Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11353

Опубликовано: 21 июл. 2026
Источник: fstec
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Уязвимость браузера Firefox и почтового клиента Thunderbird связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код

Вендор

Canonical Ltd.
Mozilla Corp.

Наименование ПО

Ubuntu
Thunderbird
Firefox

Версия ПО

22.04 LTS (Ubuntu)
152 (Thunderbird)
152 (Firefox)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Canonical Ltd. Ubuntu 22.04 LTS

Уровень опасности уязвимости

Критический уровень опасности (базовая оценка CVSS 2.0 составляет 10)
Критический уровень опасности (базовая оценка CVSS 3.1 составляет 9,8)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-16411

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

EPSS

Процентиль: 41%
0.00493
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 месяцев назад

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS3: 7.5
redhat
около 2 месяцев назад

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS3: 9.8
nvd
около 2 месяцев назад

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS3: 9.8
debian
около 2 месяцев назад

Memory safety bugs present in Firefox 152. Some of these bugs showed e ...

CVSS3: 9.8
github
около 2 месяцев назад

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153.

EPSS

Процентиль: 41%
0.00493
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2