Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
ID: 01136b9c-f1ea-5a7a-b44b-3d9467608c41
STIX ID: report--01136b9c-f1ea-5a7a-b44b-3d9467608c41
Feed Name: CISecurity.org Advisories
Multiple critical and lower-severity vulnerabilities were disclosed in Mozilla products (Firefox, Thunderbird, and ESR), including memory-safety and use-after-free bugs (e.g., CVE-2024-43097, CVE-2025-1930–1933, 1937, 1938, 1943) that could allow arbitrary code execution, plus other issues such as tapjacking, clickjacking, and passkey phishing; affected versions include Firefox 136, Thunderbird 136, and various ESR releases. Successful exploitation of the most severe flaws could let attackers install programs, view/change/delete data, or create accounts with elevated privileges, though the report does not indicate active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
