By weakness (CWE)

CWE-670: related vulnerabilities

CVEs classified under CWE-670. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

1 published vulnerability

  • CVE-2026-12321MEDIUM 5.4

    A flaw in Firefox and Thunderbird's JavaScript-to-WebAssembly compiler causes it to generate incorrect machine code in certain scenarios. An attacker could exploit this by serving a malicious webpage or email with crafted script, potentially allowing them to read sensitive data or modify page content. The vulnerability requires user interaction (visiting a site or opening an email) and does not enable system crashes or privilege escalation.