Mozilla Firefox and Thunderbird Integer Overflow Vulnerability in SVG Component

Vulnerability

An integer overflow vulnerability has been identified in the SVG component of Mozilla Firefox and Thunderbird. This issue affects Firefox versions prior to 143, Firefox ESR versions prior to 115.28 and 140.3, as well as Thunderbird versions prior to 143 and 140.3. The vulnerability could potentially be exploited to cause memory safety issues, leading to arbitrary code execution.

Impact

Exploitation of this vulnerability causes an integer overflow, which can lead to memory safety violations. Such violations have been observed to allow arbitrary code execution in similar contexts.

Remediation

Users can upgrade to Firefox 143, Firefox ESR 115.28, Thunderbird 143 or Thunderbird ESR 140.3 to address this vulnerability.

Added: Sep 16, 2025, 4:24 PM
Updated: Sep 16, 2025, 4:24 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.