*
Mozilla/Firefox 140.7.1 - 140.*
Mozilla/Firefox 147.0.4
mozilla/thunderbird < 140.7.2
Mozilla/Thunderbird 140.7.2 - 140.*
Mozilla/Thunderbird 147.0.2
Published Feb 16, 2026
Tracked Since Feb 18, 2026