Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38 and Firefox ESR 140.13. | Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13. |
| Title | Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 | Memory safety bugs fixed in Thunderbird ESR 140.13 |
| References |
|
Tue, 21 Jul 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox |
|
| Vendors & Products |
Mozilla
Mozilla firefox |
Tue, 21 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-119 | |
| Metrics |
cvssV3_1
|
Tue, 21 Jul 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38 and Firefox ESR 140.13. | |
| Title | Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-07-22T19:19:43.379Z
Reserved: 2026-07-20T21:56:10.203Z
Link: CVE-2026-16361
Updated: 2026-07-21T18:56:01.630Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-21T22:00:04Z