Mozilla Firefox and Thunderbird Integer Overflow Vulnerability in the JavaScript Standard Library Component

Vulnerability

A vulnerability has been identified in the JavaScript Standard Library component of Mozilla Firefox and Thunderbird. This issue, an integer overflow, affects multiple versions: Firefox prior to 148, Firefox ESR prior to 140.8, Thunderbird prior to 148, and Thunderbird ESR prior to 140.8.

Impact

Exploitation of this vulnerability leads to an integer overflow, which can commonly result in memory corruption or other unintended behavior in applications.

Remediation

Users can upgrade to Firefox 148, Firefox ESR 140.8, Thunderbird 148, or Thunderbird ESR 140.8 to address this vulnerability.

Added: Feb 24, 2026, 2:56 PM
Updated: Feb 24, 2026, 10:59 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.