CVE-2026-16412
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume tha
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 21 jul 2026 · Última mod.: 21 jul 2026 · CWE-119
Sin historial EPSS suficiente todavía.
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2005113%2C2025369%2C2026301%2C2028663%2C2029761%2C2042242%2C2043271%2C2043300%2C2044612%2C2045378%2C2045406%2C2045407%2C2045616%2C2045626%2C2045730%2C2045732%2C2045769%2C2045771%2C2047957%2C2048934%2C2049818%2C2049822%2C2050151%2C2050368%2C2051653%2C2051658
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2043035%2C2045057%2C2045187%2C2045402%2C2045417%2C2045482%2C2045611%2C2045618%2C2045756%2C2046917%2C2047718
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2045413%2C2053635%2C2053637
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-68/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-70/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-164119.8 CRÍ—
——0Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153.2hCVE-2026-163619.8 CRÍ—
——0Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38 and Firefox ESR 140.13.3hCVE-2026-163599.1 CRÍ—
——0Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.2hCVE-2026-162488.8 ALT37.5%
——11A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.1dCVE-2026-162256.3 MED13.7%
——4A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. The manipulation of the argument PDULength results in out-of-bounds write. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.1dCVE-2026-160978.8 ALT37.3%
——11A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.1d