Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 143
An integer overflow vulnerability has been identified in the SVG component of Mozilla Firefox and Thunderbird. This issue affects Firefox versions prior to 143, Firefox ESR versions prior to 115.28 and 140.3, as well as Thunderbird versions prior to 143 and 140.3. The vulnerability could potentially be exploited to cause memory safety issues, leading to arbitrary code execution.
Exploitation of this vulnerability causes an integer overflow, which can lead to memory safety violations. Such violations have been observed to allow arbitrary code execution in similar contexts.
Users can upgrade to Firefox 143, Firefox ESR 115.28, Thunderbird 143 or Thunderbird ESR 140.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.