Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11354

Опубликовано: 21 июл. 2026
Источник: fstec
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Уязвимость браузеров Firefox, Firefox ESR и почтовых клиентов Thunderbird, Thunderbird ESR связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код

Вендор

Red Hat Inc.
Canonical Ltd.
АО «ИВК»
Mozilla Corp.

Наименование ПО

Red Hat Enterprise Linux
Ubuntu
АЛЬТ СП 10
Thunderbird
Thunderbird ESR
Firefox ESR
Firefox

Версия ПО

7 (Red Hat Enterprise Linux)
8 (Red Hat Enterprise Linux)
22.04 LTS (Ubuntu)
9 (Red Hat Enterprise Linux)
- (АЛЬТ СП 10)
10 (Red Hat Enterprise Linux)
152 (Thunderbird)
140.12 (Thunderbird ESR)
115.37 (Firefox ESR)
140.12 (Firefox ESR)
152 (Firefox)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 7
Red Hat Inc. Red Hat Enterprise Linux 8
Canonical Ltd. Ubuntu 22.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 9
АО «ИВК» АЛЬТ СП 10 -
Red Hat Inc. Red Hat Enterprise Linux 10

Уровень опасности уязвимости

Критический уровень опасности (базовая оценка CVSS 2.0 составляет 10)
Критический уровень опасности (базовая оценка CVSS 3.1 составляет 9,8)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-16360
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-16360
Для ОС АЛЬТ СП 10: установка обновления из публичного репозитория программного средства: https://altsp.su/obnovleniya-bezopasnosti/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

EPSS

Процентиль: 39%
0.00468
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 месяцев назад

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS3: 7.5
redhat
около 2 месяцев назад

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS3: 9.8
nvd
около 2 месяцев назад

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS3: 9.8
debian
около 2 месяцев назад

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 a ...

CVSS3: 9.8
github
около 2 месяцев назад

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

EPSS

Процентиль: 39%
0.00468
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2