Mozilla Firefox and Thunderbird WebRender Component Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the WebRender component of Mozilla Firefox and Thunderbird. This issue causes excessive memory consumption, leading to out-of-memory conditions. The vulnerability affects Firefox versions prior to 142, Firefox ESR versions prior to 140.2, Thunderbird versions prior to 142, and Thunderbird ESR versions prior to 140.2.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to run out of memory and potentially crash.

Remediation

Users can upgrade to Firefox 142, Firefox ESR 140.2, Thunderbird 142, or Thunderbird ESR 140.2 to address this vulnerability.

Added: Aug 19, 2025, 9:22 PM
Updated: Aug 19, 2025, 9:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.