CVE-2026-16353
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13
CVSS
9.8
Crítico
EPSS
0.5%
p42
KEV
—
Exploit Today
13
0-100
Publicado: 21 jul 2026 · Última mod.: 24 jul 2026 · CWE-416 · CWE-476 · CWE-824
0.4%EPSS · 30 días0.5%
2026-08-092026-09-06
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2049523
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-68/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-69/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-70/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-71/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-72/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-184537.5 ALT—
———A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.5hCVE-2026-864253.3 BAJ—
———ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).7hCVE-2026-864233.3 BAJ—
———ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).7hCVE-2026-82325——
——0A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages9hCVE-2026-205176.7 MED—
——0In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781.9hCVE-2026-205155.5 MED—
——0In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.9h