Mozilla Firefox and Thunderbird Integer Overflow Vulnerability in Audio/Video Component

Vulnerability

A vulnerability has been identified in the Audio/Video component of Mozilla Firefox and Thunderbird, specifically in versions prior to Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird ESR 140.8. This vulnerability arises from an integer overflow, which can lead to various issues, including memory corruption.

Impact

Exploitation of this vulnerability causes an integer overflow, which can lead to memory corruption. Such memory safety bugs can potentially be exploited to execute arbitrary code.

Remediation

Users can upgrade to Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, or Thunderbird 140.8 to address this vulnerability.

Added: Feb 24, 2026, 2:48 PM
Updated: Feb 24, 2026, 10:52 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.9
exploitability
4.4
remediation
7.7
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.