[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-4688":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":106,"related":107,"reserved_at":9,"published_at":120,"modified_at":121,"state":122,"summary":123,"references_raw":132,"kevs":156,"epss":157,"epss_history":160,"metrics":373,"affected":382},"CVE-2026-4688","Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82,84,86,88,90,92,94,96,98,100,102,104],{"_key":25},"OPENSUSE-SU-2026:10413-1",{"_key":27},"DSA-6178-1",{"_key":29},"DLA-4510-1",{"_key":31},"DLA-4511-1",{"_key":33},"DSA-6179-1",{"_key":35},"SUSE-SU-2026:1127-1",{"_key":37},"SUSE-SU-2026:1126-1",{"_key":39},"OPENSUSE-SU-2026:10447-1",{"_key":41},"OPENSUSE-SU-2026:10458-1",{"_key":43},"SUSE-SU-2026:1163-1",{"_key":45},"OPENSUSE-SU-2026:20439-1",{"_key":47},"SUSE-SU-2026:20978-1",{"_key":49},"MGASA-2026-0080",{"_key":51},"MGASA-2026-0081",{"_key":53},"UBUNTU-CVE-2026-4688",{"_key":55},"DEBIAN-CVE-2026-4688",{"_key":57},"RHSA-2026:5930",{"_key":59},"RHSA-2026:5931",{"_key":61},"RHSA-2026:5932",{"_key":63},"RHSA-2026:6188",{"_key":65},"RHSA-2026:6342",{"_key":67},"RHSA-2026:6917",{"_key":69},"RHSA-2026:7837",{"_key":71},"RHSA-2026:7838",{"_key":73},"RHSA-2026:7839",{"_key":75},"RHSA-2026:7840",{"_key":77},"RHSA-2026:7841",{"_key":79},"RHSA-2026:7842",{"_key":81},"RHSA-2026:7843",{"_key":83},"RHSA-2026:7845",{"_key":85},"RHSA-2026:7858",{"_key":87},"RHSA-2026:8284",{"_key":89},"RHSA-2026:8285",{"_key":91},"RHSA-2026:8286",{"_key":93},"RHSA-2026:8287",{"_key":95},"RHSA-2026:8288",{"_key":97},"RHSA-2026:8289",{"_key":99},"RHSA-2026:8290",{"_key":101},"RHSA-2026:8315",{"_key":103},"RHSA-2026:8427",{"_key":105},"RHSA-2026:8850",[],[108,109,110,111,112,113,114,115,116,117,118],{"_key":25},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":119},"CGA-FWRV-HV6V-GM22","2026-03-24T12:30:22.710Z","2026-04-13T13:48:35.360Z","Modified",{"cisa_kev":124,"cisa_ransomware":124,"cisa_vendor":9,"epss_severity":125,"epss_score":126,"severity":127,"severity_score":128,"severity_version":129,"severity_source":130,"severity_vector":131,"severity_status":122},false,"low",0.00025,"critical",10,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",[133,139,144,148,152],{"url":134,"sources":135,"tags":137},"https://bugzilla.mozilla.org/show_bug.cgi?id=2016373",[136,130],"cve.org",[138],"Permissions Required",{"url":140,"sources":141,"tags":142},"https://www.mozilla.org/security/advisories/mfsa2026-20/",[136,130],[143],"Vendor Advisory",{"url":145,"sources":146,"tags":147},"https://www.mozilla.org/security/advisories/mfsa2026-22/",[136,130],[143],{"url":149,"sources":150,"tags":151},"https://www.mozilla.org/security/advisories/mfsa2026-23/",[136,130],[],{"url":153,"sources":154,"tags":155},"https://www.mozilla.org/security/advisories/mfsa2026-24/",[136,130],[],[],{"date":158,"score":126,"percentile":159},"2026-06-04",0.07515,[161,165,169,172,175,178,181,184,187,190,193,196,199,202,205,208,211,214,217,220,223,226,229,232,235,238,241,244,247,250,253,256,260,263,266,268,270,273,275,278,281,284,287,290,293,296,299,302,305,308,311,314,316,319,322,325,328,331,333,336,339,342,345,348,351,354,357,360,363,366,369,372],{"date":162,"score":163,"percentile":164},"2026-03-25",0.0002