[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-4684":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":36,"aliases":37,"duplicate_of":9,"upstream":38,"downstream":39,"duplicates":122,"related":123,"reserved_at":9,"published_at":136,"modified_at":137,"state":138,"summary":139,"references_raw":148,"kevs":176,"epss":177,"epss_history":180,"metrics":392,"affected":400},"CVE-2026-4684","Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.",null,[11,28],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-362","Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')","The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.","weakness","Draft","Class","Medium",[20,24],{"id":21,"name":22,"techniques":23},"CAPEC-26","Leveraging Race Conditions",[],{"id":25,"name":26,"techniques":27},"CAPEC-29","Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions",[],{"_key":29,"id":29,"name":30,"description":31,"type":15,"status":32,"abstraction":33,"likelihood_of_exploit":34,"capec":35},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","Stable","Variant","High",[],[],[],[],[40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82,84,86,88,90,92,94,96,98,100,102,104,106,108,110,112,114,116,118,120],{"_key":41},"OPENSUSE-SU-2026:10413-1",{"_key":43},"DSA-6178-1",{"_key":45},"DLA-4510-1",{"_key":47},"DLA-4511-1",{"_key":49},"DSA-6179-1",{"_key":51},"SUSE-SU-2026:1127-1",{"_key":53},"SUSE-SU-2026:1126-1",{"_key":55},"OPENSUSE-SU-2026:10447-1",{"_key":57},"OPENSUSE-SU-2026:10458-1",{"_key":59},"SUSE-SU-2026:1163-1",{"_key":61},"OPENSUSE-SU-2026:20439-1",{"_key":63},"SUSE-SU-2026:20978-1",{"_key":65},"MGASA-2026-0080",{"_key":67},"MGASA-2026-0081",{"_key":69},"UBUNTU-CVE-2026-4684",{"_key":71},"DEBIAN-CVE-2026-4684",{"_key":73},"RHSA-2026:5930",{"_key":75},"RHSA-2026:5931",{"_key":77},"RHSA-2026:5932",{"_key":79},"RHSA-2026:6188",{"_key":81},"RHSA-2026:6342",{"_key":83},"RHSA-2026:6917",{"_key":85},"RHSA-2026:7837",{"_key":87},"RHSA-2026:7838",{"_key":89},"RHSA-2026:7839",{"_key":91},"RHSA-2026:7840",{"_key":93},"RHSA-2026:7841",{"_key":95},"RHSA-2026:7842",{"_key":97},"RHSA-2026:7843",{"_key":99},"RHSA-2026:7845",{"_key":101},"RHSA-2026:7858",{"_key":103},"RHSA-2026:8284",{"_key":105},"RHSA-2026:8285",{"_key":107},"RHSA-2026:8286",{"_key":109},"RHSA-2026:8287",{"_key":111},"RHSA-2026:8288",{"_key":113},"RHSA-2026:8289",{"_key":115},"RHSA-2026:8290",{"_key":117},"RHSA-2026:8315",{"_key":119},"RHSA-2026:8427",{"_key":121},"RHSA-2026:8850",[],[124,125,126,127,128,129,130,131,132,133,134],{"_key":41},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},{"_key":67},{"_key":135},"CGA-C7PM-WXQ4-824C","2026-03-24T12:30:20.420Z","2026-04-13T13:46:22.818Z","Modified",{"cisa_kev":140,"cisa_ransomware":140,"cisa_vendor":9,"epss_severity":141,"epss_score":142,"severity":143,"severity_score":144,"severity_version":145,"severity_source":146,"severity_vector":147,"severity_status":138},false,"low",0.00016,"high",7.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",[149,155,160,164,168,172],{"url":150,"sources":151,"tags":153},"https://bugzilla.mozilla.org/show_bug.cgi?id=2011129",[146,152],"nvd",[154],"Permissions Required",{"url":156,"sources":157,"tags":158},"https://www.mozilla.org/security/advisories/mfsa2026-20/",[146,152],[159],"Vendor Advisory",{"url":161,"sources":162,"tags":163},"https://www.mozilla.org/security/advisories/mfsa2026-21/",[146,152],[159],{"url":165,"sources":166,"tags":167},"https://www.mozilla.org/security/advisories/mfsa2026-22/",[146,152],[159],{"url":169,"sources":170,"tags":171},"https://www.mozilla.org/security/advisories/mfsa2026-23/",[146,152],[],{"url":173,"sources":174,"tags":175},"https://www.mozilla.org/security/advisories/mfsa2026-24/",[146,152],[],[],{"date":178,"score":142,"percentile":179},"2026-06-04",0.03675,[181,185,188,191,194,197,201,204,206,209,212,214,217,219,222,225,228,231,233,236,239,242,245,248,251,254,257,260,263,266,269,272,275,278,281,284,287,290,293,296,299,302,305,308,311,314,317,320,323,326,329,332,335,338,341,344,347,350,353,356,359,362,365,368,371,374,377,380,383,386,388,391],{"date":182,"score":183,"percentile":184},"2026-03-25",0.00014,0.02275,{"date":186,"score":183,"percentile":187},"2026-03-26",0.02286,{"date":189,"score":183,"percentile":190},"2026-03-27",0.02298,{"date":192,"score":183,"percentile":193},"2026-03-28",0.02297,{"date":195,"score":183,"percentile":196},"2026-03-29",0.02291,{"date":198,"score":199,"percentile":200},"2026-03-30",0.00015,0.02777,{"date":202,"score":199,"percentile":203},"2026-03-31",0.02761,{"date":205,"score":199,"percentile":203},"2026-04-01",{"date":207,"score":199,"percentile":208},"2026-04-02",0.02837,{"date":210,"score":199,"percentile":211},"2026-04-03",0.02853,{"date":213,"score":199,"percentile":211},"2026-04-04",{"date":215,"score":199,"percentile":216},"2026-04-05",0.02854,{"date":218,"score":199,"percentile":216},"2026-04-06",{"date":220,"score":199,"percentile":221},"2026-04-07",0.02861,{"date":223,"score":199,"percentile":224},"2026-04-08",0.02863,{"date":226,"score":199,"percentile":227},"2026-04-09",0.02884,{"date":229,"score":199,"percentile":230},"2026-04-10",0.02874,{"date":232,"score":199,"percentile":216},"2026-04-11",{"date":234,"score":199,"percentile":235},"2026-04-12",0.02835,{"date":237,"score":199,"percentile":238},"2026-04-13",0.0283,{"date":240,"score":199,"percentile":241},"2026-04-14",0.02812,{"date":243,"score":199,"percentile":244},"2026-04-15",0.02796,{"date":246,"score":199,"percentile":247},"2026-04-16",0.02814,{"date":249,"score":199,"percentile":250},"2026-04-17",0.02822,{"date":252,"score":199,"percentile":253},"2026-04-18",0.02825,{"date":255,"score":199,"percentile":256},"2026-04-19",0.02817,{"date":258,"score":199,"percentile":259},"2026-04-20",0.02805,{"date":261,"score":199,"percentile":262},"2026-04-21",0.02941,{"date":264,"score":199,"percentile":265},"2026-04-22",0.02953,{"date":267,"score":199,"percentile":268},"2026-04-23",0.02972,{"date":270,"score":199,"percentile":271},"2026-04-24",0.02935,{"date":273,"score":142,"percentile":274},"2026-04-25",0.03629,{"date":276,"score":142,"percentile":277},"2026-04-26",0.03623,{"date":279,"score":142,"percentile":280},"2026-04-27",0.03608,{"date":282,"score":142,"percentile":283},"2026-04-28",0.03651,{"date":285,"score":142,"percentile":286},"2026-04-29",0.03669,{"date":288,"score":142,"percentile":289},"2026-04-30",0.0366,{"date":291,"score":142,"percentile":292},"2026-05-01",0.03657,{"date":294,"score":142,"percentile":295},"2026-05-02",0.03644,{"date":297,"score":142,"percentile":298},"2026-05-03",0.03632,{"date":300,"score":142,"percentile":301},"2026-05-04",0.03626,{"date":303,"score":142,"percentile":304},"2026-05-05",0.03624,{"date":306,"score":142,"percentile":307},"2026-05-06",0.0362,{"date":309,"score":142,"percentile":310},"2026-05-07",0.03645,{"date":312,"score":142,"percentile":313},"2026-05-08",0.03656,{"date":315,"score":142,"percentile":316},"2026-05-09",0.03682,{"date":318,"score":142,"percentile":319},"2026-05-10",0.03698,{"date":321,"score":142,"percentile":322},"2026-05-11",0.03687,{"date":324,"score":142,"percentile":325},"2026-05-12",0.03692,{"date":327,"score":142,"percentile":328},"2026-05-13",0.03718,{"date":330,"score":142,"percentile":331},"2026