Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-16356

Опубликовано: 21 июл. 2026
Источник: debian
EPSS Низкий

Описание

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed153.0-1package
firefox-esrfixed140.13.0esr-1package
thunderbirdunfixedpackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356

  • https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356

  • https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16356

EPSS

Процентиль: 32%
0.00394
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
10 дней назад

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS3: 7.5
redhat
10 дней назад

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS3: 9.8
nvd
10 дней назад

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS3: 9.8
github
10 дней назад

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

suse-cvrf
8 дней назад

Security update for MozillaFirefox

EPSS

Процентиль: 32%
0.00394
Низкий