,0.05343,{"date":166,"score":167,"percentile":168},"2026-03-26",0.00019,0.04792,{"date":170,"score":167,"percentile":171},"2026-03-27",0.04794,{"date":173,"score":167,"percentile":174},"2026-03-28",0.04796,{"date":176,"score":167,"percentile":177},"2026-03-29",0.04793,{"date":179,"score":163,"percentile":180},"2026-03-30",0.05327,{"date":182,"score":163,"percentile":183},"2026-03-31",0.05297,{"date":185,"score":163,"percentile":186},"2026-04-01",0.05313,{"date":188,"score":163,"percentile":189},"2026-04-02",0.05355,{"date":191,"score":163,"percentile":192},"2026-04-03",0.0537,{"date":194,"score":163,"percentile":195},"2026-04-04",0.05385,{"date":197,"score":163,"percentile":198},"2026-04-05",0.05384,{"date":200,"score":163,"percentile":201},"2026-04-06",0.05377,{"date":203,"score":163,"percentile":204},"2026-04-07",0.05392,{"date":206,"score":163,"percentile":207},"2026-04-08",0.05426,{"date":209,"score":163,"percentile":210},"2026-04-09",0.05449,{"date":212,"score":163,"percentile":213},"2026-04-10",0.05435,{"date":215,"score":163,"percentile":216},"2026-04-11",0.05422,{"date":218,"score":163,"percentile":219},"2026-04-12",0.05409,{"date":221,"score":163,"percentile":222},"2026-04-13",0.05401,{"date":224,"score":163,"percentile":225},"2026-04-14",0.05335,{"date":227,"score":163,"percentile":228},"2026-04-15",0.05338,{"date":230,"score":163,"percentile":231},"2026-04-16",0.05354,{"date":233,"score":163,"percentile":234},"2026-04-17",0.05363,{"date":236,"score":163,"percentile":237},"2026-04-18",0.05357,{"date":239,"score":163,"percentile":240},"2026-04-19",0.05349,{"date":242,"score":163,"percentile":243},"2026-04-20",0.05346,{"date":245,"score":163,"percentile":246},"2026-04-21",0.05519,{"date":248,"score":163,"percentile":249},"2026-04-22",0.0553,{"date":251,"score":163,"percentile":252},"2026-04-23",0.05556,{"date":254,"score":163,"percentile":255},"2026-04-24",0.05555,{"date":257,"score":258,"percentile":259},"2026-04-25",0.00022,0.06095,{"date":261,"score":258,"percentile":262},"2026-04-26",0.06089,{"date":264,"score":258,"percentile":265},"2026-04-27",0.0608,{"date":267,"score":258,"percentile":265},"2026-04-28",{"date":269,"score":258,"percentile":259},"2026-04-29",{"date":271,"score":258,"percentile":272},"2026-04-30",0.06098,{"date":274,"score":258,"percentile":272},"2026-05-01",{"date":276,"score":258,"percentile":277},"2026-05-02",0.06124,{"date":279,"score":258,"percentile":280},"2026-05-03",0.06123,{"date":282,"score":258,"percentile":283},"2026-05-04",0.06109,{"date":285,"score":258,"percentile":286},"2026-05-05",0.06114,{"date":288,"score":258,"percentile":289},"2026-05-06",0.06138,{"date":291,"score":258,"percentile":292},"2026-05-07",0.06216,{"date":294,"score":258,"percentile":295},"2026-05-08",0.06249,{"date":297,"score":258,"percentile":298},"2026-05-09",0.06291,{"date":300,"score":258,"percentile":301},"2026-05-10",0.06311,{"date":303,"score":258,"percentile":304},"2026-05-11",0.06307,{"date":306,"score":258,"percentile":307},"2026-05-12",0.06315,{"date":309,"score":258,"percentile":310},"2026-05-13",0.06319,{"date":312,"score":258,"percentile":313},"2026-05-14",0.06326,{"date":315,"score":258,"percentile":313},"2026-05-15",{"date":317,"score