-05-14",0.03733,{"date":333,"score":142,"percentile":334},"2026-05-15",0.03747,{"date":336,"score":142,"percentile":337},"2026-05-16",0.03757,{"date":339,"score":142,"percentile":340},"2026-05-17",0.03756,{"date":342,"score":142,"percentile":343},"2026-05-18",0.03732,{"date":345,"score":142,"percentile":346},"2026-05-19",0.03725,{"date":348,"score":142,"percentile":349},"2026-05-20",0.03728,{"date":351,"score":142,"percentile":352},"2026-05-21",0.0373,{"date":354,"score":142,"percentile":355},"2026-05-22",0.0391,{"date":357,"score":142,"percentile":358},"2026-05-23",0.03899,{"date":360,"score":142,"percentile":361},"2026-05-24",0.03897,{"date":363,"score":142,"percentile":364},"2026-05-25",0.03873,{"date":366,"score":142,"percentile":367},"2026-05-26",0.03867,{"date":369,"score":142,"percentile":370},"2026-05-27",0.03894,{"date":372,"score":142,"percentile":373},"2026-05-28",0.03868,{"date":375,"score":142,"percentile":376},"2026-05-29",0.03881,{"date":378,"score":142,"percentile":379},"2026-05-30",0.039,{"date":381,"score":142,"percentile":382},"2026-05-31",0.03774,{"date":384,"score":142,"percentile":385},"2026-06-01",0.03708,{"date":387,"score":142,"percentile":325},"2026-06-02",{"date":389,"score":142,"percentile":390},"2026-06-03",0.03679,{"date":178,"score":142,"percentile":179},[393,398],{"source":146,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":394,"cvss_v4_0":9},{"baseScore":144,"baseSeverity":395,"vectorString":147,"impactScore":396,"exploitabilityScore":397},"HIGH",9.8,4.1,{"source":152,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":399,"cvss_v4_0":9},{"baseScore":144,"baseSeverity":395,"vectorString":147,"impactScore":396,"exploitabilityScore":397},[401,424,434],{"ecosystem":9,"name":402,"vendor":403,"product":402,"cpe_part":404,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":405},"firefox","mozilla","a",[406,413,417,420],{"version":407,"is_range":408,"range_type":146,"version_start":409,"version_start_type":410,"version_end":411,"version_end_type":412,"fixed_in":9},">= unspecified, \u003C 149",true,"unspecified","including","149","excluding",{"version":414,"is_range":408,"range_type":415,"version_start":9,"version_start_type":9,"version_end":416,"version_end_type":412,"fixed_in":9},"lt115.34.0","cpe","115.34.0",{"version":418,"is_range":408,"range_type":415,"version_start":9,"version_start_type":9,"version_end":419,"version_end_type":412,"fixed_in":9},"lt149.0","149.0",{"version":421,"is_range":408,"range_type":415,"version_start":422,"version_start_type":410,"version_end":423,"version_end_type":412,"fixed_in":9},"gte128.0_lt140.9.0","128.0","140.9.0",{"ecosystem":9,"name":425,"vendor":403,"product":426,"cpe_part":404,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":427},"firefox esr","firefox_esr",[428,431],{"version":429,"is_range":408,"range_type":146,"version_start":409,"version_start_type":410,"version_end":430,"version_end_type":412,"fixed_in":9},">= unspecified, \u003C 115.34","115.34",{"version":432,"is_range":408,"range_type":146,"version_start":409,"version_start_type":410,"version_end":433,"version_end_type":412,"fixed_in":9},">= unspecified, \u003C 140.9","140.9",{"ecosystem":9,"name":435,"vendor":403,"product":436,"cpe_part":404,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":437},"Thunderbird","thunderbird",[438,439],{"version":407,"is_range":408,"range_type":146,"version_start":409,"version_start_type":410,"version_end":411,"version_end_type":412,"fixed_in":9},{"version":432,"is_range":408,"range_type":146,"version_start":409,"version_start_type":410,"version_end":433,"version_end_type":412,"fixed_in":9}]