Mozilla Firefox and Firefox ESR Integer Overflow Vulnerability in Widget: Win32 Component

Vulnerability

An integer overflow vulnerability has been identified in the Widget: Win32 component of Mozilla Firefox. This issue affects Firefox versions prior to 151 and Firefox ESR versions prior to 140.11. The vulnerability arises from improper handling of integer values, which can lead to unexpected behavior or conditions.

Impact

Exploitation of this vulnerability could lead to memory safety issues, allowing for potential memory corruption. With sufficient effort, such memory safety bugs could be exploited to execute arbitrary code, according to Mozilla.

Remediation

Users can upgrade to Firefox 151 or Firefox ESR 140.11 to address this vulnerability.

Added: May 19, 2026, 2:49 PM
Updated: May 19, 2026, 2:49 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.8
remediation
7.7
relevance
8.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.