":258,"percentile":318},"2026-05-16",0.06335,{"date":320,"score":258,"percentile":321},"2026-05-17",0.06328,{"date":323,"score":258,"percentile":324},"2026-05-18",0.06288,{"date":326,"score":258,"percentile":327},"2026-05-19",0.06266,{"date":329,"score":258,"percentile":330},"2026-05-20",0.06229,{"date":332,"score":258,"percentile":330},"2026-05-21",{"date":334,"score":258,"percentile":335},"2026-05-22",0.06464,{"date":337,"score":258,"percentile":338},"2026-05-23",0.06468,{"date":340,"score":258,"percentile":341},"2026-05-24",0.0647,{"date":343,"score":258,"percentile":344},"2026-05-25",0.06448,{"date":346,"score":258,"percentile":347},"2026-05-26",0.06426,{"date":349,"score":258,"percentile":350},"2026-05-27",0.0646,{"date":352,"score":258,"percentile":353},"2026-05-28",0.06552,{"date":355,"score":258,"percentile":356},"2026-05-29",0.06573,{"date":358,"score":258,"percentile":359},"2026-05-30",0.06562,{"date":361,"score":126,"percentile":362},"2026-05-31",0.0763,{"date":364,"score":126,"percentile":365},"2026-06-01",0.07601,{"date":367,"score":126,"percentile":368},"2026-06-02",0.07553,{"date":370,"score":126,"percentile":371},"2026-06-03",0.07503,{"date":158,"score":126,"percentile":159},[374,377],{"source":130,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":375,"cvss_v4_0":9},{"baseScore":128,"baseSeverity":376,"vectorString":131,"impactScore":128,"exploitabilityScore":128},"CRITICAL",{"source":136,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":378,"cvss_v4_0":9},{"baseScore":379,"baseSeverity":376,"vectorString":380,"impactScore":128,"exploitabilityScore":381},9.6,"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",7.2,[383,402,409],{"ecosystem":9,"name":384,"vendor":385,"product":384,"cpe_part":386,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":387},"firefox","mozilla","a",[388,395,399],{"version":389,"is_range":390,"range_type":136,"version_start":391,"version_start_type":392,"version_end":393,"version_end_type":394,"fixed_in":9},">= unspecified, \u003C 149",true,"unspecified","including","149","excluding",{"version":396,"is_range":390,"range_type":397,"version_start":9,"version_start_type":9,"version_end":398,"version_end_type":394,"fixed_in":9},"lt140.9.0","cpe","140.9.0",{"version":400,"is_range":390,"range_type":397,"version_start":9,"version_start_type":9,"version_end":401,"version_end_type":394,"fixed_in":9},"lt149.0","149.0",{"ecosystem":9,"name":403,"vendor":385,"product":404,"cpe_part":386,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":405},"firefox esr","firefox_esr",[406],{"version":407,"is_range":390,"range_type":136,"version_start":391,"version_start_type":392,"version_end":408,"version_end_type":394,"fixed_in":9},">= unspecified, \u003C 140.9","140.9",{"ecosystem":9,"name":410,"vendor":385,"product":411,"cpe_part":386,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":412},"Thunderbird","thunderbird",[413,414],{"version":389,"is_range":390,"range_type":136,"version_start":391,"version_start_type":392,"version_end":393,"version_end_type":394,"fixed_in":9},{"version":407,"is_range":390,"range_type":136,"version_start":391,"version_start_type":392,"version_end":408,"version_end_type":394,"fixed_in":9}]