Description
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow (CWE-190) in the Graphics: ImageLib component, which can corrupt memory when processing image data. This flaw can allow an attacker to potentially execute arbitrary code or crash the application, leading to a loss of confidentiality, integrity, or availability of the affected system.

Affected Systems

The flaw affects Mozilla Firefox and Mozilla Thunderbird. Versions prior to 153 contain the unpatched code; Firefox 153 and Thunderbird 153 contain the fix.

Risk and Exploitability

The CVSS score of 9.8 marks this issue as critical. The EPSS score of less than 1% indicates a low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Given that the overflow occurs while handling image files, the likely attack vector involves an attacker supplying a malicious image to the browser or email client to trigger the overflow.

Generated by OpenCVE AI on August 4, 2026 at 05:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 153 or later or Thunderbird 153 or later.
  • Apply the latest Mozilla security updates to ensure the Graphics: ImageLib component is patched.
  • If immediate upgrade is not possible, configure the browser and email client to block remote image loading or enforce a strict content security policy until the patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153. Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.
Title Integer overflow in the Graphics: ImageLib component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:07.716Z

Reserved: 2026-07-20T21:57:35.982Z

Link: CVE-2026-16402

cve-icon Vulnrichment

Updated: 2026-07-22T17:24:50.831Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:38:14Z

Links: CVE-2026-16402 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound