Description
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is caused by incorrect boundary checks within the graphics subsystem, which can lead to memory corruption and potentially allow an attacker to execute arbitrary code. This flaw is classified as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer. Mozilla Firefox 153 and Mozilla Firefox ESR 115.38/140.13, as well as Mozilla Thunderbird 153 and Mozilla Thunderbird ESR 140.13, are vulnerable, indicating that earlier releases remain at risk.

Affected Systems

The affected products are Mozilla Firefox and Mozilla Thunderbird. Versions prior to Firefox 153, as well as Firefox ESR 115.38 and 140.13, are impacted, along with corresponding Thunderbird releases before version 153 or the ESR 140.13 release.

Risk and Exploitability

The CVSS score of 9.8 and the EPSS score of less than 1% indicate that exploitation attempts are expected to be rare at this time. The issue is not listed in the CISA KEV catalog. The most likely attack vector involves an attacker loading malicious content that triggers graphics operations, such as a crafted image or vector graphic, which could lead to arbitrary code execution on the affected system.

Generated by OpenCVE AI on August 3, 2026 at 00:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 153 or newer, or the Firefox ESR 115.38/140.13 release if using ESR versions.
  • Upgrade to Thunderbird 153 or newer, or the Thunderbird ESR 140.13 release if using ESR versions.
  • Monitor Mozilla security advisories for any interim mitigation recommendations until a patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Title Incorrect boundary conditions in the Graphics component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:31.600Z

Reserved: 2026-07-20T21:56:03.705Z

Link: CVE-2026-16357

cve-icon Vulnrichment

Updated: 2026-07-22T15:40:30.946Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:04.207

Modified: 2026-07-24T15:28:40.633

Link: CVE-2026-16357

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T12:37:45Z

Links: CVE-2026-16357 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:00:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write